Information Security Compliance Analyst
GLORY
Date: 20 hours ago
City: Basingstoke
Contract type: Full time

Department: Legal - Information Security
Location: UK/Basingstoke
In this newly created position, you will be responsible for planning, preparing and undertaking a wide range of Information Security activities. You will work closely with internal and external audit teams and other stakeholders to ensure the effectiveness and compliance of the organization's information security measures. You will also work closely with the procurement team, business units, and third-party vendors to ensure that all third-party risks are identified, assessed, and managed effectively. Strong knowledge of Information Security governance frameworks is essential for this position.
You will be required to use your knowledge and experience to test, document, evaluate, remediate, and improve controls related to Information Security for effectiveness and operational efficiency. You will need to be able to audit all areas of the business where it is needed and take the lead when required. Within this role you will be responsible for supporting customer audits and responding to customer queries on Information Security and Information Systems and the associated functional processes and controls. You will also support third-party auditors to co-ordinate external audit activities to maintain and ensure compliance with industry standards. This will include managing the closure of any actions or findings raised. This new role offers an opportunity to be part of newly established functions to ensure we can evidence the measures put in place to protect our business and that of our customers.
You must be a highly effective communicator and a supportive team player, taking a consultative approach whilst maintaining the integrity and independence of the General Affairs department. You will combine an ability to navigate organisational politics and manage stakeholders, with a talent for operational delivery and a strong sense of accountability for results.
Main Responsibilities
- Review existing documentation of IT controls, business processes, policies, procedures, and management reports for effectiveness and sustainability
- Review, document, evaluate, and test manual and automated controls throughout the IT environment
- Develop and implement audit testing methodologies
- Design audit programs to ensure ongoing evaluation and validation of IT control effectiveness
- Lead and conduct Information Security internal and external audits working to industry standards such as CIS, SOX and ISO27001
- Assessment and evaluation of suppliers’ capabilities against applicable requirements, including GGS policies, standards and procedures
- Lead and conduct Information Security risk assessments of suppliers and vendors
- Working across internal stakeholders to collaborate and ensure that controls adhere to defined policies, process and procedures
- Work with procurement and business units to ensure that suppliers and vendors comply with cyber security policies and standards.
- Lead the completion of customer RFP, RFI due-diligence responses. working across multiple functions, including Sales, Product Development, Information Security and Information Systems to collate applicable information
- Interpret audit results and make conclusions on the adequacy and reliability of controls; prepare and present reports as necessary
- Prioritize audit findings based on severity of risk and non-compliance
- Must have experience of working in an audit function
- Knowledge of Information Security frameworks such as NIST, CIS, SOX, Cyber Essentials, ISO27001, PCI-DSS and SOC
- Contribute to an effective Information Security culture in support of audit objectives
- Establish and maintain relationships across stakeholders, functional teams and external audit teams on relevant standards and frameworks
- A good understanding of Information Security controls
- Ability to appropriately identify and manage Information Security risks identified through audit completion in line with the business’s risk appetite
- Able to produce clear and comprehensive audit documentation
- Strong written and verbal communication skills
- Commitment to excellence and high standards; strong organizational skills; able to manage time, priorities and workload
- Ability to work autonomously and drive improvement
- Comfortable to challenge seniority and existing processes
- Knowledge of OneTrust or ServiceNow an advantage
- 25 days' holiday a year with the opportunity to buy up to five additional days each year
- Competitive Company pension scheme
- Ongoing training and development
- Private medical insurance for all employees, (enhanced membership can be purchased for other family members)
- Life assurance
- Income protection scheme
- Dental insurance for all employees
- Employee assistance programme
- Loyalty awards
- Employee wellbeing events and Mental Health First Aiders
- Employee My Benefits portal offering extensive retail discounts
- Opportunity to volunteer for charity work
How to apply
To apply for this job you need to authorize on our website. If you don't have an account yet, please register.
Post a resumeSimilar jobs
HGV Class 2 Hiab - AVS Basingstoke
Lawsons (Whetstone) Ltd,
Basingstoke
8 hours ago
Company OverviewAVS is part of the Lawsons Group, which is the UK’s largest independent fencing, timber and builders’ merchants and now boasts 35 branches, 700 employees and £165 million turnover, founded in 1921 and operates across London and the South East of England.Position OverviewBe a crucial part of Lawsons as an HGV Class 2 Hiab Driver, ensuring the reliable and...

Customer Data Insight Analyst
The AA,
Basingstoke
1 week ago
Company Description/ Business UnitLocation: Basingstoke (hybrid working 3 office days per week)Employment Type: Permanent, full timeAdditional Benefits: Annual BonusJoin Our Data & Analytics Team: Transforming Data into Our Superpower!Are you passionate about data and eager to make a significant impact? The AA is a well-loved brand with a range of driver services much wider than most people realise. We have...

Senior Operations Manager
Unum UK,
Basingstoke
3 weeks ago
Job Posting End Date: June 20Who are we?We’re a specialist employee benefits provider, striving to create healthy, happy workplaces. As part of the international Unum Group, we’re on a collective mission to help the working world thrive.The roleWhat will you be doing?Position: Senior Operations ManagerLocation: Dorking or Basingstoke (with hybrid working - 3 days per week in office)Reporting To: Head...
