Engineer the Quantum RevolutionYour expertise can help us shape the future of quantum computing at Oxford Ionics.

View Open Roles

Information Security Analyst GRC

Robert Walters UK
London
1 week ago
Create job alert

My client, an International bank, based in London, is looking for an Information Security Analyst to join it's team. Three MUST for this role:1) Three days per week in the office2) They dont offer sponsorship3) You must come from banking or financial services background4) Must have at least 2/3 years experience in your current firm

About the Information Security Analyst role:

To assist the Branch Information Security Officer in developing and maintaining the Branch ISMS, and in providing a professional responsive service to assist management in identifying and mitigating information security risks which could seriously impact the Bank.

This includes the provision of expert advice, oversight, and assurance on, the selection, design, justification and operation of information security controls and management strategies to maintain the confidentiality, integrity, availability, accountability, and relevant compliance of information systems with legislation, regulation, and relevant standards, in concert with Bank Head Office alignment.

Notes from HM:

I’m ideally looking for someone who has a broad infosec background (it will usually be a smaller operation or someone who has moved roles in a larger operation) but with an understanding of how to translate this in GRC terms and generate KRI/KPI (as opposed to someone who works within a dedicated GRC function and knows how to use the tooling and work to policy).

KEY RESPONSIBILITIES

  • To maintain Information Security assurance activity (structured and unstructured) to assess and report on divergence from policy or agreed standards (control objectives) or to identify opportunities for improvement, thus allowing flaws to be redressed and continual improvement for 1st Line of Defence (1LoD)
  • To track, and report on, findings and actions arising from Information Security reviews, audits, and incidents and in update of Management Information for Information Security activity – maintaining management reporting and Key Risk reporting
  • To develop, review, and coordinate Information Security Awareness training, to ensure staff have a good understanding of their obligations and expectations for information Security
  • To track and respond to Information Security queries and activity arising from audits (internal and external) and from Bank Head Office.
  • To participate in Information Security related elements of annual Vendor risk assessments
  • To develop information security guidance for business and technical functions including agreeing information security control objectives with Branch stakeholders (Business and IT)
  • To assist in monitoring and response to Information Security alerts arising from IT security tools and logs
  • j) To assist in Incident response and in Incident simulation exercises
  • k) To assist in carrying out Information Security Roles and duties as defined in Bank procedures and policies (A4, A7-A, A7-B, Section 27, Section 61)
  • l) To undertake professional development and update knowledge in industry expected practice for Information Security to ensure personal skills and knowledge of information security are appropriate for the job holder’s duties and responsibilities

Other

  • j) To support the SMF24 (IT & InfoSec)
  • k) To carry out such other duties as requested by the Head of Information Security or the General Manager.

QUALIFICATIONS AND EXPERIENCE

Knowledge and experience of information Security Management System (ISMS) maintenance in conformance with a recognised framework such as ISO27001, NIST or SOC2.

Preferably with a recognised certification in a governance and management-oriented discipline of Information Security (CISSP, CISM or similar).

Other qualifications related to governance assessment and reporting (such as CISA).

2+ years experience in Information Security, conducting information security reviews and guiding business and technical management in prioritising security improvement for technical and procedural Information Security measures.

Strong documentation and reporting skills.

Technical experience and knowledge of Cyber Security (up to date).

(Desirable) experience working with Security Information and Event Management (SIEM) and Vulnerability Assessment.

(Desirable) Knowledge of attack methodologies and system hardening principles including aspects of vulnerability scanning and detection and security testing.

(Desirable) experience working with MS Sentinel (SIEM), Darktrace (NDR), Carbon Black (EDR) and Qualys (VM)

If the above sounds like you please apply to this advertisement or send your CV to or call me on

Robert Walters Operations Limited is an employment business and employment agency and welcomes applications from all candidates


#J-18808-Ljbffr

Related Jobs

View all jobs

Senior Security Analyst

Information Security Analyst

Information Security Analyst

Information Security Analyst

Information Security Analyst

Information Security Analyst

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Pre-Employment Checks for Cyber Security Jobs: DBS, References & Right-to-Work and more Explained

The cyber security sector in the UK stands at the forefront of protecting national infrastructure, business operations, and personal data from increasingly sophisticated cyber threats. As organisations across all sectors recognise cyber security as a critical business function, employers are implementing the most rigorous pre-employment screening processes in the technology industry to ensure they recruit professionals capable of defending against advanced persistent threats and maintaining the highest standards of security and trustworthiness. Whether you're a penetration tester, security analyst, incident response specialist, or chief information security officer, understanding the comprehensive vetting requirements is essential for successfully advancing your career in this security-critical field. This detailed guide explores the extensive background checks and screening processes you'll encounter when applying for cyber security positions in the UK, from fundamental eligibility verification to the most stringent security clearance requirements and specialised threat intelligence assessments.

Why Now Is the Perfect Time to Launch Your Career in Cyber Security: The UK's Digital Defence Revolution

The United Kingdom faces an unprecedented cyber security challenge that presents an extraordinary career opportunity. With cyber attacks increasing by 300% year-on-year and the average cost of a data breach reaching £4.24 million, Britain urgently needs skilled cyber security professionals to defend its digital infrastructure, protect citizens' data, and maintain national security in an increasingly connected world. If you've been considering a career change or seeking to future-proof your professional trajectory, cyber security represents one of the most secure, well-compensated, and socially impactful career choices available. The convergence of escalating threats, skills shortage, government investment, and regulatory requirements has created a perfect storm of opportunity that shows no signs of abating.

Automate Your Cyber Security Jobs Search: Using ChatGPT, RSS & Alerts to Save Hours Each Week

Cyber roles drop across consultancies, MSSPs, hyperscalers, banks, gov & start-ups every day—often buried in ATS portals or duplicated across boards. The fix is simple: put discovery on autopilot with keyword-rich alerts, RSS feeds & a reusable ChatGPT workflow that triages listings, ranks fit, & tailors your CV in minutes. This copy-paste playbook is built for www.cybersecurityjobs.tech readers. It’s UK-centric, practical, & designed to save you hours each week. What You’ll Have Working In 30 Minutes A role & keyword map spanning SecOps/Detection, DFIR, AppSec, Cloud Security, GRC, Red Team, Threat Intel, IAM/PAM, OT/ICS & Vulnerability Management. Shareable Boolean search strings for Google & job boards to cut noise fast. Always-on alerts & RSS feeds delivering fresh roles to your inbox/reader. A ChatGPT “Cyber Job Scout” prompt that deduplicates, scores fit & outputs tailored actions. A simple pipeline tracker so deadlines & follow-ups never slip.