Job type
PermanentLocation
LondonWorking Pattern
Flexible Working,Full-timeSpecialism
Cyber SecurityIndustry
Staffing & EmploymentPay
55000
Information Security and Data Privacy Analyst
We’re on a journey as a global business to build the technology of tomorrow and continue to lead from the front of our industry. We want to redefine and reshape our technology strategy in the face of a rapidly evolving digital world, looking at new ways to leverage AI and innovative technology. Our vision is to create a more integrated and product-led organisation, designing holistic global technology solutions that enable us to continually improve the way we deliver our services, both internally and externally.
The role
The role reports to the Head of ISDP Governance and is responsible for supporting the development, review, implementation and maintenance of Enterprise ISDP policies, procedures and guidelines in line with the ISO 27001 standard. The role involves implementation of a security risk management framework, driving employee secure behaviours and liaising with third line of defence on internal and external assurance activities.
Key Responsibilities:
Policies and framework management:
- Implement and maintain information security policies, procedures, and guidelines aligned with ISO 27001 standards.
- Implement and maintain ISDP intranet for easy access to ISDP artefacts.
- Effective and consistent implementation of these policies and framework across the organisation.
- Support delivery of the ISO27001 certification roadmap.
Security culture:
- Develop, renew, implement and maintain annual training for employees, including new hires.
- Conduct regular targeted campaigns to promote a culture of security.
- Perform periodic simulated phishing exercise to assess employee awareness.
- Work with relevant business units to improve cybersecurity awareness.
Assurances:
- Support internal or external ISDP assurance activities.
- Support management of security management plan (SMP) of activities with strategic suppliers.
- Collaborate with internal and external stakeholders to coordinate assurance activities effectively.
Stakeholder Communication:
- Appropriately communicate security requirements to key internal and external stakeholders.
- Ensure alignment with business goals and risk management strategy.
Metrics and Reporting:
- Support development of a metrics framework to effectively measure employee behaviour and compliance with policies.
- Ensure the effectiveness of an awareness programme.
Experience with ISO27001 Readiness
GDPR - NIST - DORA
Cyber Essentials
Supporting Dept with policies and frameworks, has strong knowledge of ISO2701, security Awareness processes.
Support Also, the US market, various time zones.
Tasks also Involve security governance, internal audits, suppliers, project management and Delivery experience.
Working With the vendor controls, service levels, KPI's, for visibility, checking implementation.
Implementing Data classification schemes.
What you'll get in return
Flexible working options are available.
- The opportunity to make a seismic impact and help enable business through the delivery of effective digital solutions.
- The opportunity to work in a business that values people at the heart of what they do and creates a supportive and inclusive environment to enable you to flourish.
- The reward and benefits associated with this role will be competitive for the market and experience of the successful candidate.