NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Security Analyst in United Kingdom
1 day agoBe an early applicant
Apply with autofill
Apply with autofill
G-mass·1 day ago
1 day agoBe an early applicant

Information Security Analyst

London, United KingdomContractHybridMid · 2-5 yearsSecurity Analyst

Sign up free to see how well your resume matches this role.

Boost your chances at g-mass

How you compare FREE

?
Your scoreYour score: not yet known
→
47
Top 10%Top 10%: 47 out of 100

Top 10% of NextRaise users matched against Security Analyst roles in United Kingdom.

Must-have skills for this role

  • information security
  • third-party risk management
  • iso 27001
  • risk assessment

PDF or DOCX · no account needed

Apply faster with autofill FREEg-mass uses Workable - autofill it instead of retyping.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Complete and progress supplier security due diligence, risk assessments and periodic reviews, clearly documenting findings, required remediation, and escalation points.
  • Support Triage, conduct threat intelligence, and respond to day-to-day Information Security requests from the business, providing clear, risk-based advice and escalating material matters promptly.
  • Support the assessment, coordination, documentation and follow-up of Information Security incidents and enquiries in accordance with established processes.
  • Assist with evidence gathering, control validation, audit and regulatory requests, and remediation tracking against relevant obligations and frameworks, including ISO 27001, NIST CSF, NYDFS, FCA, and PRA where applicable.
  • Assessments Conduct structured risk and control assessments across third parties, business activities, and projects, ensuring identified risks and actions are accurately recorded and tracked.

What they're looking for

  • Proven experience in an Information Security, Cyber Risk, or IT Risk role within financial services, insurance, or another regulated sector
  • Practical experience of third-party / supplier security risk assessment and due diligence processes
  • Working knowledge of ISO 27001, NIST CSF, and awareness of NYDFS Cybersecurity Regulation
  • Familiarity with UK regulatory expectations relevant to information security, including FCA and PRA requirements
  • Experience supporting security incident response, including documentation and post-incident follow-up
  • Confident engaging directly with business stakeholders, translating technical risk into clear, actionable advice
  • Strong documentation and record-keeping discipline, comfortable maintaining risk registers and audit evidence
  • Able to work independently as a deployed consultant within a client's existing Information Security team and governance structure

Nice to have

  • Relevant certification desirable (e.g. CISSP, CISM, ISO 27001 Lead Auditor/Implementer, or equivalent)

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

G MASS is seeking to deploy one of our own Information Security Analysts into a specialist Lloyd's / London Market insurance engagement, on a fixed-term contract (FTC) running to the end of November 2026. The consultant will be embedded within the client's Information Security function, providing hands-on support across third-party risk management, day-to-day security operations, incident support, and compliance and assurance activity. This is a client-facing, delivery-focused role suited to a consultant comfortable operating independently within a regulated financial services environment.

Key Responsibilities:

  • Complete and progress supplier security due diligence, risk assessments and periodic reviews, clearly documenting findings, required remediation, and escalation points.
  • Support Triage, conduct threat intelligence, and respond to day-to-day Information Security requests from the business, providing clear, risk-based advice and escalating material matters promptly.
  • Support the assessment, coordination, documentation and follow-up of Information Security incidents and enquiries in accordance with established processes.
  • Assist with evidence gathering, control validation, audit and regulatory requests, and remediation tracking against relevant obligations and frameworks, including ISO 27001, NIST CSF, NYDFS, FCA, and PRA where applicable.
  • Assessments Conduct structured risk and control assessments across third parties, business activities, and projects, ensuring identified risks and actions are accurately recorded and tracked.

Requirements

  • Proven experience in an Information Security, Cyber Risk, or IT Risk role within financial services, insurance, or another regulated sector
  • Practical experience of third-party / supplier security risk assessment and due diligence processes
  • Working knowledge of ISO 27001, NIST CSF, and awareness of NYDFS Cybersecurity Regulation
  • Familiarity with UK regulatory expectations relevant to information security, including FCA and PRA requirements
  • Experience supporting security incident response, including documentation and post-incident follow-up
  • Confident engaging directly with business stakeholders, translating technical risk into clear, actionable advice
  • Strong documentation and record-keeping discipline, comfortable maintaining risk registers and audit evidence
  • Relevant certification desirable (e.g. CISSP, CISM, ISO 27001 Lead Auditor/Implementer, or equivalent)
  • Able to work independently as a deployed consultant within a client's existing Information Security team and governance structure

Benefits

Length: Initial 2 month contract

About the Engagement

This role is a G MASS-managed consultant deployment: the successful candidate will remain a G MASS employee, working on-site or hybrid with our client under a fixed-term or ongoing statement of work. G MASS provides specialist Lloyd's and London Market resourcing and technology advisory, placing experienced consultants into insurance sector engagements across governance, risk, and technology functions.

Company

G-mass
London, United Kingdom

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from G Mass's careers site·first seen 22 Sept 2026·last verified 22 Sept 2026·How we source jobs

Similar jobs

  • Cyber Security Analyst at MotorwayLondon, United Kingdom–match not yet calculated
  • Digital Forensics & Incident Response Analyst at MaerskMaidenhead, United Kingdom–match not yet calculated
  • Security Analyst - Up to £450 per day at Cloud Bridge Tech RecruitmentLondon, United Kingdom–match not yet calculated
  • SOC Reporter at EurofinsWarrington, United Kingdom–match not yet calculated
  • Cyber Security Analyst at gandwukeuropeSouthampton, United Kingdom–match not yet calculated

Browse more jobs

  • Security Analyst jobs in United Kingdom
  • Security Engineer jobs in United Kingdom
  • Penetration Tester jobs in United Kingdom
  • Cloud Security Engineer jobs in United Kingdom
  • Security Analyst jobs in United States
  • Security Analyst jobs in India