> Markdown version of [/jobs/ext/2700413-assistant-manager-analyst-business-information-security](https://www.wearedevelopers.com/jobs/ext/2700413-assistant-manager-analyst-business-information-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Assistant Manager, Analyst - Business Information Security - **Company:** Deloitte - **Location:** Milton Keynes, UK - **Contract:** Permanent contract - **Skills:** Agile Methodology, Software System Penetration Testing, Cloud Computing Security, Code Review, Cyber Security, Identity and Access Management, Microsoft Software, Scrum Methodology, Security Information and Event Management, Software Engineering, Trusted Systems, Software Vulnerability Management, SSL Certificate Management, Software Security - **Published:** September 4, 2026 - **Apply:** https://www.careerjet.co.uk/job/gb8a0b7f3eb515f43106862d8a5e8cc23a/eaa ## About the Role * Proven experience, including cybersecurity and/or risk management experience in organizations of a similar scale or client-service experience in the field. * Demonstrated ability to work with multiple teams, business units within a large organization to effect change. * Exceptional verbal and written communication skills. Must be able to interact effectively with professionals at all levels and communicate recommendations with diplomacy and tact. * Experience with cloud security principles and functions. * Solid capabilities across multiple security domains such as identity and access management (IAM), public-key encryption, security information and event management (SIEM), incident response, threat & vulnerability management Preferred: * Familiarity with SOC 2 principles; experience in application security to meet SOC 2 requirements * Experience in a fast-moving workplace, covering diverse areas such as software development, security architecture, application security risks and vulnerabilities * Proven organizational skills, and understanding / experience of cybersecurity policies and procedures, ideally within a governance risk and compliance function * Experience with Agile practices, SCRUM, Microsoft SDL, and STRIDE ## Description As an Analyst within the Business Information Security area, you'll work closely with both technical and non-technical stakeholders within an assigned line of business or technology enablement area providing the best possible support across a range of cybersecurity, risk, and risk mitigation disciplines. Along with having knowledge of industry-accepted best practices, the Analyst is expected to ensure that all applications and systems aligned to their line of business adhere to internal cybersecurity policies, standards, escalating any non-compliance up to the associated Business Information Security Officer (BISO). Successful candidates should showcase the capability to effectively influence and cultivate robust relationships with diverse stakeholders. This role is responsible for overseeing the security posture and continual compliance of their assigned business/technology area's applications by ensuring security is embedded from the start and that all associated development security procedures are followed, with appropriate security evaluations and testing process completed. Responsibilities will span from briefing teams on new cybersecurity priorities, to discussing risks and vulnerabilities (e.g., penetration testing, code scanning, etc., infrastructure patch/configuration, end of life software, TLS configurations, etc.), and controls compliance (e.g., service account compliance, firewall rule base compliance, key and certificate management, security agent health, etc.). Responsibilities include: * Understand their assigned global line of business, gain familiarity with priorities and become an advocate for them within cybersecurity. * Work with multiple parties within their assigned service lines and the organization to help effect change and improve cybersecurity health/hygiene. * Oversee the implementation of application security controls to ensure teams remain compliant with Deloitte cybersecurity standards. * Process any risk-based matters / exceptions in accordance with Deloitte Technology's strict policies and procedures. * Support the Secure Systems Development Lifecycle (SSDLC), including functional and non-functional cybersecurity requirements. * Strive for process improvement and automation; help development and operations team build automation for repeatable Cyber related vulnerability management activities. * Maintain awareness of evolving application security threats and inform development, business, and risk stakeholders. * Provide application-specific security subject matter expertise to assigned customers. * Evaluate the likelihood and impact of application vulnerabilities; develop and drive mitigation approaches. * Lead, coach, and mentor project teams to incorporate security into enterprise and client-facing applications. ## Related Videos - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Challenges of Breaking A Monolith](https://www.wearedevelopers.com/videos/362-security-challenges-of-breaking-a-monolith) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Real-world Threat Modeling](https://www.wearedevelopers.com/videos/936-real-world-threat-modeling) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)