At a Glance
- Tasks: Manage and improve our Information Security Management System while ensuring compliance with industry standards.
- Company: Join BMLL, a leading provider of historical data and analytics in a collaborative culture.
- Benefits: Enjoy competitive salary, 25 days holiday, remote work options, and a well-being budget.
- Other info: Inclusive workplace with regular team lunches and social activities.
- Why this job: Make a real impact in information security and grow into a managerial role.
- Qualifications: 3-5 years in Information Security with ISO 27001 experience preferred.
The predicted salary is between 60000 - 80000 £ per year.
About BMLL: BMLL is the leading independent provider of harmonised Level 3, 2 and 1 historical data and analytics across global equities, ETFs, futures and US equity options. We provide market participants with immediate access to granular T+1 order book data and advanced analytics, enabling them to accelerate research, optimise trading strategies, and better understand market behaviour. BMLL was acquired in 2025 by Nordic Capital, alongside minority shareholder Optiver, marking a joint commitment to accelerate the company's next phase of growth. We offer an inclusive and collaborative culture, a hybrid working environment that includes regular days in our London office, weekly team lunches, and a variety of out-of-hours social activities.
About the role: We are seeking a Senior Information Security Analyst to support and operate the organisation's Information Security Management System (ISMS), aligned to ISO/IEC 27001:2022, NIST CSF, and regulatory requirements (e.g. GDPR, DORA). This is a hands‐on GRC-focused role responsible for the day‐to‐day operation and continuous improvement of the ISMS, working closely with the Head of Information Security. The role is ideal for a candidate looking to develop into an Information Security Manager / ISO role.
Key Responsibilities- ISMS & Governance
- Operate and maintain the ISMS in line with ISO 27001:2022
- Maintain policies, standards, and procedures
- Manage and update the Statement of Applicability (SoA)
- Track control implementation aligned to ISO Annex A
- Prepare audit artefacts and support internal and external audits
- Support management reviews and reporting
- Risk Management
- Maintain the information security risk register
- Conduct risk assessments and treatment planning
- Track remediation actions and risk acceptance
- Align controls to ISO 27001, NIST CSF, and regulatory frameworks
- Security Assurance & Operations
- Support vulnerability management and remediation tracking
- Assist with security incident triage and coordination
- Validate security controls across cloud (AWS) and SaaS platforms
- Work with engineering teams to embed security best practices
- Third-Party Risk Management (TPRM)
- Conduct supplier security assessments and due diligence
- Maintain third-party and AI risk registers
- Support DPIAs and data protection reviews
- Track supplier risks and remediation actions
- Compliance & Customer Assurance
- Support client due diligence responses (DDQs, SIG, VSA)
- Maintain audit evidence and documentation
- Support compliance with GDPR, ISO 27001, and DORA
- Business Continuity & Resilience
- Support Business Impact Analysis (BIA)
- Assist with disaster recovery testing
- Contribute to resilience and BCM improvements
- Security Awareness
- Support delivery of security awareness and training programmes
- Promote a strong security culture across the organisation
- Essential
- 3‐5+ years in Information Security, GRC, or ISMS roles
- Experience supporting or operating an ISO 27001 ISMS
- Strong understanding of risk management and control frameworks
- Familiarity with cloud environments (AWS preferred)
- Experience supporting audits and supplier assessments
- Strong communication and documentation skills
- Desirable
- Exposure to ISO 22301, NIST CSF, or DORA
- Experience with security tooling (e.g. vulnerability management, EDR, SIEM)
- Understanding of DevSecOps / CI/CD security
- Awareness of AI governance and data protection controls
- ISO 27001 Lead Implementer / Auditor (preferred)
- CISM, CISSP, or equivalent (or working towards)
- Detail‐oriented with strong audit discipline
- Structured, process‐driven approach
- Ability to manage multiple priorities
- Strong stakeholder engagement skills
- Pragmatic, risk‐based mindset
- Competitive salary
- 25 days holiday plus bank holidays
- Discretionary Bonus
- Pension Scheme
- Private Medical Insurance
- Work remotely abroad for up to 40 business days each year
- Life Insurance
- Childcare Nursery Scheme
- Combination of remote and London‐based office working, with 2 days in the office per week.
- A yearly Well‐being Physical Activity budget
- Continuous learning through funded training and challenging projects
- Collaborative culture
- Weekly team lunches
- Free Fruit, snacks, and drinks provided throughout the day (When office‐based)
- Regular Team Socials
- Cycle to Work Scheme
We are an inclusive employer and welcome applicants from all backgrounds. We pride ourselves on our commitment to Equality and Diversity. We are committed to removing barriers throughout our hiring process. If you have any special requirements or require reasonable adjustments to help you access career opportunities at BMLL, please do let us know at careers@bmlltech.com.
Senior Information Security Analyst (ISMS Management) in London employer: BMLL Technologies
Contact Detail:
BMLL Technologies Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Information Security Analyst (ISMS Management) in London
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by researching BMLL and its culture. Understand their products and how your skills align with their needs. This will help you stand out and show that you're genuinely interested in the role.
✨Tip Number 3
Practice common interview questions and scenarios related to Information Security. Use the STAR method (Situation, Task, Action, Result) to structure your answers and demonstrate your experience effectively.
✨Tip Number 4
Don’t forget to follow up after your interview! A quick thank-you email can leave a lasting impression and shows your enthusiasm for the position. Plus, it keeps you on their radar!
We think you need these skills to ace Senior Information Security Analyst (ISMS Management) in London
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Senior Information Security Analyst role. Highlight your experience with ISO 27001 and any relevant GRC or ISMS roles you've held. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how your background makes you a great fit for our team. Keep it concise but impactful – we love a good story!
Showcase Your Skills: Don’t forget to showcase your technical skills, especially around risk management and cloud environments like AWS. We’re keen on candidates who can demonstrate their hands-on experience and understanding of security frameworks.
Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. It’s super easy, and you’ll be able to keep track of your application status. Plus, we love seeing applications come directly from our site!
How to prepare for a job interview at BMLL Technologies
✨Know Your Standards
Familiarise yourself with ISO 27001:2022 and NIST CSF. Be ready to discuss how you've applied these frameworks in your previous roles, especially in managing ISMS. This shows you’re not just knowledgeable but also practical in your approach.
✨Showcase Your Risk Management Skills
Prepare examples of how you've conducted risk assessments and managed risk registers. Highlight specific instances where your actions led to improved security outcomes. This will demonstrate your hands-on experience and strategic thinking.
✨Engage with Security Tools
If you have experience with security tooling like vulnerability management or SIEM, be sure to mention it. Discuss how you've used these tools to enhance security measures, as this aligns perfectly with the role's requirements.
✨Communicate Clearly
Strong communication skills are essential for this role. Practice articulating complex security concepts in simple terms. This will help you connect with interviewers and show that you can effectively engage with stakeholders across the organisation.