About the Role
The Information Security Analyst role is a broad and varied position within the CISO function, providing structured exposure to information security governance, regulatory compliance, security awareness, and operational support. This role offers direct involvement in managing the firm's security obligations and responding to evolving regulatory and threat landscapes, serving as a strong foundation for a career in information security.
Responsibilities
- Administer ISGF and ORC meeting logistics, including preparing agendas, collating papers, recording minutes, and tracking actions.
- Maintain the CISO organizational RACI, ensuring it remains current with team structure and responsibilities.
- Compile and distribute the master CISO security reporting pack, consolidating inputs for a consistent governance view.
- Maintain and update technology roadmap tracking documents, collating status updates and producing progress summaries.
- Support the preparation of Board, ExCo, and governance forum presentations and papers.
- Manage the security policies and standards library, tracking review schedules, approvals, and version control.
- Maintain the ISO 27001 evidence library, coordinating evidence collection and supporting audit preparation.
- Administer DORA compliance tracking, gathering evidence, maintaining registers, and flagging gaps.
- Support NYDFS Part 500 compliance activities, including maintaining evidence packs and tracking certification requirements.
- Own Cyber Essentials and SWIFT CSP evidence gathering and submission processes.
- Administer the Risk & Controls Register within Vanta and RiskConnect, keeping control status and evidence current.
- Support Financial Audit and Internal Audit activities through evidence provision, scheduling, and action tracking.
- Administer the annual mandatory security training program, tracking completion rates and producing reports.
- Execute phishing simulation campaigns, analyzing results, producing reports, and coordinating follow-up training.
- Own the security awareness communications calendar, producing and distributing content for firm-wide campaigns.
- Coordinate Executive & Board training logistics, scheduling, and record-keeping.
- Coordinate specialist security training activities, managing scheduling, attendance tracking, and training records.
- Administer vendor onboarding activities, running security questionnaire processes, tracking responses, and maintaining the vendor register.
- Support vendor annual review cycles, coordinating evidence collection, scheduling review meetings, and updating vendor risk records.
- Assist the Operational Security Engineer with routine security operations tasks, including ticket handling, tool administration, and evidence gathering.
- Contribute to the automation of routine tasks by identifying, documenting, and testing repeatable processes.
Requirements
- Degree-level education or equivalent; a subject with an information security, technology, or analytical component is beneficial but not required.
- An interest in pursuing professional security qualifications (e.g., CompTIA Security+, CISMP, BCS Information Security) is expected.
- 0–2 years of professional experience; prior exposure to an information security, compliance, risk, or technology environment is advantageous but not essential.
- Strong organizational skills with the ability to manage multiple parallel tasks, track deadlines, and maintain accurate records.
- Proficient in Microsoft 365 (Word, Excel, PowerPoint, SharePoint).
- Familiarity with security or GRC tooling such as Vanta or RiskConnect is a plus.
- Clear written communication skills, with the ability to produce well-structured reports and documentation.
- Attentive to detail with a methodical approach to evidence gathering, record-keeping, and process execution.
- Genuine interest in information security as a career, with a desire to grow within the CISO function over time.
Skills
- Information Security Governance
- Regulatory Compliance (ISO 27001, DORA, NYDFS)
- Security Awareness
- Operational Support
- Security Operations
- Vendor Risk Management
- Governance Reporting
- Policies and Standards Management
- Risk and Controls Management
- Microsoft 365 (Word, Excel, PowerPoint, SharePoint)
- Security or GRC Tooling (Vanta, RiskConnect)
- Written Communication
- Attention to Detail
- Methodical Approach
- Automation
Location
- UK
Work Type
- Hybrid working (3 days in office)
Experience Level
- 0-2 years professional experience
Education Level
- Degree-level education or equivalent
Benefits
- Contributory personal pension plan
- Life Assurance – 4 times annual salary
- Group Income Protection
- Private Medical Insurance
- Discretionary Bonus
- Competitive Annual Leave
- 2 Volunteering Days
- Benefit Hub
About the Company
- Crown Agents Bank is a regulated UK bank connecting emerging and frontier markets to the rest of the world using FX and payments technology.
- We are transforming payments and FX in emerging markets, reducing friction and ensuring more money reaches those in need.
- Our solutions address challenges of payments being difficult, expensive, unreliable, and opaque in emerging markets.
- We connect hard-to-reach regions to global financial infrastructure, providing access to the best prices and fastest settlement.
- Crown Agents Bank (CAB) combines deep relationships and network strength with innovative digital capabilities and cross-border transaction banking solutions.
- We enable fintech, corporates, governments, development organisations, and banks to move money in, out of, and across hard-to-reach markets.
