> Markdown version of [/jobs/ext/3232111-information-security-analyst](https://www.wearedevelopers.com/jobs/ext/3232111-information-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Analyst - **Company:** Miller Insurance Services LLP - **Location:** London, UK - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Cyber Security, Multi-Factor Authentication, Identity and Access Management, Information Technology Operations, Phishing, Software Vulnerability Management, Malware, Vulnerability Analysis - **Published:** September 15, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=1960903a322a1708 ## About the Role * A relevant degree, professional qualification or equivalent practical experience in information security, cyber security, IT, technology risk, compliance, audit or a related discipline., * Understanding of core information-security principles, including confidentiality, integrity, availability, risk management and data protection. * Familiarity with common cyber-security threats, including phishing, social engineering, malware, ransomware, credential compromise and cloud-security risks. * Awareness of security controls and technologies such as multi-factor authentication, endpoint protection, email security, identity and access management, vulnerability scanning and security monitoring. * Familiarity with recognised information-security frameworks and requirements, such as Cyber Essentials, GDPR, ISO/IEC 27001 and the NIST Cybersecurity Framework. * Awareness of the relationship between information security, technology risk, operational resilience, business continuity and data protection. Experience * Experience gained in an information-security, cyber-security, IT operations, IT risk, compliance, audit, assurance or related technology role. * Experience supporting risk assessments, control reviews, audit activity, compliance evidence gathering, remediation tracking or operational-security processes. * Experience maintaining accurate documentation, such as risk registers, action trackers, procedures, reports, ticket records or incident logs. * Experience working collaboratively with both technical and non-technical stakeholders. * Strong written and verbal communication skills, with the ability to present information clearly and professionally. ## Description The Information Security Analyst will help protect the confidentiality, integrity and availability of Miller's systems, data and technology services. This is a hands-on, varied role for an information-security professional who wants broad exposure across cyber security, technology risk, governance, supplier assurance, security awareness and incident support within a regulated business. The role will take ownership of day-to-day security activities, maintain accurate security records and reporting, coordinate follow-up actions, and work closely with colleagues across Technology, Risk, Compliance, Legal, HR and Operations. They will be trusted to manage assigned work independently, identify potential issues early and escalate material risks or incidents appropriately. Role Responsibilities Security governance, documentation and assurance * Maintain information-security policies, procedures, standards, guidance and supporting documentation, ensuring these remain current and accessible. * Support the collection, organisation and maintenance of evidence for internal reviews, external audits, client due-diligence requests and regulatory assurance activity. * Maintain security risk registers, action trackers, control records, exception logs and incident documentation. * Produce clear, accurate and timely reports and dashboards covering security risks, outstanding actions, vulnerabilities, supplier assurance and control status. * Support the ongoing improvement of security processes, templates, documentation and reporting. Security risk * Assist with information-security risk assessments for systems, business processes, technology projects, suppliers and change initiatives. Supplier and third-party assurance * Support security due diligence for suppliers and third parties, including reviewing completed questionnaires, policies, certifications, audit reports and supporting evidence. * Track outstanding supplier actions and follow up with internal stakeholders and suppliers where required. * Help maintain an accurate record of supplier-security assessments, risks, exceptions and remediation plans. Operational security and vulnerability management * Monitor security alerts, vulnerabilities, control exceptions and security-related tasks assigned through relevant tools or processes. * Triage straightforward issues, gather relevant information and escalate potential incidents or higher-risk findings promptly. * Assist with access-control, endpoint-security, email-security, identity-management or other security-control reviews as required. Incident support * Support the investigation, documentation and coordination of information-security incidents. * Contribute to lessons-learned activity and help ensure improvement actions are followed through. Security awareness and stakeholder engagement * Support security-awareness communications, training activity and phishing-simulation exercises. * Help create clear and engaging security guidance for employees and other stakeholders. General responsibilities * Handle confidential and sensitive information with discretion, integrity and care. * Comply with relevant internal policies, regulatory obligations and professional standards. * Undertake reasonable ad hoc tasks and projects that support the objectives of the information-security function. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [MFA? Game over! Watch your protection collapse – live](https://www.wearedevelopers.com/videos/100322-mfa-game-over-watch-your-protection-collapse-live) ## Related Articles - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Data Engineer Salary UK](https://www.wearedevelopers.com/magazine/253-data-engineer-salary-uk)