At a Glance
- Tasks: Track and manage information security compliance and audit findings across multiple jurisdictions.
- Company: Join Chaucer, a leading insurance group at Lloyd’s with a global presence.
- Benefits: Flexible working arrangements, career development opportunities, and a diverse workplace culture.
- Other info: Gain exposure to ISO 27001 certification and international regulatory engagements.
- Why this job: Make a real impact in information security while building a rewarding career.
- Qualifications: Organised, persistent, and comfortable holding others accountable; experience in GRC is a plus.
The predicted salary is between 45000 - 55000 £ per year.
The Information Security Governance Risk and Compliance Analyst sits within the corporate Information Security team, which is led by the Information Security Officer and operates within the COO organisation. The team is independent of the compliance, risk, and IT functions. This role reports to the Head of Information Security Governance Risk and Compliance and exists to keep information security audit findings, compliance deliverables, and regulatory commitments moving forward - tracking open items, chasing action owners, and making sure the information security function meets its obligations across audit and compliance workstreams.
The role will work across ISO 27001 audits, penetration tests, and tabletop exercises - making sure findings have owners, owners have deadlines, and deadlines are met. On the compliance side, it will coordinate information security's inputs to Lloyd's Principles Based Oversight (PBO), DORA, GDPR, and regulatory engagements with international supervisors including the Monetary Authority of Singapore, Central Bank of Ireland, and Dubai Financial Services Authority.
This is a mid-level role with room to grow. A successful candidate does not need to have done everything on this list before, but does need to be organised, persistent, and comfortable holding people to account.
Key Responsibilities- Track and drive remediation of all information security-related findings from internal audits, ISO 27001 audits, penetration tests, and tabletop exercises. Maintain accurate registers, hold action owners to deadlines, and escalate slippage.
- Act as the primary information security point of contact for the compliance function across Lloyd's PBO (particularly cyber resilience within the operational resilience pillar), DORA, and GDPR.
- Coordinate information security evidence and inputs for regulatory engagements across multiple jurisdictions, including MAS, CBI, and DFSA.
- Chase and track all information security compliance deliverables, making sure requests from regulators, compliance, and audit are answered accurately and on time.
- Prepare progress updates on open findings, compliance deliverables, and regulatory action items for stakeholders.
- Support the Head of Information Security Governance Risk and Compliance with GRC tooling, tracking, and reporting - producing metrics that give clear visibility of where things stand.
- Build solid working relationships with action owners, compliance, risk, and audit so that chasing things down does not become adversarial.
- Experience in Information Security GRC, IT audit, IT risk, or compliance coordination - ideally in insurance, reinsurance, or the Lloyd's market.
- Familiarity with ISO 27001 and how audit finding remediation works in practice.
- Working knowledge of regulatory regimes relevant to the London market such as Lloyd's PBO and DORA. Experience with international financial regulators is a plus.
- Strong organisational skills - able to track a high volume of open items, deadlines, and dependencies across multiple workstreams without losing grip.
- Clear communicator, written and verbal. Able to produce concise status updates and engage constructively with people at all levels.
- Comfortable working across teams - information security, compliance, audit, and business stakeholders all need to see the role holder as someone who makes their life easier, not harder.
- Experience with GRC platforms or tracking tools and the ability to pull useful reporting from them is a plus.
Audit findings and regulatory commitments do not close themselves. Without someone actively tracking and chasing, items age, deadlines slip, and risk accumulates without anyone noticing until it becomes a problem. This role stops that from happening. In a Lloyd's market business with regulatory obligations spanning multiple jurisdictions, having someone who owns the tracking and coordination of Information Security GRC activity is not optional.
This is also a strong development role. The successful candidate will get direct exposure to ISO 27001 certification, Lloyd's PBO, DORA, international regulatory engagement, and the full audit lifecycle - with the Head of Information Security Governance Risk and Compliance providing direction and support. It is a good role for someone who wants to build a career in this space and is willing to put the work in.
ABOUT USChaucer is a leading insurance group at Lloyd’s, the world’s specialist insurance market. We help protect industries around the world from the risks they face. Our customers include major airlines, energy companies, shipping groups, global manufacturers and property groups.
Our headquarters are in London, and we have international offices in Bermuda, Copenhagen, Dubai and Singapore to be closer to our clients across the world. To learn more about us please visit our website.
Chaucer is committed to diversity, actively values difference and respects people regardless of the protected characteristics which are outlined in the Equality Act 2010 (UK legislation) as a result of the Equal Treatment Directive 2006 (EU legislation). A diverse workforce and an inclusive workplace are core to our success as a business and integral to our winning strategy and culture. We recruit from the widest available pool of talent, and our hiring, assessment and selection process is fair, free from bias and one which ensures we select the right person for the job, based on merit. We are committed to promoting a culture that actively values difference, and recognises that everyone has the right to be treated with dignity and respect throughout their employment.
We are open to considering flexible working arrangements for all roles and encourage you to outline your needs during the interview process.
Information Security GRC Analyst in London employer: Chaucer Underwriting Services
Chaucer is an exceptional employer, offering a dynamic work environment in the heart of London where you can thrive as an Information Security GRC Analyst. With a strong commitment to employee growth, you will gain invaluable exposure to ISO 27001 certification and international regulatory engagements, all while being part of a diverse and inclusive culture that values your contributions. The company promotes flexible working arrangements, ensuring a healthy work-life balance as you collaborate with talented professionals across various teams.
Contact Details:
Chaucer Underwriting Services Recruitment Team
StudySmarter Expert Advice🤫
We think this is how you could land Information Security GRC Analyst in London
✨Join Compliance Communities
Get involved in compliance and risk communities — both online and offline. Look for forums, LinkedIn groups, or even local meetups where compliance pros hang out. You never know who might drop a job opportunity your way!
✨Attend Industry Conferences
Keep an eye out for compliance and risk management conferences and workshops in your area. These events are a goldmine for networking, and they often have job boards or recruiters on-site looking for new talent. Plus, it’s a chance to learn what's trending in the field.
✨Leverage Your University Career Services
If you’ve recently graduated or are still studying, head over to your university's career services. Many companies, including those in compliance, actively recruit fresh talent through these services, so make sure you tap into that resource.
✨Showcase Your Knowledge Online
Start writing articles or blog posts about compliance topics that interest you. Share them on platforms like LinkedIn to demonstrate your knowledge and passion. This not only builds your presence in the field but can also catch the attention of companies like Chaucer Underwriting Services looking for candidates who are engaged and informed.
We think you need these skills to ace Information Security GRC Analyst in London
Some tips for your application 🫡
Show Your Understanding of Compliance:In the compliance-risk field, it's super important to showcase your understanding of regulations and risk management frameworks. Highlight any relevant coursework, certifications (like ICA or AML), or even projects that demonstrate your knowledge and commitment to this area. We want to see how you can navigate this complex landscape!
Quantify Your Achievements:When detailing your experience, try to quantify your achievements. For example, if you've previously worked on a project that improved compliance metrics or reduced risk exposure, give us the numbers! This data-driven approach really stands out to hiring managers in compliance-risk roles.
Tailor Your CV to Reflect Relevant Skills:Make sure your CV highlights skills that are particularly relevant to compliance, like attention to detail, analytical thinking, and report writing. Ensure these are easy to spot – consider using bullet points to break down your responsibilities and achievements for maximum impact!
Craft a Motivating Cover Letter:In your cover letter, let us know why you’re excited about the compliance-risk role at Chaucer Underwriting Services. Share what motivates you about compliance, and how you believe you can contribute to our mission. This is your chance to showcase not only your skills but also your passion for this important field!
How to prepare for a job interview at Chaucer Underwriting Services
✨Master the Regulations
Brush up on key compliance regulations relevant to the industry you're applying to. Familiarising yourself with specific laws and frameworks used in your field will give you an edge during technical questions. Show that you’re not just aware of them but can also apply them—think real-life scenarios!
✨Show Your Analytical Skills
Compliance roles really focus on analytical skills, so be prepared for case studies or situational questions during the interview. We've got to demonstrate how we approach risk assessments or compliance audits, possibly drawing on examples from past experiences or university projects. Bring some thoughtful case scenarios to discuss!
✨Know Your Tools
Get comfortable with commonly used compliance software and tools. Familiarity with platforms like RSA or MetricStream can really impress during your interview, as it shows you're ready to hit the ground running. If you’ve had any experience with them, make sure to highlight that!
✨Align with Company Culture
Since it's a full-time position, show your long-term commitment and interest in the company’s mission and values. Dive into how your ethics and professional philosophy align with Chaucer Underwriting Services’s stance on compliance. A shared vision can really resonate with interviewers looking for fit as much as skill!