We are looking for an Information Security Analyst to join our Information Security team.
Working closely with our Head of Information Security , consultants, and clients, this is a varied role combining information security and GRC consultancy with hands-on configuration and implementation of the OneTrust platform.
You will work across a range of client engagements, helping organisations understand and manage their information security risks, implement effective controls and get real value from their GRC technology.
This isn’t a role where you’ll simply produce reports and recommendations. We are looking for someone who can understand a client’s problem, work out what needs to happen and help make it happen.
Key Responsibilities
Information Security and GRC Consulting
- Support the delivery of client information security, GRC, IT Risk Management and Third Party Risk Management engagements.
- Support clients with the implementation and ongoing operation of ISO 27001 Information Security Management Systems.
- Understand client issues and requirements and translate them into practical, proportionate solutions.
- Help clients develop, implement and maintain appropriate information security policies, controls and procedures.
- Provide clear, practical information security, risk and GRC advice to both technical and non-technical stakeholders.
- Deliver training, presentations and education on information security topics.
OneTrust
- Configure and implement OneTrust GRC solutions to meet client requirements.
- Build and configure assessments, attributes, workflows and related platform functionality.
- Support the delivery of IT Risk Management and Third Party Risk Management solutions through OneTrust .
- Work with clients to translate their processes and requirements into effective OneTrust configurations.
- Maintain relevant OneTrust learning and certifications and keep your platform knowledge current.
Risk, Assurance and Compliance
- Support clients in identifying, assessing, documenting and treating information security and cyber risks.
- Undertake supplier security reviews and third-party risk assessments as part of client managed services.
- Evaluate supplier security posture and support decisions around remediation, risk acceptance or supplier rejection.
- Carry out and document ISMS reviews, audits and spot checks to determine whether controls are operating effectively.
- Help clients understand and respond to relevant information security regulatory and compliance requirements, including DORA where applicable.
- Maintain appropriate records and evidence to demonstrate compliance with relevant standards, regulatory requirements and good practice.
Client and Stakeholder Relationships
- Build effective relationships with client stakeholders, internal teams and third-party suppliers.
- Explain complex security, risk and regulatory requirements clearly to technical and non-technical audiences.
- Work confidently with senior stakeholders and constructively challenge assumptions or decisions where needed.
- Manage multiple projects and pieces of work simultaneously while maintaining quality and meeting priorities.
Supporting Information Security at Oyster IMS
Alongside client work, you will also help us maintain and continuously improve our own information security environment.
This will include:
- Maintaining Oyster IMS Policy Management processes through OneTrust , including policy publication and attestation.
- Supporting administration of our Phished platform, including phishing simulations and security awareness activities.
- Helping test and improve our internal information security processes and controls.
- Keeping your technical knowledge, OneTrust learning and relevant certifications current.
Your email address is used only to send you the requested brochure. Please see our privacy policy to find out more.
#J-18808-Ljbffr