Security Governance Analyst in City of Westminster
Security Governance Analyst

Security Governance Analyst in City of Westminster

City of Westminster Full-Time 36000 - 60000 £ / year (est.) No home office possible
Go Premium
F

At a Glance

  • Tasks: Manage information security governance and support compliance initiatives at a prestigious London store.
  • Company: Join Fortnum & Mason, a historic brand in the heart of London.
  • Benefits: Enjoy competitive salary, generous discounts, 25 days holiday, and a subsidised staff restaurant.
  • Other info: Great opportunities for personal and professional growth in a supportive environment.
  • Why this job: Make a real impact on security while working in a vibrant, central location.
  • Qualifications: Experience with security frameworks and Microsoft infrastructure is essential.

The predicted salary is between 36000 - 60000 £ per year.

Our Head Office department is in the heart of Piccadilly and occupies the 5th & 6th floor of our beautiful flagship store. This central London location offers so much to explore including restaurants, bars, cultural sites, shopping and more, and only a short walk from the Green Park Tube Station and plenty of bus stops.

As a Technology Security Governance Analyst, you will support and manage elements of Fortnum & Mason Information Security Governance Framework.

Responsibilities

  • Own and manage the process for third party information security assurance to ensure that ongoing security assessments are undertaken and that contractual agreements reflect information security requirements.
  • Support information security awareness throughout the organisation including managing phishing awareness campaigns and delivering and supporting training and awareness to specific user groups.
  • Support management and investigation of any information security incidents including ensuring that incident logs are maintained, and any actions / lessons learned are addressed.
  • Support Fortnum & Mason's PCI compliance program including ensuring evidence of compliance is collated and maintained and undertaking audit checks within stores.
  • Manage the process for Information Security Risk Management to ensure that all information security risks are owned and documented and remediated to an agreed and accepted level.
  • Support the process for project engagements to ensure that Information Security requirements are defined for each project, Architectural design documents are reviewed to ensure appropriate controls are in place and testing and acceptance processes are in place to ensure that agreed controls have been implemented.
  • Serve as a hands-on Security Analyst, proactively identifying opportunities for improvement and delivering security enhancements to our systems.
  • Understanding of server hardware, hypervisors, virtual machines, operating systems, Microsoft services, including Intune, Entra, Office365, Azure, SQL Server, SCCM, and File & Directory services.
  • Collaborate with partners to ensure the security of the Cisco Meraki network, taking an initiative-taking stance in mitigating risks and initiative-taking patch management.
  • Assist with internal and external vulnerability assessments, working with security partners to maintain PCI DSS compliance, overcome security challenges, and drive continuous improvements aligned to the NIST framework/ISO271002 standards.
  • Report and review our secure device imaging using Microsoft Intune & Autopilot, ensuring a standardised, scalable, and resilient set-up for retail, hospitality POS, and all corporate end-user devices.
  • Effectively operate security tooling reporting against our SIEM platform, endpoint protection solutions, and identity access controls, reviewing automated threat detection and forensic incident response to protect critical infrastructure and services.
  • Create and manage security policy documentation, assist with security procedures, and train our internal teams and wider retail staff.
  • Undertake disaster recovery planning, ensuring business continuity and resilience against potential disruptions.
  • Work proactively alongside support, application, and transformation teams, fostering collaboration and communicating security procedures and policies.
  • Deliver concise, well-structured documentation, providing clarity for teams and enabling rapid adoption of security best practices.
  • Function as a trusted advisor, recognised as the go-to subject matter expert for security, and bridging the gap between end-users and the infrastructure and security team.
  • Guide and support third-party engagements, ensuring vendors align with enterprise security standards, compliance requirements, and best practices.
  • Educate and empower both internal teams and the broader business, fostering a security-first culture and promoting best practices in security and business continuity.

Qualifications

  • Experience with security and compliance standards frameworks such as ISO 27001, ISO 22301, GDPR, PCI-DSS, NIST, and ACPO guidelines.
  • Understanding of UK legal frameworks including the Data Protection Act and Computer Misuse Act.
  • Understanding of Microsoft infrastructure including Windows Server Administration, Active Directory AAD Administration, Group Policy, Microsoft 365 services and Azure Cloud resource management.
  • Proficiency in Microsoft SQL Server.
  • PowerShell scripting skills.
  • Identity & Access Management (IAM) expertise, including Microsoft Entra ID (formerly Azure AD), role-based access control (RBAC), and multi-factor authentication (MFA).
  • Cloud security experience securing Azure environments, including Microsoft Defender for Cloud, Sentinel, and compliance frameworks such as PCI-DSS.
  • Threat protection and incident response capabilities: ability to identify vulnerabilities, implement threat protection, and respond to security incidents.
  • Patch management and endpoint security knowledge: understanding of patching, importance of regular updates, and endpoint protection across Windows and Azure environments.
  • Familiarity with backup and disaster recovery tools and practices.
  • Phishing awareness tools and ability to create training for end-users on security best practices.

Benefits

  • Competitive salary.
  • A generous store and restaurant discount of up to 40%.
  • 25 days holidays (excluding bank holidays) and an extra day off for your birthday.
  • A fantastic subsidised staff restaurant which uses Fortnum's ingredients.
  • A range of opportunities to develop and grow personally and professionally.
  • Excellent pension scheme.

Security Governance Analyst in City of Westminster employer: Fortnum & Mason

Fortnum & Mason is an exceptional employer, offering a vibrant work culture in the heart of London, where employees can enjoy a rich array of cultural experiences just steps away from the office. With a strong focus on professional development, competitive benefits including generous discounts and a robust pension scheme, and a commitment to fostering a security-first mindset, this role as a Security Governance Analyst provides a meaningful opportunity to contribute to the company's esteemed legacy while growing your career in a supportive environment.
F

Contact Detail:

Fortnum & Mason Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Security Governance Analyst in City of Westminster

✨Tip Number 1

Network like a pro! Get out there and connect with people in the industry. Attend events, join online forums, or even hit up LinkedIn. The more people you know, the better your chances of landing that Security Governance Analyst role.

✨Tip Number 2

Show off your skills! When you get the chance to chat with potential employers, make sure to highlight your experience with security frameworks like ISO 27001 and PCI-DSS. Be ready to discuss how you've tackled security challenges in the past.

✨Tip Number 3

Prepare for interviews by brushing up on your technical knowledge. Make sure you're comfortable discussing Microsoft infrastructure, threat protection, and incident response. We want you to feel confident when answering those tricky questions!

✨Tip Number 4

Don't forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, we love seeing candidates who are genuinely interested in joining our team at Fortnum & Mason.

We think you need these skills to ace Security Governance Analyst in City of Westminster

Information Security Governance
Third Party Information Security Assurance
Phishing Awareness Campaigns
Incident Management
PCI Compliance
Information Security Risk Management
Project Engagements
Security Enhancements
Server Hardware Understanding
Microsoft Intune
Azure Cloud Resource Management
Vulnerability Assessments
ISO 27001
PowerShell Scripting
Identity & Access Management (IAM)

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the Security Governance Analyst role. Highlight relevant experience and skills that match the job description, especially around information security frameworks and compliance standards.

Craft a Compelling Cover Letter: Your cover letter should tell us why you're the perfect fit for this role. Share specific examples of your past experiences that relate to the responsibilities listed in the job description, and show your enthusiasm for working with us at Fortnum & Mason.

Showcase Your Technical Skills: Don’t forget to highlight your technical skills! Mention your experience with Microsoft services, security tools, and any relevant certifications. This will help us see how you can contribute to our team right from the start.

Apply Through Our Website: We encourage you to apply through our website for a smoother application process. It’s the best way for us to receive your application and ensures you don’t miss out on any important updates from our team!

How to prepare for a job interview at Fortnum & Mason

✨Know Your Security Standards

Familiarise yourself with key security frameworks like ISO 27001, PCI-DSS, and NIST. Be ready to discuss how these standards apply to the role and share examples of how you've implemented them in past experiences.

✨Showcase Your Technical Skills

Brush up on your knowledge of Microsoft services, especially Azure and SQL Server. Be prepared to explain how you've used tools like PowerShell for scripting or managed identity access controls in previous roles.

✨Prepare for Scenario Questions

Expect questions that ask you to solve hypothetical security incidents or manage compliance issues. Think through your approach to risk management and incident response, and be ready to articulate your thought process clearly.

✨Demonstrate Your Communication Skills

As a Security Governance Analyst, you'll need to communicate complex security concepts to non-technical teams. Practice explaining technical terms in simple language and think of examples where you've successfully trained others on security best practices.

Security Governance Analyst in City of Westminster
Fortnum & Mason
Location: City of Westminster
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>