Expire in: a month
Our local authority client based in Hertfordshire are urgently seeking an experienced Senior Information Security Analyst.
*Remote position*
Job Role
We are seeking an experienced Senior Information Security Analyst to provide immediate support to the Information Security team. This role is a hybrid of technical security analysis and governance, risk, and compliance (GRC)activities.
The successful candidate will play a key role in assessing risks, reviewing supplier and project security documentation, responding to security questionnaires and tenders, supporting incident investigations, and helping to maintain AFC’s security posture and compliance with relevant standards (Cyber Essentials Plus, ISO 27001, DSPT, GDPR, NCSC).
This is a hands-on delivery role for someone who can work independently, make sound judgements, and communicate clearly with both technical and non-technical stakeholders.
Key Responsibilities
Security Governance & Risk
* Conduct security risk assessments for systems, projects, and suppliers, and document findings in a consistent and evidence-based way.
* Review, respond to, and attest security questionnaires and tender submissions from vendors and partners.
* Support and track remediation actions arising from risk assessments, audits, or incidents.
* Assist with the maintenance and review of the Information Security Risk Register and associated controls.
* Support compliance with ISO 27001, Cyber Essentials Plus, and Data Security & Protection Toolkit (DSPT)requirements.
* Provide input to security policies, standards, and process improvements.
Required Skills and Experience
* 5+ years’ experience in Information Security roles combining technical and GRC activities.
* Strong understanding of cloud and network security (preferably Microsoft stack: M365, Azure, Defender, DLP, Conditional Access).
* Demonstrated experience reviewing security questionnaires, tenders, and supplier assurance evidence.
* Good knowledge of risk assessment methodologies (ISO 27005, NIST RMF, or equivalent).
* Working familiarity with ISO 27001, Cyber Essentials Plus, DSPT, and GDPR requirements.
* Experience interpreting vulnerability scan results and prioritising remediation.
* Strong written communication skills for drafting risk reports, supplier reviews, and executive summaries.
* Excellent stakeholder engagement skills — able to explain technical concepts in plain language.
Desirable
* Relevant certifications such as CISSP, CISM, CRISC, CEH, CompTIA Security+, or equivalent experience.
* Experience working in healthcare, charity, or public sector environments.
* Familiarity with NCSC CAF and NHS DSPT frameworks.
* Experience working with SOCs and incident response partners.
Please apply with your updated CV ensuring that any gaps in employment are explained.
At this point, may we take this opportunity to thank you for the interest you have shown in this role. Unfortunately, due to the high volume of applications that we receive, it is not always possible to respond to everyone. Therefore, unless you hear from us within the next 7 days, your application for this vacancy will have been unsuccessfulDo not include the following in your job application, CV, or cover letter:
You should not be asked for payment or irrelevant information. If you have concerns about a job advert or employer, seek guidance on how to proceed.
Looking for your next career move? Join a top company hiring Senior Information Security Analyst job near me in Nationwide! This is your chance to work on exciting projects, grow professionally, and enjoy a rewarding career with competitive pay and excellent benefits. Whether you're an experienced professional or looking to take the next step, this role offers the perfect opportunity to enhance your skills and make an impact. Don’t miss out—apply today via Vita CV and take your career to the next level!
© Vita CV: Registered in England and Wales (16187919).
Vita CV uses cookies to enhance your experience, analyze site traffic, and personalize content. By continuing to browse, you agree to our use of cookies.