Junior Information Security Analyst
Role details
Job location
Tech stack
Job description
You will work as part of a small information security team, providing operational support across a wide range of security activities. The role focuses on practical delivery, incident support, risk reduction, and maintaining strong assurance records to protect people, data, and digital services.
You will collaborate closely with Technology teams, Information Governance colleagues, and external suppliers to help embed good security practices across the organisation., * Carrying out routine information security checks and operational tasks
- Logging, triaging, and progressing security issues within agreed timescales
- Supporting incident response activities, including evidence gathering and follow-up actions
- Assisting with vulnerability identification and remediation tracking
- Supporting secure configuration standards and baseline maintenance
- Assisting with identity and access management processes, including joiners, movers, and leavers
- Supporting data protection controls to reduce the risk of data loss or unauthorised disclosure
- Collecting and maintaining security documentation for supplier due diligence
- Assisting with security awareness initiatives, including phishing simulations and staff guidance
- Maintaining accurate security records to support audits and assurance activities
- Updating runbooks and operating procedures, suggesting improvements or automation where appropriate
- Producing management information and KPIs, including incident and compliance metrics
- Supporting security input into procurement activity and new supplier onboarding
- Providing proportionate security input into low- to medium-risk change activity
- Keeping skills and knowledge up to date through training and development
Requirements
- Experience in an information security or IT operations environment (e.g. service desk, infrastructure, or similar), with exposure to security responsibilities
- Working towards or holding a relevant IT or security qualification (e.g. Security+, SSCP, Network+) or equivalent practical experience
- Good understanding of core security principles such as least privilege, secure configuration, and basic incident handling
- Familiarity with modern cloud and SaaS environments
- Strong written and verbal communication skills, with the ability to explain technical concepts in plain English
- High attention to detail with a structured, organised approach to record-keeping
- Experience following procedures or runbooks and maintaining assurance evidence
- Ability to prioritise tasks and manage competing demands
- Awareness of handling sensitive information and safeguarding responsibilities
Desirable Experience
- Experience preparing metrics or management information using spreadsheets or dashboards
- Experience supporting supplier security questionnaires or due diligence
- Exposure to regulated or non-profit environments
- Familiarity with common security or control frameworks
Additional Information
- This is a remote role; candidates must meet remote working eligibility criteria
- A Basic DBS check is required and must be held by the agency at the point of submission, * information security or IT operations environment: 2 years (required)
Benefits & conditions
Job Types: Full-time, Temporary
Pay: £18.90 per hour
Expected hours: 35 per week