Information Security Analyst (GRC)
United Kingdom
Moneycorp
moneycorp is an award-winning foreign exchange specialist with over 40 years experience in currency exchange. Save money with moneycorp today.- Provide support to the management of the existing Information Security Management System: governance, risk management, remediation activities
- Review Information Security for key Moneycorp Third-party vendors, aligned to Moneycorp’s risk appetite
- Manage Moneycorp’s Information Security Training and Awareness programme
- Responsible for completing daily tasks, providing KPIs, and triaging ticket queue with SLAs
- At least 3 yrs Experience in an information or IT security related role within a financial or regulated firm
- Previous experience of conducting Information Security 3rd party supplier security reviews
- Applicants will have a technical background with exposure to IT, security, network or Cloud infrastructure administration
- Fully understand security concepts such as identity access management, defence in depth, least privilege, resilience (technical & operational), segregation (networks & duties), cloud security (shared responsibility)
- Ability to support audits, conduct risk assessments, and implement mitigation strategies
- Familiarity with Data Protection and Financial regulations i.e. GDPR, FCA regulations, PRA guidelines, UK Data Protection Act, DORA
- Understanding of PCI DSS, SWIFT CSP, and operational resilience frameworks
- Knowledge of implementing ISO27001:2022
- Familiar with: SOC2 Type II, NIST CSF, PCI DSS and NCSC guidance
- Technically astute, understands technical risks to the business and can provide clear risk assessment analysis to the business. Able to challenge where risks are outside of tolerance in an evidenced led, logical and methodical
- Network Security & Protocols – Deep understanding of TCP/IP, firewalls, VPNs, IDS/IPS, and secure network architecture and browser filtering technologies
- Email – understands email delivery, and controls i.e. tracing, analysing, filtering, DMARC, SPF, DKIM
- Security Frameworks & Controls – Familiarity with NIST, CIS Controls, and UK-specific frameworks like Cyber Essentials
- Cloud Security – Knowledge of securing Azure, including IAM, encryption, and monitoring (Sentinel experience beneficial)
- Data Protection & Encryption – Understanding of cryptographic protocols and secure data handling practices
- Experience in Information Security Awareness and Training, phishing simulations, managing online training (CBT), providing content for awareness
- Attention to Detail – Critical for monitoring logs, reviewing configurations, and writing formal documentation
- Analytical Thinker – Ability to assess complex systems and identify potential risks and vulnerabilities
- Ability to disseminate documentary evidence to provide objective analysis
- Maintain a current understanding of common vulnerabilities and appropriate remediation
- Communicating and documenting user reported security problems and incidents
- Keeps up to date with the latest Information and Cyber news, threats and incidents
- Appreciate when to escalate issues upwards
- BSc/MSc in Information Security, computing, science, technology, engineering or mathematics (STEM) subject
- Known security qualifications such as CompTIA Security+, CySA+, CASP, or other established certifications from ISC2, ISACA GIAC or EC-Council.
- Azure Fundamentals AZ-900; Security, Compliance and Identity Fundamentals SC-900; or other Microsoft certification
- English
- A passion for cyber security and a keen interest in IT
- Highly motivated, responsible, reliable and organised individual able to use own initiative, manage own time and workload and an excellent attention to detail
- Inquisitive, keen to learn
- Capable of developing a strong working relationship with peers to encourage good security practices
- Collaborative and team-oriented, flexible attitude, adhering to a high standard of ethical behaviour
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Agile Audits Azure Banking CASP+ Cloud Compliance CompTIA Encryption Firewalls GDPR GIAC Governance IAM IDS IPS ISACA ISO 27001 KPIs Mathematics Monitoring Network security NIST PCI DSS Risk assessment Risk management Sentinel SLAs SOC 2 STEM TCP/IP VPN Vulnerabilities
Perks/benefits: Career development Competitive pay Flex hours Flex vacation Health care Startup environment
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.