Senior Information Security Analyst
Senior Information Security Analyst - Liverpool - Office Based - £50,000 - £65,000
About the Role
We are seeking a Senior Information Security Analyst to play a key role in maintaining and improving our Information Security Management System (ISMS) and overall security posture.
Reporting to the Head of Information Security & Continuity, you will work closely with Technology, Risk, Compliance and business stakeholders to ensure information security risks are identified, assessed and appropriately managed. This is a hands-on role focused on information security governance, risk management, compliance and assurance activities, rather than infrastructure management or security operations.
Key Responsibilities
- Support the ongoing maintenance and continuous improvement of the ISO 27001 aligned Information Security Management System (ISMS).
- Conduct information security risk assessments and support the management of risk treatment plans.
- Assist with internal and external audits, including ISO 27001 certification and surveillance audits.
- Develop, review and maintain information security policies, procedures and standards.
- Support the management of security incidents, investigations and lessons learned activities.
- Monitor and track remediation of vulnerabilities, audit findings and security control weaknesses.
- Perform supplier and third-party security assessments.
- Work closely with IT teams to ensure security controls are embedded into systems and projects.
- Support security awareness and training initiatives across the business.
- Assist with compliance activities relating to GDPR, Cyber Essentials and security frameworks.
- Produce security metrics, reports and management information for stakeholders.
- Support ongoing improvements to security governance, controls and assurance processes.
Essential Experience
- Experience working within an Information Security, Cyber Security or Security Governance role.
- Experience supporting or maintaining an ISO 27001 aligned ISMS.
- Understanding of ISO 27001 controls and certification requirements.
- Experience conducting security risk assessments and managing remediation activities.
- Experience supporting security audits and compliance programmes.
- Knowledge of information security frameworks such as ISO 27001, NIST or Cyber Essentials.
- Experience developing or maintaining security policies and procedures.
- Strong stakeholder management and communication skills.
- Ability to communicate technical security risks to non-technical stakeholders.
- Good understanding of IT infrastructure, cloud technologies and security controls.
Click Apply!
Essential Qualifications
Degree or equivalent professional experience in a relevant field
Industry certifications such as CISSP, CISM, or equivalent (desirable)
ISO 27001 Lead Implementer or Auditor (desirable)