Information Security Analyst
London
The Lancashire Group
Information Security Analyst
Information security is an essential function at Lancashire and so is committed to its continuous improvement; the addition of this role is an important element in achieving its security objectives during Lancashire’s time of digital transformation and growth. Reporting to the Information Security Manager, the post holder will be responsible for evaluating cyber security controls, conducting risk assessments and collaborating with cross-functional teams. The post holder will support the Information Security Manager in maintaining all aspects of information security risk management including responding to security inquiries and incidents, maintaining cyber security governance, and ensuring compliance with relevant regulatory requirements.
Straight-talkingWe feel empowered to share thoughts and ideas, because everyone’s voice matters.
CollaborativeWe work together towards common goals, share knowledge and support each other.
Hard-workingWe all have a stake in the company’s success and are proactive in contributing to our goals and vision.
ResponsibleWe focus on achieving tangible results with consistent standards across the Group.
PositiveWe engage with brokers, clients, communities, stakeholders and colleagues professionally and passionately as proud ambassadors of Lancashire.
Application Deadline: 31 July 2025
Department: IT
Employment Type: Permanent - Full Time
Location: London
Description
PurposeInformation security is an essential function at Lancashire and so is committed to its continuous improvement; the addition of this role is an important element in achieving its security objectives during Lancashire’s time of digital transformation and growth. Reporting to the Information Security Manager, the post holder will be responsible for evaluating cyber security controls, conducting risk assessments and collaborating with cross-functional teams. The post holder will support the Information Security Manager in maintaining all aspects of information security risk management including responding to security inquiries and incidents, maintaining cyber security governance, and ensuring compliance with relevant regulatory requirements.
Responsibilities
- Support the Information Security Manager in delivering the Information Security Management System and to drive continuous improvement for information security.
- Evaluate and assess cyber security controls across the business and its third party vendors to ensure compliance with the NIST Cyber Security Framework (CSF).
- Conduct comprehensive risk assessments using the NIST CSF.
- Use risk management techniques to identify cyber threats, risks and issues in a timely manner.
- Support, develop and conduct third-party vendor security assurance activities.
- Collaborate with cross-functional teams to develop and implement risk management activities.
- Respond to security support tickets and other enquiries; providing information security support and escalation.
- Support the creation and collection of metrics, validation of security control performance and the identification of emerging cyber risks.
- Collaborate with the Enterprise Risk Management (ERM) team to maintain, develop and deliver cyber risk reporting and appetite statements.
- Maintain Information Security policy and procedure ensuring content is relevant to the current cyber threat landscape.
- Maintain, develop and test the Cyber Incident Response Plan, ensuring content is relevant to the current cyber threat landscape.
- Monitor, maintain and manage Lancashire compliance with its relevant cyber security regulation obligations.
- Manage actions and output generated by stakeholder engagements; for example customers, regulators, internal and external auditors.
- Maintain currency with emerging security trends, threat intelligence, industry standards and good practice, and security enhancing technologies.
Essential Skills, Knowledge & Experience
- A degree in Computer Science, Cybersecurity, Information Security, or a related discipline, or up to two years of experience in an Information Security role.
- Understanding of cyber security control assessments, either through academic study or practical exposure.
- Familiarity with cyber risk reporting and risk appetite statements, gained through coursework or hands-on experience.
- Knowledge of recognised security frameworks such as NIST CSF, ISO27001, acquired through study or work experience.
- Awareness of cybersecurity compliance requirements with regulatory frameworks such as FCA, PRA, NYDFS.
- Understanding of governance frameworks including policy and procedure development.
- Ability to achieve against agreed deadlines.
- Ability to work both independently and collaboratively.
- Strong interpersonal and communication skills (written and verbal), with the ability to interact with technical and non-technical stakeholders at all levels.
- Strong analytical and problem-solving skills.
- Strong organisation and planning skills.
- A pro-active and enthusiastic approach.
- Knowledge of Microsoft systems (on-premises and Azure cloud), technologies, infrastructure, awareness of systems management and operational support tools.
- Acknowledges and responds positively to exceptional events in information security to meet the objectives of the business.
The Lancashire Way
At Lancashire, we believe our culture sets us apart. The way we behave and approach our work day-to-day is what makes us unique and creates a positive experience for our people, business partners and other stakeholders. Honesty and integrity in all we do is a given and The Lancashire Way reflects our true character and spirit.Straight-talkingWe feel empowered to share thoughts and ideas, because everyone’s voice matters.
CollaborativeWe work together towards common goals, share knowledge and support each other.
Hard-workingWe all have a stake in the company’s success and are proactive in contributing to our goals and vision.
ResponsibleWe focus on achieving tangible results with consistent standards across the Group.
PositiveWe engage with brokers, clients, communities, stakeholders and colleagues professionally and passionately as proud ambassadors of Lancashire.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
2
2
0
Category:
Analyst Jobs
Tags: Azure Cloud Compliance Computer Science Governance Incident response ISO 27001 NIST Risk assessment Risk management Threat intelligence
Perks/benefits: Team events
Region:
Europe
Country:
United Kingdom
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Information System Security Officer jobsIT Security Analyst jobsSecurity Operations Engineer jobsSenior Cybersecurity Engineer jobsSenior Cloud Security Engineer jobsSenior Security Analyst jobsSenior Information Security Analyst jobsCyber Security Specialist jobsInformation Security Manager jobsSenior Product Security Engineer jobsSenior Network Security Engineer jobsSecurity Consultant jobsSenior Information Security Engineer jobsInformation System Security Officer (ISSO) jobsChief Information Security Officer jobsInformation Systems Security Engineer jobsSecurity Specialist jobsSenior Cyber Security Engineer jobsIT Security Engineer jobsCyber Threat Intelligence Analyst jobsSecurity Operations Analyst jobsSenior Software Engineer jobsSenior IT Auditor jobsCybersecurity Specialist jobsNetwork Engineer jobs
Bash jobsCEH jobsTS/SCI jobsEncryption jobsEDR jobsSDLC jobsSplunk jobsThreat detection jobsMalware jobsRMF jobsTerraform jobsFinance jobsIDS jobsSQL jobsTop Secret jobsCompTIA jobsForensics jobsITIL jobsIPS jobsSOC 2 jobsOWASP jobsActive Directory jobsDocker jobsClearance Required jobsGIAC jobs
CRISC jobsIntrusion detection jobsTCP/IP jobsOSCP jobsAnsible jobsHIPAA jobsVPN jobsMITRE ATT&CK jobsDoDD 8570 jobsZero Trust jobsData Analytics jobsJavaScript jobsSOAR jobsCCSP jobsSOX jobsBanking jobsIT infrastructure jobsJira jobsUNIX jobsDNS jobsIndustrial jobsNIST 800-53 jobsKPIs jobsCISO jobsMachine Learning jobs