Senior Information Security and Compliance Analyst

Senior Information Security and Compliance Analyst

Full-Time 60000 - 80000 £ / year (est.) No working from home possible
Marcura

At a Glance

  • Tasks: Lead security policy development and conduct audits to ensure compliance.
  • Company: Marcura, a global leader in maritime digital solutions.
  • Benefits: Competitive salary, mentorship, and exposure to product development.
  • Other info: Opportunity for career growth and working with innovative technologies.
  • Why this job: Make a real impact on security practices in a dynamic industry.
  • Qualifications: 5+ years in information security and strong problem-solving skills.

The predicted salary is between 60000 - 80000 £ per year.

Marcura is a global leader in digital solutions for the maritime industry, providing software and services that help shipowners, operators, and maritime professionals streamline operations, reduce costs, and stay compliant. With a strong focus on innovation, data integrity, and security, Marcura’s products support critical workflows such as port cost management, payments, and data intelligence. The company is committed to maintaining robust information security practices to protect sensitive financial and operational data, ensuring trust, resilience, and compliance across its global platform.

We’re searching for a Senior Information Security and Compliance Analyst to join our crew. As our ideal candidate, you will interact with multiple stakeholders within the organization and contribute innovative solutions for security programs and continuous monitoring capabilities. You will also be responsible for the ongoing management of information security policies, procedures, and technical systems in order to maintain the confidentiality, integrity, and availability of all organizational information systems.

What You’ll Do:

  • Lead in the development/adoption and enforcement of Information Security policies, procedures and standards.
  • Conduct and complete an annual review of required PCI, SOC2 regulations and reports.
  • Ensure compliance through adequate training programs and periodic security audits, both internal and external.
  • Execute and manage vulnerability scanning programs, analyse scan results in depth, prioritise risks based on exploitability and business impact, and work directly with engineering teams to remediate findings.
  • Integrate security into the software development lifecycle by performing code reviews, supporting secure coding practices, and implementing automated security testing tools such as SAST and dependency scanning.
  • Assess third-party systems and integrations from a technical security perspective, identifying risks in APIs, data flows, and external dependencies.
  • Conduct detailed risk assessments, threat modelling exercises, and security architecture reviews for new and existing systems, providing actionable recommendations and technical guidance.
  • Develop, implement, and tune detection rules and use cases within security monitoring platforms to improve visibility and reduce false positives.
  • Maintain the Company’s Security Policies, detailing mechanisms and controls including risk analysis and management, documentation management, information access controls, personnel security, physical safeguards, technical security, and transmission security.
  • Take on other tasks and duties as assigned.

Qualifications:

  • Bachelor’s degree in a related field.
  • 5+ years’ experience working in information security.
  • Experience working in a global, distributed environment is a plus.
  • Strong understanding of security frameworks and standards (e.g., ISO 27001, NIST, SOC 2).
  • Understanding of other technology sub-areas, i.e., server administration, server security, testing and implementation processes and procedures.
  • Strong skill in problem solving to identify, communicate, and implement action when needed.
  • 2+ years of experience using vulnerability assessment tools, analysing and interpreting assessment results.
  • 3+ years of experience with strong understanding of infrastructure technologies and functionalities both on-premises and cloud (e.g., firewalls, Windows/Linux servers, Active Directory, Azure, AWS, GCP).

We’ll give you extra credit for:

  • CISSP Certification.
  • Experience working in a highly regulated environment.

What You’ll Gain:

  • Exposure to strategic, monetisation, and commercial product development.
  • Mentorship from experienced product and growth leaders.
  • The opportunity to see the full product lifecycle, from discovery to revenue impact.
  • The chance to make a measurable impact on business and customer KPIs.

Senior Information Security and Compliance Analyst employer: Marcura

At Marcura, we pride ourselves on being an exceptional employer, offering a dynamic work culture that fosters innovation and collaboration within the maritime industry. Our commitment to employee growth is evident through mentorship opportunities and exposure to strategic product development, ensuring that our team members can thrive in their careers while contributing to meaningful projects that enhance operational efficiency and security. Located in a global environment, we provide a unique chance to engage with diverse stakeholders and make a tangible impact on business outcomes.

Marcura

Contact Details:

Marcura Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior Information Security and Compliance Analyst

Tip Number 1

Network like a pro! Reach out to current employees at Marcura on LinkedIn or other platforms. Ask them about their experiences and any tips they might have for landing the Senior Information Security and Compliance Analyst role.

Tip Number 2

Prepare for the interview by brushing up on security frameworks like ISO 27001 and NIST. We want you to show off your knowledge and how it applies to Marcura's operations, so think of real-world examples where you've implemented these standards.

Tip Number 3

Don’t just focus on your technical skills; highlight your problem-solving abilities too! Be ready to discuss how you've tackled challenges in previous roles, especially in a global or distributed environment.

Tip Number 4

Finally, apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you're genuinely interested in joining our crew at Marcura.

We think you need these skills to ace Senior Information Security and Compliance Analyst

Information Security Policies
PCI Compliance
SOC 2 Regulations
Vulnerability Scanning
Risk Assessment
Threat Modelling
Security Architecture Reviews

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Senior Information Security and Compliance Analyst role. Highlight your relevant experience, especially in information security policies and compliance frameworks like ISO 27001 or SOC 2. We want to see how your skills align with what we do at Marcura!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how you can contribute to our mission at Marcura. Be sure to mention any specific projects or experiences that relate directly to the job description.

Showcase Your Problem-Solving Skills:In your application, don’t forget to showcase your problem-solving skills. We’re looking for someone who can identify risks and implement solutions effectively. Share examples of how you've tackled challenges in previous roles, especially in a global environment.

Apply Through Our Website:We encourage you to apply through our website for the best chance of getting noticed. It’s super easy, and you’ll be able to submit all your documents in one go. Plus, it helps us keep track of your application better!

How to prepare for a job interview at Marcura

Know Your Security Frameworks

Make sure you brush up on your knowledge of security frameworks like ISO 27001, NIST, and SOC 2. Be ready to discuss how you've applied these standards in your previous roles, as this will show that you understand the importance of compliance and can contribute effectively to Marcura's security policies.

Showcase Your Problem-Solving Skills

Prepare examples of how you've tackled complex security challenges in the past. Highlight specific situations where you identified risks, communicated them effectively, and implemented solutions. This will demonstrate your ability to think critically and act decisively, which is crucial for the role.

Familiarise Yourself with Vulnerability Assessment Tools

Since the role involves managing vulnerability scanning programs, be ready to discuss your experience with these tools. Talk about how you've analysed scan results, prioritised risks, and worked with engineering teams to remediate findings. This shows you're hands-on and understand the technical aspects of the job.

Understand the Business Impact

It's important to connect security practices with business outcomes. Be prepared to discuss how your work in information security has positively impacted previous organisations, whether through cost savings, improved compliance, or enhanced trust with clients. This will help you stand out as someone who sees the bigger picture.