At a Glance
- Tasks: Join a dynamic team to assess and enhance information security controls and compliance.
- Company: Be part of a leading employee-owned enterprise in the global insurance sector.
- Benefits: Enjoy a competitive salary, life insurance, medical benefits, and a fully remote work environment.
- Why this job: Contribute to impactful security initiatives while growing your skills in a supportive, high-trust team.
- Qualifications: No specific experience required; knowledge of security regulations is a plus.
- Other info: This role is crucial for the company's ambitious InfoSec growth plans.
The predicted salary is between 46000 - 60000 £ per year.
Upto £57,500 + Enterprise Benefits (Life Ins/Medical/Pension) Fully Remote (UK only)
Part of their high growth InfoSec plans as they build the team to x4. Cloud Decisions have partnered with one of the UK’s most exciting enterprise technology transformations: a multi-billion, employee-owned group, one of the top 10 largest employee-owned businesses in the UK, and one of the largest global players in insurance across 100+ countries.
Following a wave of acquisitions and continued digital modernisation and compliance, they’re hiring an Information Security Assurance Analyst who understands the Controls & Compliance with security regulations and standards and is able to work autonomously while they build their InfoSec capability to ensure regulatory compliance, information security maturity, and readiness for the next audit, tender or risk review.
Control/Compliance Assessment Duties:- Schedule and Coordinate Assessments: Schedule and coordinate control assessments with control owners, asset custodians, and third parties.
- Evaluate Controls: Assess the design and effectiveness of technical and non-technical security controls against internal policies, standards, and procedures.
- Documentation Maintenance: Maintain up-to-date documentation of security control assessments and remediation activities.
- Organise Control Evidence: Ensure all control evidence is well-organised and accessible.
- Notify Deviations: Author notifications of business process and procedure deviations to inform the Information Security team and other relevant parties across the organisation.
- Risk Analysis Reports: Author analysis reports that define the impact of control deficiencies or gaps on identified risks.
- Communicate Findings: Communicate findings to Security leadership, clearly describing issues identified from analysis.
- Dashboard and Reporting Input: Provide input to ensure dashboards and reporting databases are up to date with current details.
Provide support to data and/or process owners in formally documenting the security requirements for information systems, applications, and services. This includes assisting with the scoping, selection and documentation of appropriate cybersecurity and privacy controls, testing their design and implementation, following a formal authorisation process, and establishing mechanisms for ongoing monitoring and oversight of controls.
Compliance/Control Improvement Duties:- Update Processes: Initiate and coordinate the process to update identified business process breaks/gaps.
- Enhance Procedures: Assist in the documentation, design, and enhancement of procedures, and develop operating effectiveness tests with control owners.
- Propose Enhancements: Propose enhancements to existing controls and procedures through a formal reporting structure.
- Reporting Support: Assist in monthly and quarterly reporting on the status and outcomes of control assessment activities.
- Third-Party Due Diligence: Manage third-party due diligence requests from customers and insurers, ensuring accurate and timely responses. Document and report deficiencies and serve as the primary liaison to resolve actions within agreed timescales.
- Audit Preparation and Support: Prepare for and assist with internal and external audits by collecting evidence, responding to audit requests, and addressing audit findings.
- Continuous Improvement: Identify opportunities for process improvements and implement changes to enhance the efficiency and effectiveness of control assessments.
- Training and Development: Assist in training team members and stakeholders on control assessment methodology and assessment best practices.
- Vendor Management: Ensure critical vendors have robust BCDR plans and conduct regular assessments. Conduct regular assessments of vendor BCDR capabilities.
Any knowledge of the Information Security impact requirements of DORA, PCDSS, SARBOX are all of great interest but not essential.
Information Security Analyst (United Kingdom) employer: Cloud Decisions
Contact Detail:
Cloud Decisions Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Information Security Analyst (United Kingdom)
✨Tip Number 1
Familiarise yourself with the specific compliance regulations and standards mentioned in the job description, such as DORA, PCDSS, and SARBOX. Understanding these frameworks will not only help you in interviews but also demonstrate your proactive approach to the role.
✨Tip Number 2
Network with professionals in the information security field, especially those who have experience in compliance and control assessments. Engaging with industry peers can provide valuable insights and potentially lead to referrals for the position.
✨Tip Number 3
Prepare to discuss your experience with risk analysis and reporting during interviews. Be ready to share specific examples of how you've communicated findings to leadership and contributed to audit preparations in previous roles.
✨Tip Number 4
Showcase your ability to work autonomously and as part of a high-trust team. Highlight any past experiences where you successfully managed projects independently or collaborated effectively with small teams to achieve compliance goals.
We think you need these skills to ace Information Security Analyst (United Kingdom)
Some tips for your application 🫡
Understand the Role: Before applying, make sure to thoroughly read the job description for the Information Security Analyst position. Understand the key responsibilities and required skills, such as compliance with security regulations and the ability to work autonomously.
Tailor Your CV: Customise your CV to highlight relevant experience in information security, compliance assessments, and risk analysis. Use specific examples that demonstrate your ability to evaluate controls and communicate findings effectively.
Craft a Compelling Cover Letter: Write a cover letter that showcases your passion for information security and your understanding of the company's goals. Mention any relevant certifications or experiences that align with the role's requirements, and express your enthusiasm for contributing to their InfoSec plans.
Proofread Your Application: Before submitting your application, carefully proofread all documents for spelling and grammatical errors. A polished application reflects attention to detail, which is crucial in the field of information security.
How to prepare for a job interview at Cloud Decisions
✨Understand the Role
Make sure you have a solid grasp of what an Information Security Analyst does, especially in relation to compliance and control assessments. Familiarise yourself with the specific duties mentioned in the job description, such as evaluating controls and maintaining documentation.
✨Showcase Your Experience
Prepare to discuss your previous experience with security regulations and standards. Be ready to provide examples of how you've assessed controls or managed compliance in past roles, as this will demonstrate your capability to handle the responsibilities of the position.
✨Communicate Clearly
Since the role involves communicating findings to security leadership, practice articulating complex information in a clear and concise manner. You might be asked to explain technical concepts, so being able to simplify these for non-technical stakeholders is key.
✨Ask Insightful Questions
Prepare thoughtful questions about the company's InfoSec plans and team dynamics. This shows your genuine interest in the role and helps you assess if the company culture aligns with your values, especially since they emphasise a high-trust team environment.