Cyber Security Governance Analyst

FT Select
UK
6 days ago
Apply on ftselect.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Active Directory Artificial Intelligence Cyber Security Identity and Access Management Information Security Management Web Application Security

Job description

Fantastic opportunity for someone who enjoys working across information security and technology disciplines with a variety of stakeholders, communicates well and is a strong team player. Candidates should take a proactive and analytical approach to reviewing cybersecurity policy exceptions, identifying control weaknesses and supporting remediation through to closure. The role will assess exceptions relating to access onboarding, web access, USB and removable media, firewall access and service accounts, ensuring decisions are supported by clear business justification, appropriate approvals, proportionate compensating controls and defined expiry dates. Candidates should also demonstrate a continuous improvement mindset and contribute to automation, data quality and more efficient governance processes. Forming part of the GRC and Technology Risk team within Global Information Security, the successful candidate will support information security governance activities in London and across parts of the Group., * Consult with key Global Technology and business stakeholders to assess, address and manage cybersecurity policy exceptions to successful outcomes.

  • Review requests relating to user access onboarding, web access, USB and removable media, firewall access, privileged access and other deviations from security policy.
  • Assess whether exception requests include a valid business justification, appropriate ownership and approval, a defined duration and proportionate compensating controls.
  • Review user, firewall, service and technical accounts to identify dormant, inactive, excessive or inappropriate access.
  • Coordinate the remediation or removal of inactive service accounts and other access control weaknesses, tracking actions through to closure.
  • Identify and risk-rate control gaps, document findings and recommend proportionate treatment or escalation.

  • Maintain accurate and auditable records of exceptions, approvals, risk decisions, evidence, expiry dates and remediation actions.
  • Oversee management information on exception volumes, ageing, repeat requests, inactive accounts and progress against remediation actions.
  • Support Risk Control Assessments by interviewing stakeholders, reviewing control evidence and assessing control effectiveness.
  • Support internal control audits, regulatory reviews and other assurance activity by coordinating evidence and responding to requests.
  • Interpret cybersecurity policies, standards and regulatory requirements and perform gap analysis against current processes and controls.
  • Identify opportunities to improve data quality, streamline workflows and automate recurring governance and assurance activities.

Requirements

  • Stakeholder engagement is key, with the ability to form collaborative working relationships across Information Security, Global Technology and the wider business.
  • Good understanding of information security risk, cybersecurity policies and common enterprise security controls.
  • Knowledge of Identity and Access Management, including Joiner-Mover-Leaver processes, role-based access, privileged access and service account governance.
  • An understanding of web security controls, USB and removable media controls, firewall access, Active Directory or Entra ID and access recertification.
  • Proven ability to analyse control gaps and manage remediation actions through to resolution with tenacity and attention to detail.
  • Ability to review evidence, make proportionate risk-based judgements and communicate findings clearly to technical and non-technical stakeholders.
  • Familiarity with the NIST Cybersecurity Framework or ISO 27001 and an appreciation of the technology regulatory landscape.
  • Willingness to learn and develop Governance, Risk and Compliance skillsets, alongside an appreciation of technologies such as cloud and AI.
  • A continuous improvement mindset that challenges the status quo and seeks opportunities for automation and self-improvement.
  • Good verbal and written communication skills, with strong analytical and organisational capability.
  • Experience in an information security discipline such as Security Operations, GRC, Technology Risk or Access Management.
  • An information security qualification is favourable but not mandatory.

About the company

FT Select is a niche technology search and selection company, specialising in recruiting elite Sales Executives and high-end Technology specialists for high-growth tech businesses.______________ About the Company A well-known leading global financial services organisation.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on ftselect.com
Prepare application

Good distractions

Loading talks and stories from around this role…