At a Glance
- Tasks: Lead security policy development and manage compliance audits while enhancing security measures.
- Company: Marcura, a global leader in maritime digital solutions with a focus on innovation.
- Benefits: Competitive salary, mentorship opportunities, and exposure to product development.
- Other info: Opportunity for career growth and to work with experienced leaders.
- Why this job: Make a real impact on security practices in a dynamic, global environment.
- Qualifications: 5+ years in information security and strong understanding of security frameworks.
The predicted salary is between 60000 - 80000 £ per year.
Marcura is a global leader in digital solutions for the maritime industry, providing software and services that help shipowners, operators, and maritime professionals streamline operations, reduce costs, and stay compliant. With a strong focus on innovation, data integrity, and security, Marcura’s products support critical workflows such as port cost management, payments, and data intelligence. The company is committed to maintaining robust information security practices to protect sensitive financial and operational data, ensuring trust, resilience, and compliance across its global platform.
We’re searching for a Senior Information Security and Compliance Analyst to join our crew. As our ideal Senior Information Security and Compliance Analyst you will interact with multiple stakeholders within the organization and contribute innovative solutions for security programs and continuous monitoring capabilities. You will also be responsible for the ongoing management of information security policies, procedures, and technical systems in order to maintain the confidentiality, integrity, and availability of all organizational information systems.
What You’ll Do
- Lead in the development/adoption and enforcement of Information Security policies, procedures and standards.
- Conduct and complete an annual review of required PCI, SOC2 regulations and reports.
- Ensure compliance through adequate training programs and periodic security audits, both internal and external.
- Execute and manage vulnerability scanning programs, analyse scan results in depth, prioritise risks based on exploitability and business impact, and work directly with engineering teams to remediate findings.
- Integrate security into the software development lifecycle by performing code reviews, supporting secure coding practices, and implementing automated security testing tools such as SAST and dependency scanning.
- Assess third-party systems and integrations from a technical security perspective, identifying risks in APIs, data flows, and external dependencies.
- Conduct detailed risk assessments, threat modelling exercises, and security architecture reviews for new and existing systems, providing actionable recommendations and technical guidance.
- Develop, implement, and tune detection rules and use cases within security monitoring platforms to improve visibility and reduce false positives.
- Maintain the Company’s Security Policies, detailing and documenting actual mechanisms and controls including administrative, personnel security, physical safeguards, technical security, and transmission security.
- Take on other tasks and duties as assigned.
Qualifications
- Bachelor’s degree in a related field.
- 5+ years’ experience working in information security.
- Experience working in a global, distributed environment is a plus.
- Strong understanding of security frameworks and standards (e.g., ISO 27001, NIST, SOC 2).
- Understanding of other technology sub-areas, i.e., server administration, server security, testing and implementation processes and procedures.
- Strong skill in problem solving to identify, communicate, and implement action when needed.
- 2+ years of experience using vulnerability assessment tools, analysing and interpreting assessment results.
- 3+ years of experience with strong understanding of infrastructure technologies and functionalities both on-premises and cloud (e.g., firewalls, Windows/Linux servers, Active Directory, Azure, AWS, GCP).
We’ll give you extra credit for:
- CISSP Certification.
- Experience working in a highly regulated environment.
What You’ll Gain
- Exposure to strategic, monetization, and commercial product development.
- Mentorship from experienced product and growth leaders.
- The opportunity to see the full product lifecycle, from discovery to revenue impact.
- The chance to make a measurable impact on business and customer KPIs.
Senior InfoSec & Compliance Strategist employer: Marcura
Marcura is an exceptional employer that prioritises innovation and security within the maritime industry, offering a dynamic work environment where employees can thrive. With a strong commitment to professional development, you will have access to mentorship from seasoned leaders and opportunities to influence critical business outcomes. Located in a global setting, Marcura fosters a collaborative culture that values integrity and resilience, making it an ideal place for those seeking meaningful and rewarding careers in information security.
StudySmarter Expert Advice🤫
We think this is how you could land Senior InfoSec & Compliance Strategist
✨Tip Number 1
Network like a pro! Reach out to folks in the maritime and InfoSec industries on LinkedIn. Join relevant groups, attend webinars, and don’t be shy about sliding into DMs. You never know who might have the inside scoop on job openings!
✨Tip Number 2
Prepare for interviews by brushing up on your knowledge of security frameworks like ISO 27001 and NIST. Be ready to discuss how you’ve implemented these in past roles. We want to see your problem-solving skills in action!
✨Tip Number 3
Showcase your experience with vulnerability assessment tools during interviews. Bring examples of how you’ve analysed results and worked with teams to remediate findings. This will highlight your hands-on expertise and collaborative spirit.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our crew at Marcura!
We think you need these skills to ace Senior InfoSec & Compliance Strategist
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Senior InfoSec & Compliance Strategist role. Highlight your relevant experience and skills that match the job description, especially in information security policies and compliance frameworks.
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how your background makes you a perfect fit for our team at Marcura. Don’t forget to mention any specific projects or achievements that relate to the role.
Showcase Your Problem-Solving Skills:In your application, be sure to include examples of how you've tackled complex security challenges in the past. We love candidates who can demonstrate their problem-solving abilities, especially in a global, distributed environment.
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, it shows us you’re genuinely interested in joining our crew!
How to prepare for a job interview at Marcura
✨Know Your Security Frameworks
Make sure you brush up on your knowledge of security frameworks like ISO 27001, NIST, and SOC 2. Be ready to discuss how you've applied these standards in your previous roles, as this will show your understanding of compliance and security best practices.
✨Showcase Your Problem-Solving Skills
Prepare examples that highlight your problem-solving abilities, especially in identifying and mitigating risks. Think of specific situations where you had to analyse vulnerabilities and implement solutions, as this will demonstrate your hands-on experience.
✨Familiarise Yourself with the Company’s Products
Take some time to understand Marcura's software and services. Knowing how their products streamline operations and ensure compliance will help you tailor your answers and show genuine interest in the role and the company.
✨Prepare for Technical Questions
Expect technical questions related to vulnerability assessment tools and security architecture. Brush up on your knowledge of cloud technologies and infrastructure, as well as any relevant coding practices, to confidently tackle these queries.