IU

Information Security and Assurance Analyst

InfoTrack UK
Posted 3 hours ago
United KingdomHybridEngineering & Development
Is this job info correct?

Location: Woking (hybrid after probation)


Salary: Up to £35,000, depending on your skills experience


Do you have a keen eye for detail and an interest in information security, assurance and governance?


Are you confident working with both technical and non-technical stakeholders, and enjoy making sure information is accurate, evidence-based and properly documented?


We're looking for an Information Security and Assurance Analyst to join our IT and Governance team and play an important role in supporting customer security assurance and the continued operation of InfoTrack’s ISO/IEC 27001:2022 Information Security Management System.


This is an excellent opportunity for a methodical and proactive IT or information security professional to coordinate customer assurance activities, maintain ISMS records and evidence, track risks and corrective actions, and support security controls, awareness activities and audit readiness across a growing technology business.


About InfoTrack


InfoTrack is a market-leading provider of technology solutions for the conveyancing industry, helping law firms deliver a best-in-class service to people buying and selling homes.


As our market share continues to grow, so does the importance of maintaining reliable, secure and well-governed technology services. Our UK IT and Governance team plays a key role in supporting our security framework, meeting customer assurance requirements and ensuring we continue to operate to high standards.


This role offers exposure across technical operations, governance, customer assurance and organisational stakeholders, with opportunities to broaden your existing skills and take on increasingly varied assurance work.


What you’ll be doing


In this role, you will:


• Coordinate and complete customer Due Diligence Questionnaires, security questionnaires and Site Security Surveys

• Gather, organise and maintain supporting assurance evidence, ensuring information is accurate and up to date

• Work with internal subject-matter experts to obtain accurate technical, security and governance information

• Ensure customer assurance responses are consistent with approved policies, controls and implemented practices

• Maintain approved assurance responses and supporting evidence, and support customer assurance meetings and assessments where required

• Support the operation and maintenance of InfoTrack’s ISO/IEC 27001:2022 Information Security Management System

• Maintain ISMS records, registers, documentation and control evidence, including the information security risk register and associated risk-treatment actions

• Monitor scheduled ISMS reviews and recurring governance activities, following up with responsible owners to ensure actions are completed within the required timescales

• Coordinate and track periodic user access reviews and scheduled security control and log-review activities

• Maintain evidence demonstrating completion of recurring security controls and identify missed, incomplete or overdue activities

• Coordinate information security awareness and training activities, monitor participation and completion, and maintain associated records and reporting

• Support internal, external, certification and surveillance audit activity, including coordinating evidence and information requests

• Maintain records of audit findings, observations, corrective actions and preventative actions, tracking actions through to completion


What we're looking for


Essential:


• Experience within information security, assurance, compliance or IT controls; or at least two years’ experience in first-line, second-line, service desk, infrastructure support or a comparable technical IT role

• A working understanding of common IT services, security controls and operational processes

• Awareness of ISO 27001, information security risk and evidence-based assurance

• Strong written communication skills and excellent attention to detail

• The ability to understand technical or control-based information, identify logical inconsistencies and seek appropriate clarification or evidence

• Confidence working with technical and non-technical stakeholders at different organisational levels

• Strong organisational, record-keeping and follow-up skills

• The ability to manage recurring activities, actions and deadlines effectively

• Sound judgement when handling confidential or sensitive information


Desirable (but not essential):


• Experience completing customer security questionnaires, DDQs or assurance assessments

• Exposure to Site Security Surveys or customer security reviews

• Experience supporting ISO 27001 certification or audit activity

• Experience maintaining information security risk registers and risk-treatment actions

• Understanding of corrective action, preventative action and root-cause analysis

• Experience coordinating user-access reviews or recurring security-control checks

• Experience administering information security awareness programmes

• Knowledge of Cyber Essentials, UK GDPR or related security requirements

• Broad understanding of end-user computing, identity and access, networks, systems and common IT operational controls

• Experience within technology, SaaS, legal services or another regulated environment

• A relevant security qualification, such as ISO 27001 Foundation or Internal Auditor, CISMP, Security+ or equivalent


Working Hours


• Your working week will be full time, generally 9am – 5.30pm, with the role primarily based in our Woking office

• Occasional travel will be required to other UK offices, including Waterloo, Maidstone, Southport and Leeds

• Following successful completion of the six-month probation period, you’ll have the opportunity to work from home for up to two days per week, subject to operational and departmental requirements


Salary and Progression


• Salary of up to £35,000, aligned with your experience and skills

• You’ll have the opportunity to develop your knowledge across information security, assurance, governance and customer security requirements

• Guidance and mentoring will be available from the Head of UK IT and Governance to support development in areas where you may have less experience, including ISO 27001, customer assurance, risk management, ISMS maintenance and audit activity

• The role provides exposure across technical operations, governance, customer assurance and organisational stakeholders, with opportunities to broaden your existing capability and take on increasingly varied assurance work


Benefits and Rewards


At InfoTrack, we believe in rewarding our people and creating a positive workplace culture.


You’ll benefit from:


• 25 days annual leave, plus bank holidays

• Flexible working options, including hybrid working after probation

• Private health insurance, including dental, optical and hearing cashback

• Life assurance (worth x4 your base salary)

• 24/7 health advice line and access to virtual GP appointments

• In-house barista: enjoy freshly brewed drinks throughout the day

• Office snacks, including fruit and refreshments

• Regular team breakfasts and lunches

• Recognition awards: £100 spot prizes for going above and beyond

• “Work From Anywhere” weeks: work remotely from a location of your choice

• Referral bonus: earn up to £2,000 for successful referrals

• Birthday and work anniversary gifts

• Regular social events including summer and Christmas parties, hikes, pub quizzes and more


If you’re looking to develop your career in information security and assurance while gaining exposure to customer security, governance, risk and ISO 27001 in a growing technology business, we’d love to hear from you.


If you have any questions about the role or require any reasonable adjustments as part of the recruitment process, please let us know at careers@infotrack.co.uk.

Similar jobs