Overview
In this role you will own day-to-day information security activities within a market-leading insurance broker, maintaining policies, controls and reporting. You will collaborate with Technology, Risk, Compliance, Legal, HR and Operations to support audits, due diligence and regulatory assurance. You will drive continuous improvements to security processes and assist with risk assessments, supplier security and incident handling. This is an impact-focused position enabling stronger security governance and timely risk insights.
Responsibilities
- Maintain up-to-date information-security policies, procedures, standards and guiding documents.
- Organise and maintain evidence for internal reviews, audits, client due diligence and regulatory assurance.
- Keep security risk registers, action trackers, control records and incident documentation current.
- Produce clear security reports and dashboards covering risks, actions, vulnerabilities and control status.
- Support continuous improvement of security processes, templates and reporting.
- Assist with information-security risk assessments across systems, processes and projects.
- Support due diligence for suppliers and third parties by reviewing questionnaires and evidence.
- Track supplier-security actions and maintain records of assessments and remediation plans.
- Monitor security alerts and vulnerabilities; escalate higher-risk findings when needed.
- Triage straightforward security issues and escalate incidents or high-risk findings promptly.
- Assist reviews of access control, endpoint security, email security and identity management.
- Support investigation and coordination of information-security incidents and lessons learned.
- Support security-awareness communications and phishing simulations, creating clear guidance for staff.
Key requirements
- Practical experience in information security, cyber security, IT, technology risk, compliance or related discipline.
- Understanding of core information-security principles: confidentiality, integrity, availability, risk management and data protection.
- Familiarity with common cyber-security threats: phishing, social engineering, malware, ransomware, credential compromise and cloud-security risks.
- information-security principles
- risk management
- incident coordination
- security reporting
- supplier due diligence
…
