Information Security Analyst

Connells Group
Milton Keynes, UK
4 days ago
Apply on www.totaljobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Cyber Security Phishing

Job description

We are seeking an Information security Analyst to join our team in Milton Keynes. The Security Analyst supports the delivery and continuous improvement of Connells Group’s security governance, risk and compliance activities. The role provides operational support across security awareness, control monitoring, GRC reporting, audit and compliance, and supplier risk management. The postholder will collect and analyse information, maintain accurate records, coordinate stakeholders and help ensure security and resilience activities are completed consistently, on time and with appropriate evidence., Security Awareness

  • Support the delivery of the Security Awareness Programme, including campaigns, communications, learning content and reporting.
  • Assist with phishing simulations, awareness initiatives and behavioural risk monitoring.
  • Produce awareness metrics and identify opportunities for continuous improvement.
  • Promote positive security behaviours and support the development of a strong security culture.

Governance, Risk and Compliance

  • Collect, validate and maintain information used in security, risk and compliance reporting.
  • Administer risk registers, issue logs, action trackers and control records.
  • Monitor progress of remediation actions and follow up with stakeholders for updates and evidence.
  • Support the production of dashboards, reports and governance documentation.

Audit and Compliance

  • Support internal audits, external assessments and assurance activities.
  • Coordinate evidence gathering and maintain audit-ready documentation.
  • Track findings and agreed actions through to completion.
  • Escalate overdue actions, compliance concerns or control weaknesses where appropriate.

Supplier Risk Management

  • Support supplier due diligence and ongoing assurance reviews.
  • Review security questionnaires, certifications and supporting evidence.
  • Maintain supplier assurance records and action plans.
  • Assist with the identification and escalation of third-party security risks.

General Responsibilities

  • Build productive relationships with stakeholders across the organisation.
  • Maintain accurate records and clear audit trails.
  • Handle sensitive information appropriately and confidentially.
  • Identify opportunities to improve processes, reporting and data quality.
  • Provide flexible support across the Security GRC function in response to changing priorities.

Requirements

  • Demonstrable interest in information security, cyber risk, compliance or technology-related disciplines.
  • Experience gathering information, maintaining records and following structured processes.
  • Ability to organise work effectively and manage tasks through to completion.
  • Strong attention to detail and commitment to accuracy.

Desirable

  • Experience in information security, governance, risk management, compliance, audit, business continuity or supplier assurance.
  • Experience supporting awareness programmes, audits, compliance reviews or reporting activities.
  • Experience working within a regulated, large or complex organisation

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.totaljobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · World Congress 2026 Europe

Videos

See all

Related articles

See all