Senior Information Security Analyst (ISMS Management)
Senior Information Security Analyst (ISMS Management)

Senior Information Security Analyst (ISMS Management)

Full-Time 60000 - 75000 £ / year (est.) No home office possible
BMLL Technologies

At a Glance

  • Tasks: Manage and improve our Information Security Management System while ensuring compliance with industry standards.
  • Company: Join BMLL, a leading provider of historical data and analytics in a collaborative culture.
  • Benefits: Enjoy competitive salary, 25 days holiday, remote work options, and a well-being budget.
  • Other info: Inclusive workplace with regular team lunches, social activities, and excellent career growth opportunities.
  • Why this job: Make a real impact on security practices and grow into an Information Security Manager role.
  • Qualifications: 3-5 years in Information Security with ISO 27001 experience and strong communication skills.

The predicted salary is between 60000 - 75000 £ per year.

About BMLL: BMLL is the leading independent provider of harmonised Level 3, 2 and 1 historical data and analytics across global equities, ETFs, futures and US equity options. We provide market participants with immediate access to granular T+1 order book data and advanced analytics, enabling them to accelerate research, optimise trading strategies, and better understand market behaviour. BMLL was acquired in 2025 by Nordic Capital, alongside minority shareholder Optiver, marking a joint commitment to accelerate the company's next phase of growth. We offer an inclusive and collaborative culture, a hybrid working environment that includes regular days in our London office, weekly team lunches, and a variety of out-of-hours social activities.

About the role: We are seeking a Senior Information Security Analyst to support and operate the organisation's Information Security Management System (ISMS), aligned to ISO/IEC 27001:2022, NIST CSF, and regulatory requirements (e.g. GDPR, DORA). This is a hands‑on GRC-focused role responsible for the day‑to‑day operation and continuous improvement of the ISMS, working closely with the Head of Information Security. The role is ideal for a candidate looking to develop into an Information Security Manager / ISO role.

Key Responsibilities

  • ISMS & Governance
    • Operate and maintain the ISMS in line with ISO 27001:2022
    • Maintain policies, standards, and procedures
    • Manage and update the Statement of Applicability (SoA)
    • Track control implementation aligned to ISO Annex A
    • Prepare audit artefacts and support internal and external audits
    • Support management reviews and reporting
  • Risk Management
    • Maintain the information security risk register
    • Conduct risk assessments and treatment planning
    • Track remediation actions and risk acceptance
    • Align controls to ISO 27001, NIST CSF, and regulatory frameworks
  • Security Assurance & Operations
    • Support vulnerability management and remediation tracking
    • Assist with security incident triage and coordination
    • Validate security controls across cloud (AWS) and SaaS platforms
    • Work with engineering teams to embed security best practices
  • Third-Party Risk Management (TPRM)
    • Conduct supplier security assessments and due diligence
    • Maintain third-party and AI risk registers
    • Support DPIAs and data protection reviews
    • Track supplier risks and remediation actions
  • Compliance & Customer Assurance
    • Support client due diligence responses (DDQs, SIG, VSA)
    • Maintain audit evidence and documentation
    • Support compliance with GDPR, ISO 27001, and DORA
  • Business Continuity & Resilience
    • Support Business Impact Analysis (BIA)
    • Assist with disaster recovery testing
    • Contribute to resilience and BCM improvements
  • Security Awareness
    • Support delivery of security awareness and training programmes
    • Promote a strong security culture across the organisation

Requirements

Essential

  • 3‑5+ years in Information Security, GRC, or ISMS roles
  • Experience supporting or operating an ISO 27001 ISMS
  • Strong understanding of risk management and control frameworks
  • Familiarity with cloud environments (AWS preferred)
  • Experience supporting audits and supplier assessments
  • Strong communication and documentation skills

Desirable

  • Exposure to ISO 22301, NIST CSF, or DORA
  • Experience with security tooling (e.g. vulnerability management, EDR, SIEM)
  • Understanding of DevSecOps / CI/CD security
  • Aware of AI governance and data protection controls

Qualifications

  • ISO 27001 Lead Implementer / Auditor (preferred)
  • CISM, CISSP, or equivalent (or working towards)

Key skills:

  • Detail‑oriented with strong audit discipline
  • Structured, process‑driven approach
  • Ability to manage multiple priorities
  • Strong stakeholder engagement skills
  • Pragmatic, risk‑based mindset

Benefits

  • Competitive salary
  • 25 days holiday plus bank holidays
  • Discretionary Bonus
  • Pension Scheme
  • Private Medical Insurance
  • Work remotely abroad for up to 40 business days each year
  • Life Insurance
  • Childcare Nursery Scheme
  • Combination of remote and London‑based office working, with 2 days in the office per week.
  • A yearly Well‑being Physical Activity budget
  • Continuous learning through funded training and challenging projects
  • Collaborative culture
  • Weekly team lunches
  • Free Fruit, snacks, and drinks provided throughout the day (When office‑based)
  • Regular Team Socials
  • Cycle to Work Scheme

We are an inclusive employer and welcome applicants from all backgrounds. We pride ourselves on our commitment to Equality and Diversity. We are committed to removing barriers throughout our hiring process. If you have any special requirements or require reasonable adjustments to help you access career opportunities at BMLL, please do let us know at careers@bmlltech.com.

Senior Information Security Analyst (ISMS Management) employer: BMLL Technologies

BMLL is an exceptional employer, offering a dynamic and inclusive work culture that fosters collaboration and innovation. With a hybrid working model based in London, employees enjoy competitive benefits such as a generous holiday allowance, private medical insurance, and opportunities for continuous learning and professional growth. The company prioritises employee well-being through regular team lunches, social activities, and a supportive environment that encourages career advancement in the field of information security.
BMLL Technologies

Contact Detail:

BMLL Technologies Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Senior Information Security Analyst (ISMS Management)

✨Tip Number 1

Network like a pro! Reach out to current or former employees at BMLL on LinkedIn. A friendly chat can give you insider info and maybe even a referral, which can really boost your chances.

✨Tip Number 2

Prepare for the interview by brushing up on ISO 27001 and risk management frameworks. We want to see that you know your stuff, so be ready to discuss how you've applied these in past roles.

✨Tip Number 3

Show off your soft skills! Communication is key in this role, so think of examples where you've effectively engaged with stakeholders or led a team through a security challenge.

✨Tip Number 4

Don't forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you're genuinely interested in joining our team.

We think you need these skills to ace Senior Information Security Analyst (ISMS Management)

Information Security Management System (ISMS)
ISO/IEC 27001:2022
NIST CSF
GDPR
Risk Management
Cloud Security (AWS)
Vulnerability Management
Security Incident Response
Third-Party Risk Management (TPRM)
Audit Support
Strong Communication Skills
Documentation Skills
Business Continuity Management (BCM)
Security Awareness Training
Stakeholder Engagement

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the Senior Information Security Analyst role. Highlight your experience with ISO 27001 and any relevant GRC or ISMS roles you've held. We want to see how your skills align with what we're looking for!

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how your background makes you a great fit for our team. Don't forget to mention your familiarity with cloud environments like AWS!

Show Off Your Communication Skills: Strong communication is key in this role, so make sure your application reflects that. Whether it's your CV, cover letter, or any additional documents, keep your language clear and professional. We love a well-structured application!

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets to us quickly and efficiently. Plus, you'll find all the details you need about the role and our company culture there!

How to prepare for a job interview at BMLL Technologies

✨Know Your Standards

Familiarise yourself with ISO/IEC 27001:2022 and NIST CSF. Be ready to discuss how you've applied these standards in your previous roles, especially in managing ISMS. This shows you’re not just knowledgeable but also practical in your approach.

✨Showcase Your Risk Management Skills

Prepare examples of how you've conducted risk assessments and managed risk registers. Highlight specific instances where your actions led to improved security outcomes. This will demonstrate your hands-on experience and understanding of risk management frameworks.

✨Engage with the Team Culture

BMLL values collaboration and inclusivity, so be sure to express your enthusiasm for team dynamics. Share experiences where you’ve worked effectively in a team setting, particularly in security awareness or incident response scenarios.

✨Ask Insightful Questions

Prepare thoughtful questions about BMLL's current security challenges or their approach to third-party risk management. This not only shows your interest in the role but also your proactive mindset in wanting to contribute to their security culture.

Senior Information Security Analyst (ISMS Management)
BMLL Technologies

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>