Information Security Analyst - 6 month FTC
The Information Security Analyst will play a key role in supporting the delivery of information security and compliance activities across Newmark, with a particular focus on achieving ISO 27001 certification. This role will involve assisting with security policies, risk assessments, and operational activities. This position requires a strong technical background, analytical skills, and the ability to collaborate effectively with IT, operations, and business teams. This varied and dynamic role offers exposure across information security, risk management, and compliance, providing an excellent platform for career development within a professional services environment.
Key Responsibilities
- Support the implementation and maintenance of an information security framework with a focus on achieving ISO 27001 certification.
- Take ownership of day-to-day information security processes, ensuring the effective delivery of security and compliance activities.
- Act as a first point of contact for information security queries, resolving routine matters and escalating complex issues when necessary.
- Assist in the development, review, and revision of security policies, standards, and procedures in line with regulatory changes and business needs.
- Support the administration and monitoring of security compliance registers, including incident logs, risk registers, and access control records.
- Assist with security risk assessments, audits, and gap analyses, and support the implementation of mitigating actions.
- Assist in identifying and evaluating security risks, and contribute to proposing appropriate controls to mitigate them.
- Support the monitoring of emerging threats, vulnerabilities, and industry trends to contribute to security planning.
- Contribute to the risk management framework to help teams track and manage security risks.
- Coordinate and document security awareness training and contribute to the ongoing education of staff on cybersecurity best practices.
- Liaise with external auditors and regulatory bodies, maintaining accurate records and documentation to support audit readiness and regulatory reporting.
- Collaborate with the Legal, Compliance, Facilities and IT teams to help align security activities with organisational and regulatory requirements.
Qualifications and Skills
- Experience in an information security, cybersecurity, or risk management role within professional services, property, or a corporate environment.
- Strong organisational and project coordination skills, with the ability to manage multiple priorities and deadlines.
- Understanding of information security frameworks (in particular, ISO 27001), compliance monitoring processes, and regulatory obligations.
- Excellent written and verbal communication skills, with confidence engaging stakeholders at all levels and explaining technical concepts to non-technical audiences.
- Proficiency in Microsoft Office (Word, Excel, PowerPoint, Outlook), with the ability to analyse and present information effectively.
- Strong attention to detail and accuracy, with the ability to take ownership of security and compliance responsibilities.
- Ability to work independently, use initiative, and manage tasks with minimal supervision.
- Interest in information security, professional standards and/or regulatory compliance as part of a longer-term career path.
Personal Attributes
- Professional, dependable, and solutions-focused.
- Proactive self-starter with strong problem-solving skills.
- Collaborative team player with excellent interpersonal skills.
- Flexible and adaptable, able to manage changing priorities effectively.
- Committed to continuous improvement and personal development.