
Information Security Analyst
- Birmingham
- Permanent
- Full-time
- Assist in the daily maintenance of the Information Security risk management process, ensuring accurate documentation of risks and effective follow-through on treatment actions.
- Support the investigation and resolution of security incidents and breaches in accordance with established procedures.
- Play an active role in coordinating and preparing for internal assurance activities and external audits.
- Assist in compiling and coordinating management information and statistics to support continual assessment and evaluation aligned with key metrics and objectives.
- Conduct research for policy creation and assist in the development and preparation of relevant documentation.
- Prepare agendas, presentations, and other documents to support information security governance meetings.
- Aid in researching, monitoring, and creating elements of group training and engagement programs, including monthly ISO bulletins as part of the Information Security Awareness Program.
- Maintain awareness of Business Continuity Processes (BCP), assist with testing, and understand team BCP and Disaster Recovery responsibilities.
- Support the supplier risk management processes to ensure ongoing security of the group supply chain.
- Assist with client security engagement activities, such as tenders and audits, ensuring that client security requirements and contractual obligations are met.
- Provide support to the Information Security Operations Team on technical security initiatives and facilitate cross-skilling opportunities between the GRC and Security Operations Teams.
- Stay updated on emerging security threats and trends to ensure effective information risk management and identify potential improvement opportunities.
- Experience of working within an information security GRC role or team would be advantageous.
- Experience working within the legal or professional services sector and a group organisational structure would be advantageous.
- Good organisational skills and the ability to prioritise and manage tasks in a fast-paced environment.
- You will hold or may be working towards a relevant security certification.
- An understand of the basic principles of information security.
- An understanding of compliance frameworks and regulations (e.g., PCI DSS, NIST, ISO27001, CE+, CIS).
- Able to effectively communicate and collaborate with cross-functional teams.
- Good problem-solving and analytical skills to identify and address security risks and incidents effectively.
- Experience in incident response planning, handling security incidents, and conducting post-incident analysis.
- Good IT skills and knowledge of Excel, PowerPoint, and experience using multiple applications.
- Excellent interpersonal and communication skills, and a keen eye for detail.
- A willingness to learn and a passion to offer a solution focused approach every time.
- High degree of drive and self-motivation. A “can do” attitude, able to make things happen.
- Always committed to delivering excellent outcomes for clients.
- Willingness to be flexible,going above and beyond to meet the changing needs of the business.
- Completer/finisher with a strong focus on getting things done.
- Be a team player and want to make a difference.