Information Security - Security Analyst
Role details
Job location
Tech stack
Job description
At WHSmith our people are at the heart of everything we do. They are the ones that go the extra mile for our customers. The ones that enable our growth. That's why our IT team works closely with stakeholders to develop and implement technology solutions.
As an Information Security Analyst here you will be responsible for the operational and process assurance activities related to the availability, integrity and confidentiality of customer, business partner, employee and business information in compliance with the organisation's information security policies.
What you will be doing :
- Maintaining information security policies, processes, and standards in coordination with internal security and business stakeholders
- Managing and maintain the information & data security roadmap, incident, and information requests
- Working directly with business partners to facilitate risk assessment and management, assessing, and communicating in line with relative policies and processes
- Facilitating the delivery of the information and data security education and awareness training framework across the business to ensure consistent application of policies and standards
- Maintaining technical solutions and procedural controls required to manage information security risk in line with the organisation's information security policies
- Facilitating regular access control, asset inventory reviews and remediation plans, in line with the access control policy and asset management policy
- Partnering with all technology groups(internal and external) as the data security representative on development projects to deliver secure and compliant security operational services
- Documenting evidence in support of annual PCI DSS and privacy impact assessments (DPIA)
Requirements
Do you have experience in SharePoint?, * Experience in a combination of risk management, information security and IT roles (including Audit)
- Knowledge gained through working with common information security management frameworks (e.g.ISO27001, Cyber Essentials, NIST, PCI DSS, SOC2)
- A strong knowledge of Office 365, Teams, and SharePoint
- Knowledge of data protection regulations and requirements
- Experience of PCI-DSS controls and implementation
Benefits & conditions
- Hybrid Working Model from home and in the office
- 4pm Friday Finish
- Flexible Working
- 25 Days holiday, plus your Birthday off, plus Bank Holidays with an opportunity to buy extra days holiday
- Family Friendly Leave
- Competitive Pension Contribution
- Share save Scheme
- Annual Bonus based on company and personal performance
- Competitive Salary and Car Allowance
- Private Medical Insurance
- Staff Discount Card for stores and online