We are currently partnering with a market-leading Insurance Broker to recruit an Information Security Analyst. The successful candidate will take ownership of day-to-day security activities, maintain accurate security records and reporting, coordinate follow-up actions, and work closely with colleagues across Technology, Risk, Compliance, Legal, HR and Operations.
Key Responsibilities:
- Maintain current and accessible information-security policies, procedures, standards, guidance and supporting documentation.
- Support the collection, organisation and maintenance of evidence for internal reviews, external audits, client due diligence and regulatory assurance activities.
- Maintain security risk registers, action trackers, control records, exception logs and incident documentation.
- Produce clear, accurate and timely security reports and dashboards covering risks, actions, vulnerabilities, supplier assurance and control status.
- Support the continuous improvement of security processes, templates, documentation and reporting.
- Assist with information-security risk assessments covering systems, business processes, technology projects, suppliers and change initiatives.
- Support security due diligence for suppliers and third parties by reviewing questionnaires, policies, certifications, audit reports and supporting evidence.
- Track outstanding supplier-security actions and maintain accurate records of assessments, risks, exceptions and remediation plans.
- Monitor security alerts, vulnerabilities, control exceptions and security-related tasks, escalating higher-risk findings where appropriate.
- Triage straightforward security issues, gather relevant information and escalating potential incidents or higher-risk findings promptly.
- Assist with reviews of access control, endpoint security, email security, identity management and other security controls.
- Support the investigation, documentation and coordination of information-security incidents, including lessons learned and follow-up improvement actions.
- Support security-awareness communications, training, phishing simulations and the creation of clear security guidance for employees and stakeholders.
- Handle confidential information with integrity and discretion, comply with relevant policies, regulations and professional standards, and undertake reasonable ad hoc security tasks and projects.
Skills & Experience:
- Practical experience in information security, cyber security, IT, technology risk, compliance, audit or a related discipline.
- Understanding of core information-security principles, including confidentiality, integrity, availability, risk management and data protection.
- Familiarity with common cyber-security threats, including phishing, social engineering, malware, ransomware, credential compromise and cloud-security risks.
#J-18808-Ljbffr…
