Information Security Controls Assurance Analyst at The Guardian | England, GBR | Rezi

Information Security Controls Assurance Analyst at The Guardian

Information Security Controls Assurance Analyst

The Guardian · England, GBR

Today

Information Security Controls Assurance Analyst

The Guardian · England, GBR

6 hours ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

The Controls Assurance Analyst will support the Assurance Manager in delivering the information security assurance programme. You’ll perform control testing, coordinate assurance evidence, support audits and compliance activities, monitor remediation actions, and provide assurance reporting that demonstrates the effectiveness of the organisation's security control environment.

Responsibilities

  • Perform scheduled testing of Information Security controls to assess both design and operating effectiveness.
  • Execute control assessments across key security domains including Identity and Access Management, Vulnerability Management, Security Monitoring, Cloud Security, Data Protection and Third Party Security.
  • Maintain documentation supporting compliance with security policies, standards and regulatory requirements, including internal and external Information Security audits.
  • Support assurance activities relating to customer and third-party security assessments.
  • Monitor compliance against Information Security policies, standards and regulatory requirements.
  • Assist in mapping security controls to recognised frameworks including NIST, PCI DSS, ISO 27001, ISO 42001 and assist in identifying compliance gaps and supporting remediation planning.
  • Support assurance activities relating to privacy, information governance and secure data handling.

Requirements

  • Demonstrated experience performing Information Security control testing and assurance activities, including a good understanding of control design and operating effectiveness.
  • Good experience collecting, validating and maintaining assurance evidence.
  • Familiarity with internal and external audit processes.
  • Understanding of Information Security frameworks including ISO 27001, NIST CSF, NIST 800-53 and CIS Controls and experience mapping controls against recognised security frameworks
  • Understanding of security control domains including Identity and Access Management, Vulnerability Management, Security Monitoring, Cloud Security, Data Protection
  • Strong analytical and documentation skills with the ability to produce clear reporting, dashboards and management information.
  • Strong communication and stakeholder engagement skills.

Skills

  • Information Security control testing
  • Assurance activities
  • Control design
  • Operating effectiveness
  • Assurance evidence collection
  • Assurance evidence validation
  • Assurance evidence maintenance
  • Internal audit processes
  • External audit processes
  • ISO 27001
  • NIST CSF
  • NIST 800-53
  • CIS Controls
  • Security framework mapping
  • Identity and Access Management
  • Vulnerability Management
  • Security Monitoring
  • Cloud Security
  • Data Protection
  • Analytical skills
  • Documentation skills
  • Reporting
  • Dashboards
  • Management information
  • Communication skills
  • Stakeholder engagement

Location

  • Kings Cross

Work Type

  • Hybrid
  • Remote

Salary/Compensations

  • The minimum salary for any full-time role within the organisation is £30,000 per annum. Salary ranges are dependent on skills and experience

Benefits

  • 30 days of annual leave per year plus bank holidays
  • Option to purchase an additional 5 days of annual leave
  • Pension scheme: If you contribute 5% then we will contribute 8-12% (depending on your age)
  • 2 volunteering days annually
  • Option of payroll giving
  • Season ticket loans
  • Private healthcare
  • Life cover
  • Income protection
  • Eye tests
  • Optional dental insurance
  • Enhanced maternity, paternity, adoption and shared parental leave policies
  • IVF, menopause, baby loss, and trans equality policy support
  • Access to employee benefits platform for tailored support for health and wellbeing
  • Free yoga and pilates classes
  • Corporate gym membership
  • Cycle to work scheme

About the Company

  • Join our team at the Guardian and be a part of a diverse and inclusive global organisation that delivers fearless, investigative journalism and holds power to account.
  • Our team of award-winning journalists, cutting-edge commercial professionals and industry-leading digital experts are committed to making a difference and represent a wide range of backgrounds and perspectives.
  • We offer a challenging and exciting environment for career development, with a focus on training, growth and fostering an inclusive culture.
  • We became the first major media organisation to achieve B Corp status.
  • Our canteen has views overlooking the Regents Canal and caters for breakfast, lunch and dinner.

Equal Opportunity

  • We actively encourage applications from groups traditionally underrepresented in the UK media
  • We value and respect all differences (seen and unseen) in all people.
  • We aspire to have inclusive working experiences and an environment that reflects the audience we serve, where our people have equal access to career development opportunities, their voices are heard and can contribute to our future.
  • We actively encourage applications from people of all backgrounds.
  • All roles at the Guardian are open for everybody to apply.
  • It is important to us that you feel supported and comfortable throughout your recruitment process, in order to perform your best.
  • Please let us know if there are any changes we could make to help your application, this includes providing documents in accessible formats or personalising the process to better support your needs.
  • Guardian News and Media is proud to be a London Living wage employer.