At a Glance
- Tasks: Manage and improve our Information Security Management System while ensuring compliance with key regulations.
- Company: Join a forward-thinking tech company committed to security and inclusivity.
- Benefits: Enjoy competitive salary, 25 days holiday, remote work options, and wellness budgets.
- Why this job: Step into a pivotal role that shapes security practices and drives your career forward.
- Qualifications: 3-5 years in Information Security with ISO 27001 experience preferred.
- Other info: Collaborative culture with regular team socials and continuous learning opportunities.
The predicted salary is between 60000 - 75000 ÂŁ per year.
We are seeking a Senior Information Security Analyst to support and operate the organisation’s Information Security Management System (ISMS), aligned to ISO/IEC 27001:2022, NIST CSF, and regulatory requirements such as GDPR and DORA. This hands‑on GRC‑focused role involves day‑to‑day operation and continuous improvement of the ISMS, working closely with the Head of Information Security. It is ideal for a candidate who wants to progress into an Information Security Manager or ISO leadership position.
Key Responsibilities
- ISMS & Governance
- Operate and maintain the ISMS in line with ISO 27001:2022.
- Maintain policies, standards and procedures.
- Manage and update the Statement of Applicability (SoA).
- Track control implementation aligned to ISO Annex A.
- Prepare audit artefacts and support internal and external audits.
- Support management reviews and reporting.
- Risk Management
- Maintain the information‑security risk register.
- Conduct risk assessments and treatment planning.
- Track remediation actions and risk acceptance.
- Align controls to ISO 27001, NIST CSF and regulatory frameworks.
- Security Assurance & Operations
- Support vulnerability management and remediation tracking.
- Assist with security incident triage and coordination.
- Validate security controls across cloud (AWS) and SaaS platforms.
- Work with engineering teams to embed security best practices.
- Third‑Party Risk Management (TPRM)
- Conduct supplier security assessments and due diligence.
- Maintain third‑party and AI risk registers.
- Support DPIAs and data‑protection reviews.
- Track supplier risks and remediation actions.
- Compliance & Customer Assurance
- Support client due‑diligence responses (DDQs, SIG, VSA).
- Maintain audit evidence and documentation.
- Support compliance with GDPR, ISO 27001 and DORA.
- Business Continuity & Resilience
- Support Business Impact Analysis (BIA).
- Assist with disaster recovery testing.
- Contribute to resilience and BCM improvements.
- Security Awareness
- Support delivery of security awareness and training programmes.
- Promote a strong security culture throughout the organisation.
Requirements
- Essential
- 3–5+ years in Information Security, GRC, or ISMS roles.
- Experience supporting or operating an ISO 27001 ISMS.
- Strong understanding of risk‑management and control frameworks.
- Familiarity with cloud environments (AWS preferred).
- Experience supporting audits and supplier assessments.
- Strong communication and documentation skills.
- Desirable
- Exposure to ISO 22301, NIST CSF or DORA.
- Experience with security tooling (e.g. vulnerability management, EDR, SIEM).
- Understanding of DevSecOps / CI/CD security.
- Awareness of AI governance and data‑protection controls.
Qualifications
- ISO 27001 Lead Implementer / Auditor (preferred).
- CISM, CISSP or equivalent (or working toward).
Key Skills
- Detail‑oriented with strong audit discipline.
- Structured, process‑driven approach.
- Ability to manage multiple priorities.
- Strong stakeholder engagement skills.
- Pragmatic, risk‑based mindset.
Benefits
- Competitive salary.
- 25 days holiday plus bank holidays.
- Discretionary bonus.
- Pension scheme.
- Private medical insurance.
- Work remotely abroad for up to 40 business days each year.
- Life insurance.
- Childcare nursery scheme.
- Combination of remote and London‑based office working, with 2 days in the office per week.
- Year‑long well‑being physical‑activity budget.
- Continuous learning through funded training and challenging projects.
- Collaborative culture.
- Weekly team lunches.
- Free fruit, snacks and drinks provided throughout the day (when office‑based).
- Regular team socials.
- Cycle‑to‑work scheme.
We are an inclusive employer and welcome applicants from all backgrounds. We pride ourselves on our commitment to Equality and Diversity and are committed to removing barriers throughout our hiring process. If you have any special requirements or require reasonable adjustments to help you access career opportunities at BMLL, please let us know at careers@bmlltech.com.
Senior Information Security Analyst (ISMS Management) employer: BMLL
Contact Detail:
BMLL Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Information Security Analyst (ISMS Management)
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect on LinkedIn. We all know that sometimes it’s not just what you know, but who you know that can help you land that Senior Information Security Analyst role.
✨Tip Number 2
Prepare for those interviews by brushing up on your knowledge of ISO 27001 and NIST CSF. We recommend doing mock interviews with friends or using online platforms to get comfortable discussing your experience and how it aligns with the job description.
✨Tip Number 3
Showcase your hands-on experience! When you get the chance to chat with potential employers, highlight specific projects where you’ve operated or improved an ISMS. We want to see your practical skills in action!
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who are proactive about their job search. Let’s get you that dream role!
We think you need these skills to ace Senior Information Security Analyst (ISMS Management)
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Senior Information Security Analyst role. Highlight your experience with ISO 27001 and any relevant GRC roles. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how your background makes you a great fit for our team. Keep it concise but impactful!
Showcase Your Achievements: When detailing your experience, focus on specific achievements rather than just duties. Did you improve a process or lead a successful audit? We love to see quantifiable results that demonstrate your impact!
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, it shows us you're keen on joining our awesome team at StudySmarter!
How to prepare for a job interview at BMLL
✨Know Your Standards
Make sure you’re well-versed in ISO/IEC 27001:2022, NIST CSF, and GDPR. Brush up on the key principles and how they apply to the role. Being able to discuss these frameworks confidently will show that you’re not just familiar with them, but that you can actively contribute to the ISMS.
✨Showcase Your Experience
Prepare specific examples from your past roles where you’ve successfully managed ISMS or conducted risk assessments. Use the STAR method (Situation, Task, Action, Result) to structure your answers. This will help you demonstrate your hands-on experience and problem-solving skills effectively.
✨Engage with Security Culture
Be ready to discuss how you’ve promoted security awareness in previous positions. Share any initiatives you’ve led or participated in that fostered a strong security culture. This shows that you understand the importance of security beyond just compliance.
✨Ask Insightful Questions
Prepare thoughtful questions about the company’s current ISMS challenges or future goals. This not only shows your interest in the role but also your proactive mindset. It’s a great way to demonstrate that you’re already thinking about how you can add value to their team.