Information Security and Assurance Analyst
Job Summary
Information Security and Assurance Analyst
Location:Woking (hybrid after probation)
Salary:Up to 35000 depending on your skills experience
Do you have a keen eye for detail and an interest in information security assurance and governance
Are you confident working with both technical and non-technical stakeholders and enjoy making sure information is accurate evidence-based and properly documented
Were looking for an Information Security and Assurance Analyst to join our IT and Governance team and play an important role in supporting customer security assurance and the continued operation of InfoTracks ISO/IEC 27001:2022 Information Security Management System.
This is an excellent opportunity for a methodical and proactive IT or information security professional to coordinate customer assurance activities maintain ISMS records and evidence track risks and corrective actions and support security controls awareness activities and audit readiness across a growing technology business.
About InfoTrack
InfoTrack is a market-leading provider of technology solutions for the conveyancing industry helping law firms deliver a best-in-class service to people buying and selling homes.
As our market share continues to grow so does the importance of maintaining reliable secure and well-governed technology services. Our UK IT and Governance team plays a key role in supporting our security framework meeting customer assurance requirements and ensuring we continue to operate to high standards.
This role offers exposure across technical operations governance customer assurance and organisational stakeholders with opportunities to broaden your existing skills and take on increasingly varied assurance work.
What youll be doing
In this role you will:
Coordinate and complete customer Due Diligence Questionnaires security questionnaires and Site Security Surveys
Gather organise and maintain supporting assurance evidence ensuring information is accurate and up to date
Work with internal subject-matter experts to obtain accurate technical security and governance information
Ensure customer assurance responses are consistent with approved policies controls and implemented practices
Maintain approved assurance responses and supporting evidence and support customer assurance meetings and assessments where required
Support the operation and maintenance of InfoTracks ISO/IEC 27001:2022 Information Security Management System
Maintain ISMS records registers documentation and control evidence including the information security risk register and associated risk-treatment actions
Monitor scheduled ISMS reviews and recurring governance activities following up with responsible owners to ensure actions are completed within the required timescales
Coordinate and track periodic user access reviews and scheduled security control and log-review activities
Maintain evidence demonstrating completion of recurring security controls and identify missed incomplete or overdue activities
Coordinate information security awareness and training activities monitor participation and completion and maintain associated records and reporting
Support internal external certification and surveillance audit activity including coordinating evidence and information requests
Maintain records of audit findings observations corrective actions and preventative actions tracking actions through to completion
What were looking for
Essential:
Experience within information security assurance compliance or IT controls; or at least two years experience in first-line second-line service desk infrastructure support or a comparable technical IT role
A working understanding of common IT services security controls and operational processes
Awareness of ISO 27001 information security risk and evidence-based assurance
Strong written communication skills and excellent attention to detail
The ability to understand technical or control-based information identify logical inconsistencies and seek appropriate clarification or evidence
Confidence working with technical and non-technical stakeholders at different organisational levels
Strong organisational record-keeping and follow-up skills
The ability to manage recurring activities actions and deadlines effectively
Sound judgement when handling confidential or sensitive information
Desirable (but not essential):
Experience completing customer security questionnaires DDQs or assurance assessments
Exposure to Site Security Surveys or customer security reviews
Experience supporting ISO 27001 certification or audit activity
Experience maintaining information security risk registers and risk-treatment actions
Understanding of corrective action preventative action and root-cause analysis
Experience coordinating user-access reviews or recurring security-control checks
Experience administering information security awareness programmes
Knowledge of Cyber Essentials UK GDPR or related security requirements
Broad understanding of end-user computing identity and access networks systems and common IT operational controls
Experience within technology SaaS legal services or another regulated environment
A relevant security qualification such as ISO 27001 Foundation or Internal Auditor CISMP Security or equivalent
Working Hours
Your working week will be full time generally 9am 5.30pm with the role primarily based in our Woking office
Occasional travel will be required to other UK offices including Waterloo Maidstone Southport and Leeds
Following successful completion of the six-month probation period youll have the opportunity to work from home for up to two days per week subject to operational and departmental requirements
Salary and Progression
Salary of up to 35000 aligned with your experience and skills
Youll have the opportunity to develop your knowledge across information security assurance governance and customer security requirements
Guidance and mentoring will be available from the Head of UK IT and Governance to support development in areas where you may have less experience including ISO 27001 customer assurance risk management ISMS maintenance and audit activity
The role provides exposure across technical operations governance customer assurance and organisational stakeholders with opportunities to broaden your existing capability and take on increasingly varied assurance work
Benefits and Rewards
At InfoTrack we believe in rewarding our people and creating a positive workplace culture.
Youll benefit from:
25 days annual leave plus bank holidays
Flexible working options including hybrid working after probation
Private health insurance including dental optical and hearing cashback
Life assurance (worth x4 your base salary)
24/7 health advice line and access to virtual GP appointments
In-house barista: enjoy freshly brewed drinks throughout the day
Office snacks including fruit and refreshments
Regular team breakfasts and lunches
Recognition awards: 100 spot prizes for going above and beyond
Work From Anywhere weeks: work remotely from a location of your choice
Referral bonus: earn up to 2000 for successful referrals
Birthday and work anniversary gifts
Regular social events including summer and Christmas parties hikes pub quizzes and more
If youre looking to develop your career in information security and assurance while gaining exposure to customer security governance risk and ISO 27001 in a growing technology business wed love to hear from you.
If you have any questions about the role or require any reasonable adjustments as part of the recruitment process please let us know at.
Required Experience:
IC