> Markdown version of [/jobs/ext/1123885-it-security-and-compliance-analyst](https://www.wearedevelopers.com/jobs/ext/1123885-it-security-and-compliance-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security and Compliance Analyst - **Company:** Holman, Inc. - **Location:** Chippenham, UK - **Experience:** Expert - **Salary:** £55,000.0 - £60,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cyber Security, Data Mapping, Data Security, Information Security Management, Microsoft Office, Vulnerability Analysis - **Published:** July 2, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=ceb04ab5cb073bbb ## About the Role * Ideally at least one industry certification (e.g. CISA, CISM, CRISC, CISSP, ISAAP) * 5 years of combined Information Security and Technical Administration Experience. * Proven experience in an information security role including experience of developing Information Security policies and plans. * Working knowledge of General Data Protection Regulation (GDPR). * Experience with information security internal & external audits and contract compliance. * Good understanding of system technology security testing (vulnerability scanning and penetration testing). * Excellent understanding of information security concepts, protocols, industry best practices and strategies. * Knowledge of information security & control frameworks e.g., NIST, ISO 27001/27002 a plus. * Familiarity with regulatory and compliance mandates e.g., PCI, CCPA, GDPR a plus * Proficient with Microsoft Office suite of products * Sound analytical judgement, self-motivated, attention to detail, ability to manage deliverables against firm timelines, and commitment to producing results. * Strong verbal and written communication skills. The ideal candidate will have a flexible, proactive approach to work and be committed to delivering an exceptional customer experience and be comfortable dealing with conflicting priorities. ## Description * Works with fellow team members and other departments to address customer assurance requests, preparing responses to customer inquiries. * Work with senior managers across the business to drive the information security agenda and ensure that it meets complex compliance requirements. * Works closely with Senior Analysts supporting compliance, regulatory, vendor and cyber-maturity assessments and reporting. * Provides direct support for control activities such as access reviews, data mapping and vendor assessment. * Works toward, establishes, and maintains a firm knowledge of data security practices and relevant regulatory requirements. * Assist with the development of control frameworks to meet business and regulatory requirements * Participates in project reviews, working with business representatives, technical staff, suppliers, and project team members to evaluate information security requirements, and to help mitigate potential exposures. * Provides support for contract review and negotiation of information security and privacy requirements. * Monitors and promotes compliance with information security policies and standards. Recommends changes to policies, standards and procedures. * Consult with IT colleagues to ensure that security is factored into the evaluation, selection, installation and configuration of hardware, applications and software * Supports UK DPO in providing technical expertise in relation to UK GDPR, Data Protection Act 2018 and PECR 2003 ## Related Videos - [Web-based Information Visualization](https://www.wearedevelopers.com/videos/84-web-based-information-visualization) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk)