At a Glance
- Tasks: Protect and manage Moneycorp's data and information systems in line with security standards.
- Company: Join a dynamic global payments company committed to innovation and collaboration.
- Benefits: Enjoy competitive salary, 25 days holiday, private health insurance, and flexible working options.
- Why this job: Make a real impact in cyber security while growing your skills in a supportive environment.
- Qualifications: 3+ years in IT security, knowledge of ISO27001, and experience with DLP solutions.
- Other info: Be part of a culture that values diversity and fosters inclusivity.
The predicted salary is between 30000 - 50000 ÂŁ per year.
Welcome to Moneycorp. In the last decade, Moneycorp has transformed from a largely domestic, consumer‑focused provider of foreign exchange to an end‑to‑end global payments ecosystem. With two banking licences and operations across the entire value chain of the international payments and foreign exchange sectors, we enable businesses, institutions and individuals to thrive beyond borders. We help our clients realise their growth ambitions by providing them with worldwide reach, relentless regulatory excellence and tailored, relevant solutions that resiliently optimise their financial operations.
This role sits within the Information Security Team, part of Group Risk and Compliance, reporting into the Head of Information Security. The candidate will be responsible for ensuring Moneycorp’s data and information processing systems are protected in‑line with the information & cyber security programme. The role will assist compliance to the ISO27001:2022 standard, by supporting day‑to‑day activities; by ensuring the organisation adopts good industry practices which are aligned to the organisation’s Information Security Policies.
What we’re looking for / Skills that will help you in the role:
- ISO27001/SOC2 GRC support: Provide support to the management of the existing Information Security Management System: governance, risk management, remediation activities.
- Information Security assessments: Conduct information security risk assessments across project lifecycle from incubation to decommission. Where necessary, provide advisory to ensure sufficient controls are implemented.
- Data management: Manage and tune Data Loss Prevention tools, to protect and prevent the loss of sensitive information.
- Operational Team activities: Responsible for completing daily tasks, providing KPIs, and triaging ticket queue with SLAs.
Person Specification Knowledge and Experience:
- At least 3 years experience in an information or IT security related role within a financial or regulated firm.
- Experience with DLP solutions, such as email filtering, Cloud access security broker and or Microsoft Purview.
- Applicants will have a technical background with exposure to IT, security, network or Cloud infrastructure administration.
- Fully understand security concepts such as identity access management, defence in depth, least privilege, resilience (technical & operational), segregation (networks & duties), cloud security (shared responsibility).
- Ability to support audits, conduct risk assessments, and implement mitigation strategies.
- Understanding of PCI DSS, SWIFT CSP, and operational resilience frameworks.
- Knowledge of implementing ISO27001:2022.
- Data loss prevention & management.
Skills:
- Technically astute, understands technical risks to the business and can provide clear risk assessment analysis to the business.
- Able to challenge where risks are outside of tolerance in an evidence‑led, logical and methodical manner.
- Network Security & Protocols – Deep understanding of TCP/IP, firewalls, VPNs, IDS/IPS, and secure network architecture and browser filtering technologies.
- Email – understands email delivery, and controls i.e. tracing, analysing, filtering, DMARC, SPF, DKIM.
- Security Frameworks & Controls – Familiarity with NIST, CIS Controls, and UK‑specific frameworks like Cyber Essentials.
- Cloud Security – Knowledge of securing Azure, including IAM, encryption, and monitoring (Sentinel experience beneficial).
- Data Protection & Encryption – Understanding of cryptographic protocols and secure data handling practices.
- Experience in Information Security Awareness and Training, phishing simulations, managing online training (CBT), providing content for awareness.
- Attention to Detail – Critical for monitoring logs, reviewing configurations, and writing formal documentation.
- Analytical Thinker – Ability to assess complex systems and identify potential risks and vulnerabilities.
- Ability to disseminate documentary evidence to provide objective analysis.
- Maintain a current understanding of common vulnerabilities and appropriate remediation.
- Communicating and documenting user‑reported security problems and incidents.
- Keeps up to date with the latest Information and Cyber news, threats and incidents.
- Appreciate when to elevate issues upwards.
Desirable Skills:
- Familiarity with Data Protection and Financial regulations i.e. GDPR, FCA regulations, PRA guidelines, UK Data Protection Act, DORA.
- Familiar with SOC2 Type II, NIST CSF, PCI DSS and NCSC guidance.
Education:
- BSc/MSc in Information Security, computing, science, technology, engineering or mathematics (STEM) subject.
- Known security qualifications such as CompTIA Security+, CySA+, CASP, or other established certifications from ISC2, ISACA GIAC or EC‑Council.
- Azure Fundamentals AZ‑900; Security, Compliance and Identity Fundamentals SC‑900; or other Microsoft certification.
Personal Attributes:
- A passion for cyber security and a keen interest in IT.
- Highly motivated, responsible, reliable and organised individual able to use own initiative, manage own time and workload and an excellent attention to detail.
- Inquisitive, keen to learn.
- Capable of developing a strong working relationship with peers to encourage good security practices.
- Collaborative and team‑oriented, flexible attitude, adhering to a high standard of ethical behaviour.
This position is full‑time, permanent. The role is office‑based in Coventry as part of the Risk and Compliance team. However, we have an agile flexible working policy which enables you to work up to 2 days from home if desired.
What you get in return:
This role offers a competitive salary with commission or bonus, plus a comprehensive benefits package including 25 days holiday plus a day off for your birthday, pension, BUPA private medical health insurance and more.
Fostering a culture of belonging and inclusivity:
We’re committed to creating a workplace where every individual feels valued, respected, and included. As an Equal Opportunity Employer, we actively cultivate an inclusive culture where diversity thrives, and we empower our colleagues to drive meaningful change within our organisation through initiatives like our DE&I focus groups and value champion network.
Information Security Analyst (GRC) in Coventry employer: Moneycorp
Contact Detail:
Moneycorp Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Information Security Analyst (GRC) in Coventry
✨Tip Number 1
Network like a pro! Reach out to people in the industry, attend events, and connect on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by researching Moneycorp's values and recent projects. Tailor your answers to show how your skills align with their mission. Remember, they want to see your passion for information security!
✨Tip Number 3
Practice common interview questions related to GRC and information security. Use the STAR method (Situation, Task, Action, Result) to structure your responses. This will help you articulate your experience clearly and confidently.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, it shows you’re genuinely interested in being part of the Moneycorp team.
We think you need these skills to ace Information Security Analyst (GRC) in Coventry
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Information Security Analyst role. Highlight your experience with ISO27001, DLP solutions, and any relevant certifications. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about cyber security and how your background makes you a great fit for our team. Let us know what excites you about working at Moneycorp!
Showcase Your Technical Skills: In your application, don't forget to showcase your technical skills. Mention your understanding of network security protocols, data protection regulations, and any hands-on experience you've had. We love candidates who can demonstrate their expertise!
Apply Through Our Website: We encourage you to apply through our website for a smoother process. It helps us keep track of your application and ensures you get all the updates directly from us. Plus, it's super easy!
How to prepare for a job interview at Moneycorp
✨Know Your ISO27001 Inside Out
Make sure you’re well-versed in the ISO27001:2022 standard. Brush up on how it applies to information security management systems and be ready to discuss how you’ve implemented or supported compliance in your previous roles.
✨Showcase Your Technical Skills
Be prepared to talk about your experience with DLP solutions and network security protocols. Highlight specific projects where you’ve managed data loss prevention tools or conducted risk assessments, as this will demonstrate your hands-on expertise.
✨Understand the Business Context
Moneycorp operates in a fast-paced financial environment, so show that you understand the importance of protecting sensitive information. Discuss how your role as an Information Security Analyst can directly impact the company’s ability to thrive beyond borders.
✨Ask Insightful Questions
Prepare thoughtful questions about Moneycorp’s approach to information security and compliance. This shows your genuine interest in the role and helps you gauge if the company’s values align with yours, especially regarding collaboration and commitment to success.