Information Security Analyst

2 weeks ago


Greater London, United Kingdom C2 RISK Full time

About C2


C2 Risk exists to solve complex cyber and information security challenges and has extensive experience managing risk across all three sectors in local and central government, healthcare, financial services, retail, and not-for-profit/charity enterprises. Our approaches and methodologies blend a pragmatic mix of technical and human control measures to reduce vulnerability, limit risk, realise resilience and enable businesses to operate efficiently.


Using international standards and industry-specific regulations, C2 Risk helps its customers to assess, identify and treat threats to their operations and business. We engage at an executive level with our customers and maintain that culture, leadership, behaviour, and education are key factors for success. Even in today’s world of pervasive communications and the Internet of Things, technology is developed to deliver value to people. It is also attacked and targeted by people, and frequently the most challenging vulnerabilities are the people who interact with it.


Our human-centric approach to cyber security starts by understanding what the business is trying to achieve, what part people play in realising those objectives, and what risks threaten the vision and aspirations. This enables us to help our clients to define and implement the right processes, prepare the people and organisation, and choose the most appropriate technology so that security becomes an enabler and differentiator, not an obstacle.


We actively develop innovative and unique technology to enable us to deliver our services to clients in the most efficient, consistent, insightful, and consumable way possible. These technology platforms allow us to deliver the cross benefits of both expert consultancy and efficient cloud services supported by deep data analytics.


With services that generate value from strategy and governance, through to delivering capability into operations, C2 Risk works side by side with our clients as their security partners on the journey to see resilience realised.


Roles and Responsibilities:


  • Conduct comprehensive security risk assessments of third-party vendors and partners using industry-standard frameworks, such as NIST CSF, ISO 27001, and PCI DSS. The assessments will include but not be limited to the following areas: information security, privacy, data protection, and regulatory compliance risks.
  • Develop and maintain documentation, including risk assessment reports, issue logs, and management reports, to support the third-party risk management program. Ensure the quality of the documentation and completeness of the assessments.
  • Collaborate with various stakeholders, including business owners, legal, procurement, and IT, to identify, evaluate, and manage risks associated with third-party vendors and partners. Provide guidance and recommendations on how to mitigate or remediate identified risks.
  • Review and evaluate third-party vendor and partner security policies, standards, and controls to ensure compliance with our company's security requirements. Provide feedback and recommendations for improvements as necessary.
  • Develop and maintain metrics and reporting to track the progress and effectiveness of the third-party risk management program. Ensure that the metrics and reporting are accurate, timely, and actionable.
  • Participate in third-party vendor and partner security audits and assessments conducted by external auditors or regulators. Coordinate and facilitate the assessments, as necessary.
  • Stay up to date with industry trends, emerging threats, and regulatory requirements related to third-party risk management. Share knowledge and expertise with other team members and stakeholders.


Education and Experience/Skills:


  • Recent graduate with a Bachelor's or Master's degree in Cybersecurity, Computer Science, Information Technology, or a related field.
  • Strong academic background in cybersecurity, information security, or a closely related field.
  • Understanding and familiarity with industry-standard security frameworks such as ISO 27001, NIST, or other relevant frameworks.
  • Proficiency in creating and understanding security reports.
  • Ability to articulate complex security concepts and findings in a clear and concise manner.
  • Excellent written and verbal communication skills to convey security-related information effectively.
  • Ability to work collaboratively with cross-functional teams within the organisation.
  • Proactive attitude and willingness to take initiative in learning and contributing to information security efforts.


Benefits:


  • Gain practical, hands-on experience in identifying, assessing, and mitigating security risks for diverse client environments.
  • Develop a deep understanding of industry-standard security frameworks such as ISO 27001 and NIST, contributing to a well-rounded knowledge base.
  • Work closely with experienced professionals in the information assurance field, receiving mentorship and guidance to accelerate professional growth.
  • Explore potential career paths within the organisation, with the possibility of transitioning into full-time positions upon successful completion of the internship.
  • Receive constructive feedback on performance, allowing you to continuously improve and tailor their skills to the demands of the information security field.


NOTE: Sponsorship is not available for this position. Applicants must have the right to work in the UK to be eligible for this opportunity. Please apply only if you have experience in third-party risk management.



  • Kingston upon Thames, Greater London, United Kingdom JNC Recruitment Limited Full time €68,000

    Information Security Analyst Kingston upon Thames or Eastleigh - Hybrid Up to £68,000 Per Annum + Car Allowance We are working with an established international services company as they search for an enthusiastic Information Security Analyst to help maintain a secure enterprise IT estate. This position is available as hybrid working in the office...


  • London, Greater London, United Kingdom Verint Full time

    Role OverviewVerint is seeking a highly skilled Information Security Analyst to join our Global SOC Infrastructure team. As a front-line Operations Centre role, you will play a critical part in supporting our security services around the world.This internal triage analyst position requires you to assess inbound security data and communications to evaluate...


  • London, United Kingdom Cititec Talent Full time

    Information Security Analyst (12-Month Contract) Location: Hybrid, London Duration: 12 Months Sector: Banking Paying up to £350 per day Inside IR35 Role Overview: We are seeking an experienced Information Security Analyst to support our regional Information Security and IT Risk functions. This role involves critical daily support and...


  • London, United Kingdom Cititec Talent Full time

    Information Security Analyst (12-Month Contract)Location: Hybrid, LondonDuration: 12 MonthsSector: BankingPaying up to £350 per day Inside IR35Role Overview:We are seeking an experienced Information Security Analyst to support our regional Information Security and IT Risk functions. This role involves critical daily support and collaboration with the...


  • London, United Kingdom Cititec Talent Full time €350

    Information Security Analyst (12-Month Contract) Location: Hybrid, London Duration: 12 Months Sector: Banking Paying up to £350 per day Inside IR35 Role Overview: We are seeking an experienced Information Security Analyst to support our regional Information Security and IT Risk functions. This role involves critical daily support and collaboration...


  • London, United Kingdom Cititec Talent Full time €350

    Information Security Analyst (12-Month Contract) Location: Hybrid, London Duration: 12 Months Sector: Banking Paying up to £350 per day Inside IR35 Role Overview: We are seeking an experienced Information Security Analyst to support our regional Information Security and IT Risk functions. This role involves critical daily support and collaboration...


  • London, United Kingdom Computappoint Full time

    Senior Process Risk and Control Analyst Base Salary: £80,000 to £90,000 (based on experience) Package: Excellent company benefits & competitive bonus Hybrid Model: 3 days per week in the office Office Location: City of London About the Client and the Role: My client, a highly prestigious, globally renowned name in financial services is seeking a...


  • London Area, United Kingdom Cititec Talent Full time

    Information Security Analyst (12-Month Contract) Location: Hybrid, London Duration: 12 Months Sector: Banking Paying up to £350 per day Inside IR35 Role Overview: We are seeking an experienced Information Security Analyst to support our regional Information Security and IT Risk functions. This role involves critical daily support and collaboration...


  • London Area, United Kingdom Cititec Talent Full time

    Information Security Analyst (12-Month Contract)Location: Hybrid, LondonDuration: 12 MonthsSector: BankingPaying up to £350 per day Inside IR35Role Overview:We are seeking an experienced Information Security Analyst to support our regional Information Security and IT Risk functions. This role involves critical daily support and collaboration with the...


  • London Area, United Kingdom Cititec Talent Full time

    Information Security Analyst (12-Month Contract)Location: Hybrid, LondonDuration: 12 MonthsSector: BankingPaying up to £350 per day Inside IR35Role Overview:We are seeking an experienced Information Security Analyst to support our regional Information Security and IT Risk functions. This role involves critical daily support and collaboration with the...


  • London, United Kingdom Osborne Clarke Full time

    Description Award winning law firm Osborne Clarke are looking for an Information Security Analyst to join their growing Information Security team in in our London or Bristol office. This is a permanent role offering hybrid working. The role of the Information Security Analyst is committed to maintaining the highest level of data security and protecting...


  • London, United Kingdom Cititec Talent Full time €350

    Information Security Analyst (12-Month Contract) Location: Hybrid, London Sector: Banking We are seeking an experienced Information Security Analyst to support our regional Information Security and IT Risk functions. This role involves critical daily support and collaboration with the regional Information Security Manager, focusing on security...


  • London, United Kingdom Cititec Talent Full time €350

    Information Security Analyst (12-Month Contract) Location: Hybrid, London Sector: Banking We are seeking an experienced Information Security Analyst to support our regional Information Security and IT Risk functions. This role involves critical daily support and collaboration with the regional Information Security Manager, focusing on security...


  • London, United Kingdom Cititec Talent Full time

    Information Security Analyst (12-Month Contract) Location: Hybrid, London Sector: Banking We are seeking an experienced Information Security Analyst to support our regional Information Security and IT Risk functions. This role involves critical daily support and collaboration with the regional Information Security Manager, focusing on security...


  • London, Greater London, United Kingdom Octopus Energy Full time

    About Octopus EnergyWe're making electric vehicle ownership as smart and as simple as possible, by building the giant, virtual charging platform of the future. In just three years, Octopus Energy has grown to become one of the largest eMobility players globally, with over 800,000 connected electric vehicle chargers and a customer ecosystem spanning web, iOS,...


  • London, United Kingdom Computappoint Full time

    Senior Process Risk and Control Analyst Base Salary: £80,000 to £90,000 (based on experience)Package: Excellent company benefits & competitive bonusHybrid Model: 3 days per week in the officeOffice Location: City of LondonAbout the Client and the Role:My client, a highly prestigious, globally renowned name in financial services is seeking a Senior Process...


  • London, United Kingdom CMC Markets Full time

    We are looking for an Information Security Analyst to join us on a 3 month Fixed Term Contract.The role involves:Implementing information Security industry standard (ISO27001) documentation (framework, processes, procedures, policy etc) in compliance with standards, specifically BAIT.Defining and documenting reporting, responsibilities, and processes for...


  • London, Greater London, United Kingdom Hays PLC Full time

    Job Title: Information Security Business AnalystJob Description:Our client, a well-known firm, is seeking an experienced Business Analyst with a strong background in Information Security. The ideal candidate will have a proven track record of working in highly regulated environments and have expertise in DevSecOps, IAM, PAM, DLP, and NDR.Key...


  • London, Greater London, United Kingdom Cynergy Bank Limited Full time

    About the RoleWe are seeking a highly motivated and detail-oriented Information Security Analyst to join our security team at Cynergy Bank Limited. As a key member of our team, you will play a critical role in ensuring the bank's information systems are secure, compliant with industry regulations, and aligned with risk management practices.Key...


  • London Area, United Kingdom Computappoint Full time

    Senior Process Risk and Control Analyst Base Salary: £80,000 to £90,000 (based on experience) Package: Excellent company benefits & competitive bonus Hybrid Model: 3 days per week in the office Office Location: City of London About the Client and the Role: My client, a highly prestigious, globally renowned name in financial services is seeking a...