At a Glance
- Tasks: Lead and maintain Sodexo's Information Security Management System and ensure ongoing ISO27001 certification.
- Company: Join Sodexo, a global leader in services that improve Quality of Life.
- Benefits: Competitive salary, 20+ benefits, gym discounts, and 24/7 employee support.
- Other info: Inclusive workplace celebrating diversity and offering excellent career growth.
- Why this job: Make a real impact on security compliance across the UK & Ireland.
- Qualifications: Expertise in ISO27001, PCI DSS, and Cyber Essentials + required.
The predicted salary is between 36000 - 60000 £ per year.
We are looking for a Senior Information Security Compliance Analyst to lead and maintain Sodexo's Information Security Management System (ISMS) and ensure ongoing ISO27001 certification. This role will oversee the delivery of Information Security compliance activities across the UK & Ireland, supporting our PCI DSS programme and maintaining Cyber Essentials Plus compliance. The successful candidate will also manage third party security assurance across our supplier landscape and work closely with Legal teams to ensure appropriate Information Security requirements are embedded within contracts.
Main Responsibilities:
- Build an annual consolidated Information Security Compliance Programme that provides the business, IT visibility of internal and external Audit & Assurance activity to allow appropriate demand & resource planning.
- Deliver effective Security Compliance reporting to inform Risk & Issue reporting to the CISO, IT & Business Senior Leadership.
- Ensure Audit & Assurance actions are managed, tracked, and reported through to mitigation.
- Ensure the ISMS is managed and maintained in alignment with the Statement of Applicability and ISO27001/2 framework.
- Define requirements for the ISMS, document and implement security policies to develop and maintain the ISMS.
- Manage and maintain the ISMS document set.
- Run regular audits of the activities on locations covered by the ISMS scope.
- Develop a plan to scale up ISO27001 practices to a wider scope to improve overall security maturity.
- Explore opportunities for consolidation of ISMS where practical and appropriate.
- Build and maintain a PCI-DSS compliance programme that provides direction and assurance of operational controls to meet Sodexo's compliance requirements.
- Support PCI-DSS compliance efforts in performing and/or coordinating information security audits across payment channels/business segments.
- Coordinate and support the PCI-DSS Audit Activity to ensure delivery of the ROC and the AOC.
- Build and maintain a CE+ compliance framework that provides prioritised and targeted assurance activities.
- Support CE+ compliance efforts in performing and/or coordinating targeted CE+ compliance monitoring across applicable segments and related Sodexo infrastructure.
- Work with internal and external stakeholders to deliver CE+ certifications and recertifications.
The Ideal Candidate:
- Expert knowledge and practical experience of ISO27001 certification requirements and ISMS documentation.
- Expert knowledge and practical experience of PCI DSS certification requirements.
- Expert knowledge and practical experience of Cyber Essentials + certification requirements.
- Experience of leading and performing internal or external IT audits.
- Experience of dealing with third party supplier audits.
- Experience of negotiating with stakeholders in designing relevant action plans.
- Experience of comprehensive IT internal audit program design and development.
- General knowledge of IT environments and technologies.
- General Knowledge of Security Architecture or Enterprise Architecture.
- Desirable Certifications: CISA, CRISC, QSA, ISO27001 LI, ISO27001 LA.
- Ability to communicate effectively to a wide range of people from various horizons, both written and verbally.
- Analytical and problem-solving capabilities.
- Proactive and able to overcome obstacles.
- Rigorous and organised.
- Ability to gain Government Security Clearance.
Competitive salary depending on experience. Working with Sodexo is more than a job; it’s a chance to be part of something greater. You’ll belong in a company and team that values you for you; you’ll act with purpose and have an impact through your everyday actions; and you’ll be able to thrive in your own way.
In addition, we offer 20+ Sodexo benefits such as Sodexo retirement plan, discounts to over 1,900 brands to shop online, Gym discount to maintain a healthy lifestyle, a confidential 24/7 employee assistance programme providing independent support to overcome whenever life has its obstacles including emotional support, legal and financial advice.
Ready to be part of something greater? Apply today!
Senior Information Security Compliance Analyst in Manchester employer: Sodexo
Contact Detail:
Sodexo Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Information Security Compliance Analyst in Manchester
✨Tip Number 1
Network like a pro! Reach out to your connections in the industry, attend relevant events, and engage with professionals on platforms like LinkedIn. You never know who might have the inside scoop on job openings or can refer you directly.
✨Tip Number 2
Prepare for interviews by researching the company and its culture. Understand their values and how they align with your own. This will help you tailor your responses and show that you're genuinely interested in being part of their team.
✨Tip Number 3
Practice common interview questions and scenarios related to Information Security Compliance. Use the STAR method (Situation, Task, Action, Result) to structure your answers and highlight your experience effectively.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, it shows you’re serious about joining Sodexo and being part of something greater.
We think you need these skills to ace Senior Information Security Compliance Analyst in Manchester
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Senior Information Security Compliance Analyst role. Highlight your experience with ISO27001, PCI DSS, and Cyber Essentials +. We want to see how your skills match what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about information security compliance and how you can contribute to our team at Sodexo. Keep it engaging and relevant to the job description.
Showcase Your Achievements: Don’t just list your responsibilities; showcase your achievements in previous roles. Did you lead a successful audit or improve compliance processes? We love to see concrete examples of how you've made an impact!
Apply Through Our Website: We encourage you to apply through our website for a smoother application process. It helps us keep track of your application and ensures you don’t miss out on any important updates from us!
How to prepare for a job interview at Sodexo
✨Know Your Standards
Make sure you have a solid understanding of ISO27001, PCI DSS, and Cyber Essentials Plus. Brush up on the specific requirements and how they apply to Sodexo's operations. Being able to discuss these frameworks confidently will show that you're not just familiar with them, but that you can lead compliance efforts effectively.
✨Showcase Your Audit Experience
Prepare examples from your past experiences where you've led or participated in audits. Be ready to discuss the challenges you faced, how you overcame them, and the outcomes. This will demonstrate your hands-on experience and problem-solving skills, which are crucial for this role.
✨Communicate Clearly
Since you'll be working with various stakeholders, practice articulating complex information security concepts in simple terms. Think about how you would explain the importance of compliance to someone without a technical background. Clear communication is key to ensuring everyone is on the same page.
✨Be Proactive and Organised
Sodexo values proactive individuals who can manage multiple tasks efficiently. Prepare to discuss how you prioritise your workload and handle competing demands. Share specific strategies you use to stay organised, especially when managing compliance programmes and audit activities.