Information Security Analyst
Guildford, Surrey, England, United Kingdom
Hybrid / WFH Options
Hybrid / WFH Options
Sanderson
key role in advancing the company's security posture by delivering Governance, Risk, and Compliance (GRC) initiatives and embedding the NIST Cyber Security Framework (CSF) across the business. Key skills/responsibilities: Deliver day-to-day GRC activities, including designing and implementing security controls and managing information security risks Interpret and apply requirements from the Group Information Security Framework … compliance activities for frameworks such as Cyber Essentials, PCI DSS, and the Group Information Security Framework Facilitate reviews and updates to ensure controls remain effective against evolving threats Essential skills: Minimum 2 year's experience in information security, with a solid understanding of security control and governance frameworks Experience in developing security controls catalogue in a financial services environment … highly desirable) Proven experience in delivering security projects within a federated organisation Desirable skills: Knowledge of NIST CSF, ISO 27001, Cyber Essentials, PCI DSS, DORA Understanding of risk methodologies and data analysis for reporting Strong documentation skills (control matrices, process flows, SOPs) Excellent communication skills for both technical and non-technical stakeholders Relevant certifications such as More ❯
Employment Type: Full-Time
Salary: Salary negotiable
Posted: