Enable job alerts via email!

IT Security Analyst

83zero Limited

Gerrards Cross

Hybrid

GBP 50,000 - 55,000

Full time

3 days ago
Be an early applicant

Job summary

A leading software company based in the UK is seeking an IT Security Analyst to enhance their security function. This position entails managing customer security responses and compliance assessments while collaborating across departments. Candidates should have over three years of related experience, strong communication skills, and knowledge of security frameworks. This role offers a competitive salary, flexible hybrid working, and excellent career development opportunities.

Benefits

25 days annual leave + public holidays
Matched pension scheme
Private medical insurance
Fitness allowance
Paid study leave
Flexible hybrid working

Qualifications

  • 3+ years' experience in Information Security, GRC, or Vendor Risk Management.
  • Strong experience issuing or responding to security questionnaires.
  • Knowledge of ISO 27001 Annex A, SOC 2, and GDPR/CCPA.

Responsibilities

  • Own and manage responses to customer security questionnaires.
  • Work cross-functionally with Legal, Compliance, Procurement, Product, and Security teams.
  • Conduct vendor risk assessments against frameworks.

Skills

Information Security
Vendor Risk Management
Compliance
Communication Skills

Tools

ISO 27001
Cyber Essentials
SOC 2
Job description
IT Security Analyst

Location: Hybrid - Buckinghamshire

Salary: £50,000 - £55,000 + Benefits

83zero are partnered with a market-leading software company who are on a mission to transform the construction and related industries through their end-to-end digital solutions. With teams across the UK, Europe, USA and India, they are delivering large-scale transformation projects on a global scale and are continuing to expand.

We are now looking for a highly organised and detail-driven IT Security Analyst to join their growing security function. This role plays a key part in securing customer trust and supplier integrity, ensuring compliance with recognised frameworks, and supporting wider security initiatives.

The Role
  • Own and manage responses to customer security questionnaires (SIG, CAIQ, bespoke).
  • Work cross-functionally with Legal, Compliance, Procurement, Product and Security teams.
  • Maintain the security assurance matrix in line with ISO 27001, Cyber Essentials, and SOC 2.
  • Act as the key point of contact for security assurance queries.
  • Conduct vendor risk assessments against ISO 27001, NIST, and CIS Controls.
  • Manage the third-party due diligence programme, including onboarding and periodic reviews.
  • Track and publish key security metrics such as risk severity, SLA adherence, and turnaround times.
  • Provide audit artefacts and support internal/external audits.
  • Contribute to broader security initiatives and continuous improvement within the organisation.
About You
  • 3+ years' experience in Information Security, GRC, or Vendor Risk Management.
  • Strong experience issuing or responding to security questionnaires.
  • Knowledge of ISO 27001 Annex A, SOC 2, and GDPR/CCPA.
  • Excellent communication skills, able to translate technical risk to non-technical stakeholders.
  • Eligible to work in the UK and able to pass background checks.
Desirable
  • Certifications such as CRISC, CISSP, CISA, or ISO 27001 Lead Auditor.
  • Familiarity with SaaS/cloud platforms (AWS, Azure, GCP).
  • Understanding of secure software supply chains (SBOM, SLSA).
What's on Offer
  • £50,000 - £55,000 base salary
  • 25 days annual leave + public holidays (increasing with service)
  • Matched pension scheme
  • Private medical insurance & life assurance
  • Fitness allowance
  • Paid study leave & volunteering days
  • Flexible hybrid working
  • Excellent career development and training opportunities
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs