Senior Trust Security Analyst

NICE

City Of London

Hybrid

GBP 70,000 - 120,000

Full time

9 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

NiCE is seeking a Senior Trust Analyst to lead security posture assessments and respond to customer security questionnaires for UK Sovereign clients. You will bridge UK government security expectations with engineering teams, translating complex controls into clear guidance and ensuring timely remediation updates.

In this senior, customer-facing role, you will own dialogue on security posture, privacy terms, and trust documentation while coordinating cross-functional inputs and maintaining key

Qualifications

  • Citizenship and ability to pass SC clearance.
  • 5+ years in security, GRC, trust, or customer-facing role with security questionnaires and reporting.
  • Hands-on experience responding to SIG, CAIQ, VSA, and government questionnaires.
  • Working knowledge of Cyber Essentials Plus, ISO 27001, SOC 2 Type II, and at least one of PCI DSS, GDPR/UK GDPR, HIPAA, or FedRAMP.
  • Strong technical understanding of security principles, architecture, vulnerability management, access control, encryption, incident response, network security, and secure SDLC.
  • Familiarity with cloud infrastructure (AWS, Azure, or GCP) and SaaS security models.
  • Excellent written and verbal communication, capable of explaining technical controls to non-technical audiences.
  • Proven customer-facing experience in security or technology sectors, including regulated or government customers.
  • Ability to manage high-volume queues, set priorities, and drive multi-stakeholder responses to deadlines.
  • Bachelor-level education or equivalent practical experience.

Responsibilities

  • Serve as primary contact for UK Sovereign customers on security posture, vulnerabilities, remediation, and trust docs.
  • Lead end-to-end responses to security questionnaires (SIG, CAIQ, VSA, MoD/UK govt) for UK Sovereign context.
  • Translate technical controls into clear business language for technical and non-technical stakeholders.
  • Maintain and update the public trust center and UK Sovereign customer documentation.
  • Collaborate with security teams to assess current security posture of UK Sovereign environments.
  • Support POA&M reporting with vulnerabilities, remediation steps, owners, and timelines.
  • Prepare and deliver monthly security status updates to UK Sovereign customers.
  • Monitor remediation activity across engineering and security teams to meet timelines and compliance.
  • Read and interpret third-party audit reports (SOC 2 Type II, ISO 27001, pen tests) and present findings to customers.
  • Gather technical details from engineering and translate into concise updates for stakeholders.
  • Participate in security review meetings and capture actions for timely follow-up.

Skills

Security governance
Questionnaire responses
Communication
Customer relations
Stakeholder management
Vulnerability management
Security reporting
Cloud security
Organisational skills
Technical security knowledge

Education

Bachelor's degree in a relevant field

Tools

ServiceNow
Whistic
Vanta Trust
Drata Trust

Job description

At NiCE, we don't limit our challenges. We challenge our limits. Always. We're ambitious. We're game changers. And we play to win. We set the highest standards and execute beyond them. And if you're like us, we can offer you the ultimate career opportunity that will light a fire within you.

So what's the role all about?

The Senior Trust Analyst - UK Sovereign sits at the intersection of security, sales, and customer success, serving as the primary trust and security point of contact for our UK Sovereign customers. This role owns the response to customer security inquiries and questionnaires, supports contract reviews on security and privacy terms, and acts as a trusted advisor on the security posture of our UK Sovereign environments.

In addition to traditional Trust Analyst responsibilities, this role serves as the dedicated liaison between UK Sovereign technical security teams and customers, ensuring transparency, trust, and proactive communication. The Senior Trust Analyst will track and report vulnerability remediation activities in a structured Plan of Action and Milestones (POA&M) format, deliver regular security status updates, and translate complex technical information into clear, customer-ready communications.

This is a senior, customer-facing position critical to building and sustaining trust with UK government and regulated sector customers, accelerating deal cycles, and reinforcing the integrity of our UK Sovereign security program.

How will you make an impact?
Customer Trust & Security Engagement
  • Trusted Advisor: Serve as the primary point of contact for UK Sovereign customers on all matters related to security posture, vulnerabilities, remediation activities, and trust documentation.
  • Security Questionnaires: Support end-to-end responses to customer and prospect security questionnaires (SIG, CAIQ, VSA, MoD/UK government questionnaires, and bespoke enterprise formats), ensuring accurate, timely, and consistent answers tailored to UK Sovereign context.
  • Responder: Help respond to inbound customer security inquiries via email and ticketing, translating technical controls into clear business language for both technical and non-technical stakeholders.
  • Trust Portal & Documentation: Maintain the public trust center and UK Sovereign customer-facing documentation, ensuring security whitepapers, certifications, and standard responses remain current and reusable.
Security Posture & Vulnerability Reporting
  • Security Posture Assessment: Collaborate closely with UK Sovereign technical and engineering teams to understand and assess the current security posture of UK Sovereign environments.
  • POA&M Reporting: help support vulnerability remediation status in a structured Plan of Action and Milestones (POA&M) format, documenting identified vulnerabilities, planned remediation steps, responsible parties, target completion dates, and progress against agreed timelines.
  • Monthly Customer Reporting: help prepare anddeliver monthly security status updates to UK Sovereign customers, including progress on scheduled remediation items and key security metrics.
  • Remediation Oversight: Monitor and track remediation activities across engineering and security teams, ensuring alignment with agreed timelines and compliance requirements.
Audit
  • Audit Interpretation: Read and interpret third-party audit reports (SOC 2 Type II, ISO 27001, penetration test summaries) and represent findings to customers in questionnaires and security responses.
Communication & Stakeholder Management
  • Information Translation: Gather detailed technical information from engineering and security teams, then convert and filter it into clear, concise, and structured updates accessible to both technical experts and non-technical stakeholders.
  • Customer Meetings: participate in security review meetings, capture feedback and action items, and ensure timely follow-up and resolution by technical teams.
  • Cross-Functional Coordination: Coordinate input from internal teams to validate questionnaire answers and resolve gaps between stated controls and operational reality.
Have you got what it takes?
  • Citizenship & Clearance: UK citizenship and ability to pass and maintain SC clearance.
  • Experience: 5+ years in a security, GRC, trust, or technical customer-facing role, with direct ownership of security questionnaires, customer inquiries, and security reporting.
  • Questionnaire Expertise: Hands-on experience responding to SIG, CAIQ, VSA, and bespoke enterprise/government security questionnaires.
  • Compliance Knowledge: Working knowledge of Cyber Essentials Plus, ISO 27001, SOC 2 Type II, and at least one of PCI DSS, GDPR/UK GDPR, HIPAA, or FedRAMP.
  • Technical Expertise: Strong technical understanding of security principles, architecture, and vulnerability management, including access control, encryption, incident response, network security, and secure SDLC.
  • Cloud & SaaS: Familiarity with cloud infrastructure (AWS, Azure, or GCP) and SaaS security models.
  • Communication: Exceptional written and verbal communication skills, with proven ability to translate complex technical controls for non-technical audiences (procurement, legal, executives, government stakeholders).
  • Customer Relations: Proven experience in customer-facing roles within security or technology sectors, ideally including regulated or government customers.
  • Organisational Skills: Demonstrated ability to manage a high-volume queue, set priorities, and drive multi-stakeholder responses to deadline.
  • Education: Bachelor's degree in a relevant field, or equivalent practical experience.
  • Discretion: Proven ability to handle confidential customer and company information with integrity and discretion.
You will have an advantage if you also have
  • Professional cybersecurity certifications (e.g., CISSP, CISM, CISA, CCSK, ISO 27001 Lead Auditor, Security+).
  • Experience working with UK Sovereign, MoD, or UK government environments.
  • Familiarity with POA&M processes and structured vulnerability remediation reporting.
  • Experience with trust portal platforms (ServiceNow, Whistic, Vanta Trust, Drata Trust).
  • Familiarity with AI/ML security and emerging frameworks (NIST AI RMF, ISO 42001).
  • Previous leadership or line management experience.
  • Integrity and discretion when handling sensitive customer and government information.
  • Resilience and adaptability in dynamic, high-pressure regulated environments.
  • Proactive, self-motivated, and committed to continuous improvement.
  • Fast learner with a demonstrated ability to self-educate on new technologies, products, and evolving security frameworks.
  • Collaborative working style across technical, legal, sales, and customer-facing teams.

Requisition ID:

Reporting into: Director, Cloud Information Security and Architecture

Role type: Individual contributor

#LI-Hybrid

About NiCE

NICE Ltd. (NASDAQ: NICE) software products are used by 25,000+ global businesses, including 85 of the Fortune 100 corporations, to deliver extraordinary customer experiences, fight financial crime and ensure public safety. Every day, NiCE software manages more than 120 million customer interactions and monitors 3+ billion financial transactions.

Known as an innovation powerhouse that excels in AI, cloud and digital, NiCE is consistently recognized as the market leader in its domains, with over 8,500 employees across 30+ countries.

NiCE is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, age, sex, marital status, ancestry, neurotype, physical or mental disability, veteran status, gender identity, sexual orientation or any other category protected by law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Trust Security Analyst
Senior Trust Security Analyst

NiCE • Greater London

On-site
GBP 90,000 - 125,000
Senior Trust Security Analyst
Senior Trust Security Analyst

Nice Ltd. • Greater London

Hybrid
GBP 75,000 - 110,000
Hybrid work
Professional Sevices Engineer (Implementation Engineer)
Professional Sevices Engineer (Implementation Engineer)

Nice • Southampton

On-site
GBP 50,000 - 75,000
Senior Trust & Security Advisor — UK Sovereign
Senior Trust & Security Advisor — UK Sovereign

NICE • City Of London

Hybrid
GBP 70,000 - 120,000
Senior Trust & Security Lead - UK Sovereign
Senior Trust & Security Lead - UK Sovereign

Nice Ltd. • Greater London

Hybrid
GBP 75,000 - 110,000
Hybrid work
Senior Trust & Security Advisor - UK Sovereign
Senior Trust & Security Advisor - UK Sovereign

NiCE • Greater London

On-site
GBP 90,000 - 125,000
DevOps Engineer
DevOps Engineer

Nice • Greater London

On-site
GBP 85,000 - 110,000
NICE-FLEX hybrid model
Lead DevOps Engineer
Lead DevOps Engineer

Nice • Greater London

Hybrid
GBP 90,000 - 120,000
NICE-FLEX hybrid model
Senior Software Engineer
Senior Software Engineer

Nice-0a1ef543 • Greater London

Hybrid
GBP 90,000 - 130,000
NICE-FLEX hybrid model
Global company
Senior Software Engineer
Senior Software Engineer

NICE • Greater London, Southampton

Hybrid
GBP 90,000 - 120,000
Hybrid work model