Назад
Company hidden
4 дня назад

Senior Information Security Analyst (GRC)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Information Security Analyst (GRC) (ISO 27001/NIST): Strengthening information and cyber security across retirement, retail, and investment business areas through security risk and control management with an accent on translating policies into architecture patterns, assessing vulnerabilities, and evaluating third-party security maturity. Focus on reviewing configurations, coordinating penetration testing, analysing security findings, and recommending proportionate risk treatments.

Location: Hove, United Kingdom

Company

Legal & General is a UK financial services group and global investor providing retirement, protection, pension, and insurance solutions.

What you will do

  • Interpret information security policies, standards, and control requirements and translate them into architecture patterns and solution designs.
  • Advise project managers, developers, technology teams, and business stakeholders on security controls and good practice.
  • Monitor emerging security risks, assess vulnerabilities from application and infrastructure scans, and recommend proportionate solutions.
  • Review findings, compensating controls, risk ratings, system configurations, and solution designs with technical teams.
  • Evaluate third-party suppliers’ security maturity and support due diligence, tender, and contract reviews.
  • Scope penetration tests and assess and document the resulting findings.

Requirements

  • Understanding of information security principles and controls, including encryption, identity and access management, and security information and event management.
  • Experience in an IT, technology, information security, risk, or business-focused environment.
  • Strong analytical, judgement, communication, organisational, and prioritisation skills.
  • Ability to collaborate with a range of stakeholders and recommend practical security solutions.
  • Relevant degree or equivalent practical experience in computer science, IT, business, or a related discipline.

Nice to have

  • Experience in report writing, producing metrics, risk management, or security engineering and design.
  • Adaptable and creative approach with curiosity and willingness to learn new technologies and solutions.

Culture & Benefits

  • Welcoming and inclusive culture with opportunities to work with people from diverse backgrounds and experiences.
  • Flexible working options, including part-time work and job shares where business needs allow.
  • Annual performance-related bonus plan and share schemes.
  • Pension contribution, life assurance, holiday allowance, family leave, and employee discounts.
  • Healthcare plan and electric car scheme are available to permanent employees only.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →