
Senior Information Security Analyst
- Bristol Area
- Permanent
- Full-time
- You will be the SME and lead for the technical aspects of Cloud security assurance risk and controls.
- You will oversee and conduct, as necessary, Cloud Compliance assessments for AWS and Azure risk assessments, enforce cloud security policies and standards. Leading the AWS SRC workstream.
- Assisting the Information Security Team in ensuring HL's Information Security Management System remains effective in protecting HL critical information assets within risk appetite.
- Lead assurance activities against Information Security Compliance frameworks, including but not limited to: PCI, NIST, SWIFT, GDPR
- Conducting analysis of cloud-based assets pertaining to information security incidents, audits, and testing while adhering to best practices.
- Lead engagement of Cloud Audits and remediation activities.
- Leading in the identification and reporting of remediation and mitigation activities related to cloud security findings across multiple cloud platforms (AWS and Azure).
- Identifying gaps in cloud security posture and prioritise remediation efforts.
- Building relationships across multiple business functions, locations, and technical stakeholders to accomplish goals. You will help deliver the strategy by emphasising the importance of AWS Well Architected Framework, Shared responsibility model and good cloud governance.
- Delivering a best-in-class service within a high performing Security team
- Leading by example to create a culture of continuous service improvements
- Experience in a regulated environment, preferably Financial Services.
- Previous experience in Information/Cyber Security, with demonstrable experience of Cloud Security tooling, to reduce risks and maintain strong controls in a DevSecOps cloud context
- Highly organised with the ability to prioritise workload
- Excellent verbal and written communication skills
- A willingness to learn as well as to knowledge share.
- Effective interpersonal skills to engage and collaborate with multiple internal and external Stakeholders at all levels.
- Practical work-based experience across the areas of security policy, culture, audit, and risk management.
- Strong knowledge of common, cloud technologies, enterprise, and network architecture.
- AWS Certified Cloud Practitioner
- Certified to advanced security standards, for example CCSK, CCSP, CISSP, CRISC
- Carrying out security reviews against recognised security control frameworks such as CSA Cloud Control Matrix, ISO27017/27001, NIST CSF, PCI-DSS, SWIFT, AWS CAF
- Atlassian, IAAC Terraform, Merge Requests,
- GIT Ops, Git Hub, Workflow, Wiz, Security Hub, Macie, Audit Manager, Microsoft Compliance Portal/Purview, Microsoft Information Protection (AIP), Azure Security Centre.
- Strong experience with DevOps practices, continuous integration/continuous deployment (CI/CD) pipelines, and related tools
- Ability to evaluate the adequacy of cloud security controls, and how they are applied in a business context.
- Discretionary annual bonus* and annual pay review
- 25 days* holiday plus bank holidays and 1-day additional Christmas closure
- Option to purchase an additional 5 days holiday**
- Flexible working options available, including hybrid working
- Enhanced parental leave
- Pension scheme up to 11% employer contribution
- Income Protection and Life insurance (4 x salary core level of cover)
- Private medical insurance*
- Health care cash plans - including optical, dental, and outpatient care
- Health screening programme
- Help@hand - confidential support including mental health counselling and remote GP
- Wellhub - unlimited access to fitness providers and wellness coach sessions
- Variety of travel to work schemes with bike storage and shower facilities
- Inhouse barista and deli serving subsidised coffee and sandwiches
- Two paid volunteering days per year
- dependant on role level