Information Security Analyst

Information Security Analyst

Full-Time 39000 - 52000 £ / year (est.) No working from home possible
C

At a Glance

  • Tasks: Support day-to-day information security operations and collaborate with teams to secure infrastructure.
  • Company: Cifas, a leader in fraud prevention with a commitment to diversity and inclusion.
  • Benefits: Remote work, generous leave, private healthcare, and excellent pension package.
  • Other info: Agile working culture with opportunities for personal and professional growth.
  • Why this job: Make a real impact in cybersecurity while growing your skills in a supportive environment.
  • Qualifications: A Level education or equivalent, understanding of risk management, and relevant experience.

The predicted salary is between 39000 - 52000 £ per year.

We are looking for an Information Security Analyst to strengthen the Information Security team at Cifas. The successful applicant will report directly to the Director of Information Security and will be responsible for supporting the day-to-day information security operations. This is a hands-on role that will work with internal and external stakeholders to secure our infrastructure (including cloud) and other operational matters relating to information security, governance and cyber risk, ensuring alignment with organisational objectives and industry standards.

Key Responsibilities

  • Performing information security risk assessments of third parties, as part of the wider third-party risk management process and obtain assurance that they are protecting Cifas assets, as well providing assurance to members regarding information security.
  • Assisting the Information Security Manager (ISM) with the approach to security architecture, secure controls and assurance for our cloud-native production environment, working closely with our MSP’s and technology team, ensuring alignment to and enabling business objectives and Information Security strategy.
  • Supporting the implementation, maintenance and assurance of security controls across the corporate IT infrastructure aligning to business objectives and Information Security strategy.
  • Assisting the development of security policies, standards, and frameworks across the organisation, working with teams to influence embedding them into the business.
  • Supporting the business with InfoSec risk identification and treatment within the context of the latest threats, assist with regular risk assessments, threat modelling and identifying mitigation strategies.
  • Supporting the technical response to a security incident, as well as assisting with the development and testing of response plans.
  • Assisting with the delivery of relevant information security training & awareness material as part of a wider program designed to drive a culture of security awareness across the organisation.
  • Obtaining assurance data (KPI/KRI) for security controls and create regular high-quality reports for all levels of the business.

Skills, Knowledge and Expertise

  • An A Level education or equivalent qualification. Relevant experience acceptable.
  • An understanding of risk management practices and experience working within a risk culture.
  • Knowledge of key security frameworks (ISO 27001, NIST CSF, CIS Controls).
  • Experience performing third party security risk assessments.
  • Understanding of corporate security technologies (IAM, EDR, cloud security).
  • Experience of working within an incident response team.
  • An awareness of cloud security architecture principles and emerging threats.
  • Excellent communication skills, particularly in translating technical concepts for non-technical business stakeholders.
  • Proven problem solving and analysis abilities.
  • CISM, CISA, CRISC or other relevant information security certifications, an advantage.
  • A degree in a relevant subject e.g. Cyber Security would be advantageous.

Benefits

  • Remote working with approximately 2 days a month in the London office, although there will be a requirement to attend conventions, forums and events.
  • Generous annual leave, plus bank holidays.
  • Private healthcare.
  • Excellent pension package through salary sacrifice.
  • Personal and professional growth.
  • Employee wellbeing – Wellbeing breaks, wellbeing hub access including exercise programmes, meditation guides, sleep stories and yoga.

We have introduced agile ways of working, allowing teams to decide how best they work, while ensuring regular opportunities to collaborate and innovate. We create an environment to help you to unleash your potential and perform the most rewarding work of your career, whilst keeping your wellbeing at the foremost with initiatives in place to promote the wellness of our people. We are committed to building a diverse and inclusive culture and have dedicated inclusion champions across the business to celebrate and promote our uniqueness. We also have a dedicated team of volunteers looking for innovative ways to give back as part of our commitments under our Corporate Social Responsibility. And we’re delighted to be recognised in the 2021, 2022 & 2024 best companies to work for listings. We have also been awarded the Investors in People Gold accreditation.

If you are passionate about our purpose and would like an opportunity to make a valuable contribution to fraud prevention, we would like to hear from you.

Information Security Analyst employer: Cifas

Cifas is an exceptional employer, offering a dynamic work environment in London that prioritises employee wellbeing and professional growth. With generous benefits including private healthcare, an excellent pension package, and flexible remote working options, we foster a culture of collaboration and innovation while celebrating diversity and inclusion. Join us to make a meaningful impact in fraud prevention and enjoy a rewarding career with opportunities for personal development.

C

Contact Details:

Cifas Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Security Analyst

Tip Number 1

Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Prepare for interviews by researching the company and its security practices. Be ready to discuss how your skills align with their needs, especially around risk management and incident response. Show them you’re not just another candidate!

Tip Number 3

Practice your technical skills! Brush up on your knowledge of security frameworks like ISO 27001 and NIST CSF. Being able to talk confidently about these will set you apart from the competition.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who are genuinely interested in joining our team at Cifas.

We think you need these skills to ace Information Security Analyst

Information Security Risk Assessment
Third-Party Risk Management
Security Architecture
Cloud Security
Security Controls Implementation
Security Policies Development
Threat Modelling

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Information Security Analyst role. Highlight relevant experience and skills that match the job description, like risk assessments and security frameworks. We want to see how you can contribute to our team!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how your background aligns with our mission at Cifas. Keep it concise but impactful – we love a good story!

Showcase Your Skills:Don’t forget to showcase your technical skills and certifications in your application. Mention any experience with cloud security or incident response teams, as these are key for us. We’re looking for someone who can hit the ground running!

Apply Through Our Website:We encourage you to apply through our website for a smoother process. It helps us keep track of applications and ensures you don’t miss out on any important updates. Plus, it’s super easy – just a few clicks and you’re done!

How to prepare for a job interview at Cifas

Know Your Security Frameworks

Familiarise yourself with key security frameworks like ISO 27001 and NIST CSF. Be ready to discuss how these frameworks apply to the role and how you've used them in past experiences.

Showcase Your Risk Management Skills

Prepare examples of how you've performed risk assessments or managed third-party risks. Highlight your understanding of risk management practices and be ready to explain how you would approach risk identification and treatment.

Communicate Clearly

Practice translating technical concepts into layman's terms. The ability to communicate effectively with non-technical stakeholders is crucial, so think of examples where you've successfully done this in the past.

Demonstrate Your Problem-Solving Abilities

Be prepared to discuss specific incidents where you've had to respond to security threats or incidents. Share your thought process and the steps you took to resolve the issue, showcasing your analytical skills.