At a Glance
- Tasks: Manage information security governance and support compliance across the organisation.
- Company: Join Fortnum & Mason, a prestigious brand in a vibrant central London location.
- Benefits: Enjoy competitive salary, generous discounts, 25 days holiday, and career development opportunities.
- Why this job: Be a key player in enhancing security and making a real impact in a historic company.
- Qualifications: Experience with security frameworks and Microsoft infrastructure is essential.
- Other info: Work in a collaborative environment that values diversity and personal growth.
The predicted salary is between 36000 - 60000 £ per year.
Our Head Office department is in the heart of Piccadilly and occupies the 5th & 6th floor of our beautiful flagship store. This central London location offers so much to explore including restaurants, bars, cultural sites, shopping and more, and only a short walk from the Green Park Tube Station and plenty of bus stops.
As a Technology Security Governance Analyst, you will support and manage elements of Fortnum & Mason Information Security Governance Framework.
Responsibilities- Own and manage the process for third party information security assurance to ensure that ongoing security assessments are undertaken and that contractual agreements reflect information security requirements.
- Support information security awareness throughout the organisation including managing phishing awareness campaigns and delivering and supporting training and awareness to specific user groups.
- Support management and investigation of any information security incidents including ensuring that incident logs are maintained, and any actions / lessons learned are addressed.
- Support Fortnum & Mason's PCI compliance program including ensuring evidence of compliance is collated and maintained and undertaking audit checks within stores.
- Manage the process for Information Security Risk Management to ensure that all information security risks are owned and documented and remediated to an agreed and accepted level.
- Support the process for project engagements to ensure that Information Security requirements are defined for each project, Architectural design documents are reviewed to ensure appropriate controls are in place and testing and acceptance processes are in place to ensure that agreed controls have been implemented.
- Serve as a hands-on Security Analyst, proactively identifying opportunities for improvement and delivering security enhancements to our systems.
- Understanding of server hardware, hypervisors, virtual machines, operating systems, Microsoft services, including Intune, Entra, Office365, Azure, SQL Server, SCCM, and File & Directory services.
- Collaborate with partners to ensure the security of the Cisco Meraki network, taking an initiative-taking stance in mitigating risks and initiative-taking patch management.
- Assist with internal and external vulnerability assessments, working with security partners to maintain PCIDSS compliance, overcome security challenges, and drive continuous improvements align to the NIST framework/ISO271002 standards.
- Report and review our secure device imaging using Microsoft Intune & Autopilot, ensuring a standardized, scalable, and resilient setup for retail, hospitality POS, and all corporate end user devices.
- Effective operation of security tooling reporting against our SIEM platform, endpoint protection solutions, and identity access controls, reviewing automated threat detection and forensic incident response to protect critical infrastructure and services.
- Create and manage security policy documentation, assist with security procedures, and training our internal teams and wider retail staff.
- Undertake disaster recovery planning, ensuring business continuity and resilience against potential disruptions.
- Work proactively alongside support, application, and transformation teams, fostering collaborative and communicating security procedures and policies.
- Deliver concise, well-structured documentation, providing clarity for teams and enabling rapid adoption of security best practices.
- Function as a trusted advisor, recognised as the go-to subject matter expert for security, and bridging the gap between end user and the infrastructure and security team.
- Guide and support third-party engagements, ensuring vendors align with enterprise security standards, compliance requirements, and best practices.
- Educate and empower both internal teams and the broader business, fostering a security-first culture and promoting best practices in security and business continuity.
- Experience of security and compliance standards frameworks such as ISO 27001, ISO 22301, GDPR, PCI-DSS, NIST, and ACPO guidelines.
- Understanding of UK legal frameworks including the Data Protection Act and Computer Misuse Act.
- Understanding of Microsoft infrastructure including Windows Server Administrator, Active Directory AAD Administrator, Group Policy, and Microsoft 365 services and Azure Cloud resource management.
- Microsoft SQL Server PowerShell scripting.
- Identity & Access Management (IAM), Expertise in Microsoft Entra ID (formerly Azure AD), role-based access control (RBAC), and multi-factor authentication (MFA).
- Cloud Security, Experience securing Azure environments, including Microsoft Defender for Cloud, Sentinel, and compliance frameworks like PCIDSS.
- Threat Protection & Incident Response: Ability to identify vulnerabilities, implement threat protection, and respond to security incidents.
- Patch Management & Endpoint Security: Understanding of patching, importance of regular updates, patching, and endpoint protection across Windows and Azure environments.
- Familiarity with backup and disaster recovery tools and practices.
- Phishing awareness tools and ability to create training for end users on security best practices.
- Competitive salary.
- A generous store and restaurant discount of up to 40%.
- 25 days holidays (excluded bank holidays) and an extra day off for your birthday.
- A fantastic subsidised staff restaurant which uses Fortnum's ingredients.
- A range of opportunities to develop and grow personally and professionally.
- Excellent pension scheme.
We are committed to developing your career and nurturing your talent, regardless of age; disability; gender reassignment; marriage and civil partnership; pregnancy and maternity; race; religion or belief; sex; sexual orientation. We respect and embrace each other's differences, to create a truly inclusive environment. In the last year alone, our people have been recognised and celebrated, winning awards for their outstanding contributions to Retail, Technology, Global Hospitality & Tourism, Visual Merchandising & Display, Customer Service and Local Community Awards.
Security Governance Analyst employer: Fortnum & Mason
Contact Detail:
Fortnum & Mason Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Security Governance Analyst
✨Tip Number 1
Network like a pro! Reach out to current employees at Fortnum & Mason on LinkedIn. Ask them about their experiences and any tips they might have for landing the Security Governance Analyst role. Personal connections can make a huge difference!
✨Tip Number 2
Prepare for the interview by brushing up on your knowledge of security frameworks like ISO 27001 and PCI-DSS. Be ready to discuss how you've applied these in past roles. We want to see your expertise shine through!
✨Tip Number 3
Showcase your problem-solving skills! Think of specific examples where you identified security risks and implemented solutions. This will demonstrate your proactive approach, which is key for a Security Analyst.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, it shows you're genuinely interested in being part of the Fortnum & Mason team.
We think you need these skills to ace Security Governance Analyst
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Security Governance Analyst role. Highlight relevant experience and skills that match the job description, like your knowledge of security frameworks and incident response. We want to see how you can bring value to our team!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about security governance and how your background makes you a perfect fit for us. Don’t forget to mention specific projects or experiences that relate to the responsibilities listed in the job description.
Showcase Your Soft Skills: While technical skills are crucial, don’t forget to highlight your soft skills too! Communication, collaboration, and problem-solving are key in this role. Share examples of how you've worked with teams or managed projects to demonstrate these abilities.
Apply Through Our Website: We encourage you to apply through our website for a smoother application process. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, you’ll get to explore more about what we do at Fortnum & Mason!
How to prepare for a job interview at Fortnum & Mason
✨Know Your Security Standards
Familiarise yourself with key security frameworks like ISO 27001, PCI-DSS, and NIST. Be ready to discuss how these standards apply to the role and share examples of how you've implemented them in past experiences.
✨Showcase Your Technical Skills
Brush up on your knowledge of Microsoft services, especially Azure and Intune. Be prepared to explain how you've used these tools in previous roles, particularly in relation to security governance and incident response.
✨Prepare for Scenario Questions
Expect questions that ask you to solve hypothetical security incidents or compliance challenges. Practice articulating your thought process and decision-making steps clearly, as this will demonstrate your analytical skills and proactive approach.
✨Emphasise Collaboration
Highlight your experience working with cross-functional teams. Discuss how you've communicated security policies effectively and fostered a security-first culture within an organisation, as collaboration is key in this role.