We are seeking an Information Security and Assurance Analyst to support the protection, resilience and effective governance of... Read more
We are seeking an Information Security and Assurance Analyst to support the protection, resilience and effective governance of information systems, data and technology services. This role will contribute to the development and maintenance of security controls, assurance processes and risk management activities, helping to ensure that information security requirements are understood and consistently applied across the organisation. You will work with colleagues across technology, business and operational teams to promote good security practices and provide practical, risk-based advice.
Key responsibilities will include supporting security risk assessments, reviewing control effectiveness and maintaining accurate records of risks, issues, exceptions and remediation actions. You will assist with internal and external audits, compliance reviews, supplier assurance activities and the preparation of evidence, reports and management information. The role will also involve monitoring security policies and standards, identifying opportunities for improvement, contributing to incident investigations and supporting the coordination of actions arising from security events, audits and assurance reviews. You may also help deliver security awareness activities and provide guidance on data protection, access management, vulnerability management and secure working practices.
The successful candidate will have experience in information security, IT assurance, risk, governance, audit or a related discipline, together with a sound understanding of security frameworks, policies, controls and regulatory requirements. You should be analytical, organised and confident in assessing information, identifying weaknesses and communicating recommendations to both technical and non-technical audiences. Strong written and verbal communication skills, attention to detail and the ability to manage competing priorities are essential. Experience with recognised frameworks such as ISO 27001, the NIST Cybersecurity Framework, COBIT or comparable standards would be advantageous, as would relevant professional qualifications or demonstrable equivalent experience. A proactive approach, sound judgement and a commitment to continuous improvement are central to success in this role.
Read lessWoking, England, United KingdomPermanent
We are seeking an experienced Information & Cybersecurity Assurance Manager to lead the development, coordination and continuous improvement... Read more
We are seeking an experienced Information & Cybersecurity Assurance Manager to lead the development, coordination and continuous improvement of information security assurance activities. This role will provide independent oversight of cybersecurity controls, policies and risk management practices, helping to ensure that technology, information and business processes remain secure, resilient and compliant with applicable regulatory and industry requirements.
Key responsibilities will include maintaining the cybersecurity assurance framework; planning and delivering internal control reviews, risk assessments and assurance testing; monitoring remediation activities; and preparing clear reports for senior stakeholders and governance forums. You will work closely with technology, risk, compliance, audit and operational teams to identify control weaknesses, assess emerging threats and agree practical, risk-based improvements. The role will also support third-party and supplier assurance, review security exceptions, contribute to incident and lessons-learned processes, and help ensure that security policies, standards and procedures are effectively implemented. You may also be involved in audit preparation, regulatory submissions, security metrics and the continuous enhancement of assurance methodologies.
Applicants should have substantial experience in information security, cybersecurity assurance, IT audit, risk management or a closely related discipline, ideally within a complex or highly regulated environment. You will have a strong understanding of recognised security frameworks and standards, such as ISO 27001, NIST, COBIT or equivalent, together with experience assessing technical and organisational controls. Relevant professional qualifications, such as CISA, CISSP, CISM, CRISC or ISO 27001 Lead Auditor, are desirable. Strong analytical, report-writing and stakeholder management skills are essential, as is the ability to communicate complex security matters clearly to both technical and non-technical audiences. A pragmatic, collaborative approach and a commitment to maintaining high standards of confidentiality, integrity and professional judgement are also required.
Read lessGuildford, England, United KingdomPermanent
We are seeking a Cyber Security and Information Assurance Lead to provide strategic and operational leadership across cyber... Read more
We are seeking a Cyber Security and Information Assurance Lead to provide strategic and operational leadership across cyber security, information assurance, risk management and data protection. The successful candidate will help safeguard critical systems, information assets and services by developing robust security frameworks, policies and controls aligned with recognised standards and regulatory requirements. You will work closely with technology, operational and business stakeholders to ensure that security is embedded throughout the organisation’s services, projects and change programmes.
Key responsibilities will include leading the assessment and management of cyber and information risks; maintaining security policies, standards, procedures and assurance documentation; and overseeing compliance with relevant legislation, regulations and good-practice frameworks. You will coordinate security audits, risk assessments, control testing and remediation activity, providing clear reports and recommendations to senior leadership. The role will also contribute to incident response, business continuity, disaster recovery and third-party assurance, helping to ensure that risks are identified, escalated and managed effectively. You will promote security awareness and foster a culture of continuous improvement through guidance, training and effective stakeholder engagement.
Applicants should have substantial experience in cyber security, information assurance, governance, risk and compliance, ideally within a complex or regulated environment. You will have a strong understanding of security principles, risk assessment methodologies, data protection, incident management and relevant industry standards such as ISO 27001, NIST or equivalent frameworks. Professional qualifications in information security, risk management or auditing are desirable. Excellent communication, influencing and analytical skills are essential, along with the ability to translate technical risks into clear business advice. You should be organised, pragmatic and confident working independently while collaborating with colleagues, suppliers and senior decision-makers.
Read lessWarrington, England, United KingdomPermanent
An opportunity is available for an Information Security Assurance Administrator to support the effective management, monitoring and continuous... Read more
An opportunity is available for an Information Security Assurance Administrator to support the effective management, monitoring and continuous improvement of information security controls. The role will assist with maintaining assurance activities across systems, processes and third-party services, helping to ensure that security requirements are understood, implemented and evidenced. You will work with colleagues across technology, risk, compliance and operational teams to coordinate security reviews and support a strong culture of information protection.
Key responsibilities will include maintaining security assurance records, control frameworks, policies, procedures and risk documentation; coordinating evidence collection for internal and external audits; tracking remediation actions and escalating overdue or significant issues; and preparing clear reports, dashboards and updates for relevant stakeholders. You will assist with security risk assessments, supplier assurance reviews, control testing and periodic reviews of access, vulnerability, incident and business continuity arrangements. The role will also involve scheduling meetings, recording decisions, managing action logs and ensuring that documentation is accurate, current and readily available.
The successful candidate will have experience in information security, IT governance, risk, compliance, audit coordination or a related administrative role. You should be organised, detail-oriented and confident handling sensitive information, with the ability to manage competing priorities and meet deadlines. Strong written and verbal communication skills are essential, along with the ability to explain security requirements clearly to both technical and non-technical audiences. Familiarity with recognised information security principles, risk management practices, audit processes, data protection requirements or frameworks such as ISO 27001, NIST or Cyber Essentials would be advantageous. A proactive approach, sound judgement and a commitment to maintaining high standards of confidentiality and accuracy are also required.
Read lessBristol, England, United KingdomPermanent
We are seeking a Cyber Assurance Analyst to support the delivery of effective cybersecurity governance, risk management and... Read more
We are seeking a Cyber Assurance Analyst to support the delivery of effective cybersecurity governance, risk management and assurance activities in Belfast. This role will help assess the organisation’s security posture, identify areas for improvement and provide clear, practical advice to stakeholders across the business. You will contribute to maintaining a strong control environment and promoting consistent compliance with internal policies, regulatory expectations and recognised security standards.
Key responsibilities will include carrying out security control reviews, risk assessments and assurance checks; supporting the management and tracking of remediation actions; and preparing concise reports, dashboards and briefings for technical and non-technical audiences. You will assist with audits, evidence gathering and responses to security questionnaires, while helping to monitor compliance with frameworks such as ISO 27001, NIST or similar. The role will also involve reviewing security policies and procedures, contributing to risk and exception processes, supporting third-party assurance activities, and working with colleagues to improve security awareness and control effectiveness. You will be expected to maintain accurate records, challenge gaps constructively and escalate significant risks where appropriate.
The successful candidate will have experience in cybersecurity, information assurance, IT risk, compliance or a related discipline, together with a good understanding of security controls, risk principles and audit methodologies. Familiarity with recognised frameworks and standards, data protection requirements, vulnerability management or supplier assurance would be advantageous. You should be analytical, well organised and confident in interpreting information, identifying trends and producing high-quality written outputs. Strong communication and stakeholder management skills are essential, as is the ability to manage competing priorities and work collaboratively. Relevant professional qualifications, such as CISSP, CISM, CRISC, ISO 27001 or equivalent experience, are desirable. This is an excellent opportunity to develop your career while helping strengthen cyber resilience across a complex and evolving environment.
Read lessBelfast, Northern Ireland, United KingdomPermanent
We are seeking a Security Assurance Analyst to support the organisation’s information security, risk management and compliance objectives.... Read more
We are seeking a Security Assurance Analyst to support the organisation’s information security, risk management and compliance objectives. In this role, you will help assess the effectiveness of security controls across systems, applications, suppliers and business processes. You will work with stakeholders across technology and operations to identify risks, recommend practical improvements and help ensure that security requirements are understood and consistently applied.
Your responsibilities will include planning and conducting security assurance reviews, documenting findings and tracking remediation activities through to completion. You will maintain risk and control registers, support internal and external audits, and contribute evidence for regulatory, contractual and governance requirements. You will also review security policies, standards and procedures, assist with third-party and supplier assessments, and help evaluate areas such as access management, vulnerability management, incident response, data protection and business continuity. Clear reporting will be essential, including the preparation of concise updates, risk summaries and recommendations for senior stakeholders.
The successful candidate will have experience in information security, IT risk, assurance, audit, governance or a related discipline, with a good understanding of security frameworks and control principles. Familiarity with standards such as ISO 27001, NIST, CIS Controls, SOC 2 or relevant data protection regulations would be advantageous. You should be analytical, organised and confident in challenging processes constructively, with the ability to translate technical issues into clear business impacts. Strong written and verbal communication skills, attention to detail and the ability to manage multiple priorities are essential. Professional qualifications in information security, audit, risk or compliance are desirable, as is experience using governance, risk and compliance tools. This role offers the opportunity to contribute to meaningful security improvements while developing broad experience across assurance and risk management.
Read lessCambridge, England, United KingdomPermanent
We are seeking a Security Assurance Analyst to support the delivery of robust information security, risk management and... Read more
We are seeking a Security Assurance Analyst to support the delivery of robust information security, risk management and assurance activities across a complex technology and business environment. The successful candidate will help assess whether security controls are suitably designed, consistently applied and operating effectively, while providing clear, practical advice to support continuous improvement. This is an opportunity to work with stakeholders across technology, operations, compliance and governance functions.
Key responsibilities will include planning and performing security control assessments, reviewing policies, standards, procedures and technical evidence, and identifying control gaps or areas of non-compliance. You will contribute to risk assessments, audit preparation, supplier and third-party assurance reviews, security exception management and remediation tracking. The role will involve documenting findings, evaluating the potential impact of identified risks, agreeing proportionate corrective actions and monitoring progress through to completion. You will also help prepare management reports, assurance dashboards and briefing materials for governance forums, ensuring that complex security matters are communicated clearly to both technical and non-technical audiences.
Applicants should have experience in information security, cyber assurance, IT audit, risk or a related discipline, with a practical understanding of security frameworks, control principles and regulatory expectations. Familiarity with standards such as ISO 27001, NIST, COBIT or CIS is desirable, as is experience assessing cloud services, applications, infrastructure or third-party suppliers. You will need strong analytical and investigative skills, excellent written and verbal communication, and the ability to challenge constructively while building effective working relationships. Relevant professional qualifications or certifications, such as CISA, CRISC, CISSP, ISO 27001 or equivalent experience, would be advantageous. A proactive, organised approach and the confidence to manage multiple priorities are essential.
Read lessCambridge, England, United KingdomPermanent
We are seeking an experienced Security Assurance Lead to strengthen the organisation’s approach to information security governance, risk... Read more
We are seeking an experienced Security Assurance Lead to strengthen the organisation’s approach to information security governance, risk management and regulatory compliance. In this role, you will lead assurance activities across technology, operational and third-party environments, providing confidence that security controls are appropriately designed, implemented and operating effectively. You will work closely with senior stakeholders, technology teams, internal audit and external partners to promote a consistent, risk-based approach to security assurance.
Your responsibilities will include developing and maintaining the security assurance framework, policies, standards and control requirements. You will plan and deliver control assessments, risk reviews, supplier assurance activities and audit engagements, while tracking findings through to effective remediation. The role will involve analysing evidence, identifying control weaknesses, preparing clear reports for governance forums and advising on practical improvements. You will also support regulatory and client assurance requests, contribute to security metrics and reporting, and help ensure that security risks are understood, prioritised and managed within agreed tolerances.
The successful candidate will have substantial experience in information security, technology risk, audit, compliance or a related assurance discipline, ideally within a complex or regulated environment. You should have a strong understanding of security frameworks and standards such as ISO 27001, NIST, CIS Controls, COBIT or equivalent, together with experience assessing technical and operational controls. Excellent communication and stakeholder management skills are essential, as is the ability to translate complex security matters into concise, actionable recommendations for both technical and non-technical audiences. Professional qualifications such as CISSP, CISM, CRISC, CISA or ISO 27001 Lead Auditor are desirable. A pragmatic, collaborative approach, strong attention to detail and the confidence to challenge constructively will be key to success.
Read lessLondon, England, United KingdomPermanent
We are seeking an experienced Security Assurance Lead to strengthen security governance, assurance, and risk management across a... Read more
We are seeking an experienced Security Assurance Lead to strengthen security governance, assurance, and risk management across a complex technology and business environment. In this role, you will provide trusted advice to senior stakeholders, ensure that security controls are designed and operating effectively, and support the organisation in meeting regulatory, contractual, and industry requirements. You will act as a key point of contact for assurance activities, helping teams understand their security responsibilities and embed secure practices into projects, products, and operational services.
Your responsibilities will include developing and maintaining the security assurance framework, policies, standards, and control requirements; planning and coordinating internal and external audits, assessments, and certifications; and monitoring the remediation of identified risks, control gaps, and audit findings. You will conduct or oversee risk assessments, control reviews, supplier and third-party assurance activities, and security reviews for new or changed services. The role will also involve producing clear reports and management information, tracking key security metrics, and escalating material risks where appropriate. You will work closely with technology, engineering, privacy, compliance, procurement, and operational teams to ensure assurance requirements are practical, proportionate, and consistently applied.
The successful candidate will have substantial experience in information security, security assurance, risk, audit, governance, or a related discipline, together with a strong understanding of recognised frameworks and standards such as ISO 27001, NIST, CIS Controls, SOC 2, or equivalent. Professional qualifications in information security, audit, risk, or compliance are desirable. You will be confident interpreting technical and regulatory requirements, challenging constructively, and communicating complex issues clearly to both technical and non-technical audiences. Strong organisation, analytical ability, attention to detail, and stakeholder management skills are essential. Experience leading assurance programmes, managing remediation plans, and working with third-party providers would be advantageous.
Read lessLondon, England, United KingdomPermanent
We are seeking a Security Assurance Lead to strengthen the organisation’s information security governance, risk management and assurance... Read more
We are seeking a Security Assurance Lead to strengthen the organisation’s information security governance, risk management and assurance capabilities. In this role, you will provide expert guidance on security controls, regulatory obligations and risk treatment across technology, business and third-party environments. You will work with senior stakeholders, technical teams and control owners to ensure that security requirements are clearly defined, consistently implemented and supported by reliable evidence.
Your responsibilities will include developing and maintaining security assurance frameworks, policies, standards and operating procedures; coordinating internal and external audits; and overseeing assessments against recognised security and privacy standards. You will plan and deliver risk-based assurance reviews, identify control weaknesses, assess their potential business impact and agree practical remediation plans. You will monitor progress through to completion, prepare clear reports for governance forums and escalate material risks where appropriate. The role will also contribute to supplier assurance, new technology assessments, security architecture reviews, incident lessons learned and the continuous improvement of control effectiveness.
To succeed, you will have substantial experience in information security, IT risk, audit, compliance or assurance, together with a strong understanding of security governance frameworks and industry standards such as ISO 27001, NIST, CIS Controls or comparable models. Experience working with third-party risk, cloud environments, data protection requirements and regulatory compliance would be advantageous. You should be confident interpreting technical information, challenging constructively and communicating complex risks to both technical and non-technical audiences. Strong analytical, organisational and stakeholder-management skills are essential, along with the ability to manage multiple priorities, influence across teams and deliver high-quality work in a changing environment. Relevant professional qualifications, such as CISM, CISSP, CISA, CRISC or ISO 27001 Lead Auditor, are desirable.
Read lessBristol, England, United KingdomPermanent
All your saved jobs are no longer available or you've already applied.
for the following search criteria