Information Security Analyst - GRC
Kent - Mainly Remote site visits once per month
£45,000 - £50,000 + benefits
Fantastic new permanent opportunity for an experienced GRC focused Information Security Analyst with this market leading financial services business based in Kent.
As an Information Security Analyst, you will join an established team to provide Governance, Risk and Compliance oversight and services to deliver Information Security Strategy and help manage internal and third-party information security risk. You will also support other initiatives, such as the management of the Logical Access Management (LAM) of key technology systems, to meet full compliance requirements and always protecting customers and colleagues.
Main responsibilities:
- Support the execution of the Cyber Strategic Plan while continuously seeking innovative methods to enhance the cyber security function, reduce risk across the organisation, and improve customer and colleague experiences.
- Oversee and manage cyber security governance controls in line with the Cyber Assurance Framework, including tracking performance through KPIs and SLAs, supporting vulnerability, management activities and providing relevant management information as needed.
- Assist with compliance activities such as policy and process assessments / improvements, ISO27001 and PCI-DSS re-certifications and audits.
- Implement and ensure the efficiency of internal and third-party cyber risk mitigation controls to align with risk appetites. Utilising internal reviews and third-party risk management systems and processes to ensure third parties meet security standards.
- Stay updated on the external cyber threat landscape through participation in internal/external events and obtaining certifications and share best practices with colleagues.
- Manage the technology access review process, coordinating with technology teams, broader business functions, and audit teams to ensure proper system access management and review.
- Assist and support the incident management processes, including handling incidents, performing root cause analysis, documenting lessons learned, creating and ongoing reviews of playbooks.
- Offer cyber consultancy services to support business initiatives, ensuring compliance and risk appetite requirements are met.
- Adhere to our Governance and Business Code of Conduct, consistently acting with integrity and due diligence.
Skills Required:
- You will have proven experience of working within a similar GRC focused Information Security Analyst position.
- Have a good understanding of risk management approaches and the application of Cyber risk management controls.
- A broad understanding of the Cyber Security domain and associated compliance requirements such as FCA, GDPR, and PCI/DSS.
- Experience with 3rd Party Risk Assessments.
- Broad knowledge and understanding of cyber-attack techniques and vulnerability testing approaches.
- Experience in undertaking Risk assessments, control testing and reporting in a regulated environment.
- Proven stakeholder management experience and be able to demonstrate good written and verbal communications skills.
- Can demonstrate previous experience in the planning, leading and delivering of audits and compliance activities.
For any further queries regarding the role, please contact Danny Palmer at