Job Specification
Cyber Security & Compliance Analyst
Organisation: Shivom Consultancy Ltd.
Department: Technology / Security & Compliance
Job Title: Cyber Security & Compliance Analyst
Employment Type: Permanent
Salary: £36,000 per annum
Contracted Hours: 37.5 hours per week
Location: 950 Great West Road, Suite B, Part First Floor, Profile West, Brentford, England, TW8 9ES
Working Arrangement: Office Based
Reporting To: Head of Business Development
SOC Code: 2135 – Cyber Security Professionals
Role Purpose
The Cyber Security & Compliance Analyst is responsible for supporting, operating and continuously improving Shivom's organisational cyber security and information security capabilities.
The role provides hands on responsibility across cyber security operations, vulnerability management, security patching, security incident management, information security governance, security policies, security awareness, audit and compliance activities.
The role is also responsible for supporting and maintaining Shivom's ISO 27001 Information Security Management System and Cyber Essentials Plus certification, ensuring that appropriate security controls, processes, documentation and evidence are maintained across the organisation.
The Cyber Security & Compliance Analyst will work closely with Technology, Operations, HR, senior management and other relevant stakeholders to identify and manage security risks and ensure that appropriate security practices are embedded throughout the organisation.
Key Responsibilities
Cyber Security Operations
The Cyber Security & Compliance Analyst will:
- Carry out and coordinate day to day cyber security activities across the organisation.
- Monitor the security posture of corporate systems, devices and services.
- Identify security weaknesses, risks and control failures and coordinate appropriate remediation.
- Maintain security operational records, registers, evidence and reporting.
- Monitor security actions through to completion and escalate significant or overdue issues.
- Work with technical and operational teams to ensure agreed security controls are implemented and operating effectively.
- Continuously review security operations and recommend improvements to controls, processes and tooling.
Vulnerability Management
- Manage the identification, assessment and remediation of vulnerabilities affecting corporate devices and systems.
- Review vulnerability findings and assess their potential impact on the organisation.
- Prioritise vulnerabilities according to risk and severity.
- Coordinate remediation activities with relevant technical teams and users.
- Track identified vulnerabilities through to resolution.
- Maintain appropriate vulnerability records and evidence.
- Escalate significant vulnerabilities or overdue remediation activities to management.
- Monitor recurring vulnerability issues and recommend preventative improvements.
Security Patch Management
- Monitor the security patching status of corporate devices and relevant systems.
- Identify devices that are missing security updates or are outside agreed compliance requirements.
- Coordinate the deployment and remediation of outstanding security patches.
- Track patch compliance and escalate significant exceptions.
- Maintain evidence demonstrating the operation and effectiveness of the patch management process.
- Identify opportunities to improve and automate patch management and compliance monitoring.
Security Incident Management
- Maintain and operate the organisation's security incident management processes.
- Identify, assess and triage suspected security incidents.
- Coordinate investigation of security incidents and security events.
- Support containment, remediation and recovery activities.
- Escalate material incidents to appropriate management stakeholders.
- Maintain accurate security incident records and supporting evidence.
- Coordinate post incident reviews and lessons learned activities.
- Identify root causes and corrective actions following security incidents.
- Track incident related remediation actions through to completion.
- Recommend changes to controls, policies or processes following security incidents.
Security Governance and Compliance
- Support and maintain Shivom's cyber security and information security governance framework.
- Monitor compliance with organisational security requirements.
- Maintain security related records, registers, documentation and evidence.
- Identify security and compliance gaps and coordinate corrective actions.
- Support management with security reporting and compliance information.
- Ensure security activities are appropriately documented and traceable.
- Support continuous improvement of Shivom's security governance arrangements.
ISO 27001 and Information Security Management System
- Support the operation, maintenance and continuous improvement of Shivom's ISO 27001 Information Security Management System.
- Maintain relevant ISMS policies, procedures, registers, records and supporting evidence.
- Support security risk assessments and risk treatment activities.
- Maintain and monitor security control evidence.
- Support the maintenance of the Statement of Applicability where applicable.
- Coordinate actions arising from ISO 27001 control reviews.
- Support the internal security audit programme.
- Prepare for external certification and surveillance audits.
- Coordinate the provision of evidence to auditors.
- Record, manage and track audit findings, observations and corrective actions.
- Support management review and continuous improvement activities relating to the ISMS.
Cyber Essentials Plus
- Coordinate activities required to maintain Shivom's Cyber Essentials and Cyber Essentials Plus certification.
- Monitor compliance with relevant technical security requirements.
- Prepare the organisation for Cyber Essentials Plus assessments.
- Coordinate evidence gathering and technical readiness activities.
- Work with relevant technical teams to identify and remediate gaps.
- Liaise with authorised assessors where required.
- Track findings and remediation activities through to completion.
- Maintain appropriate records relating to certification and ongoing compliance.
Security Audits and Assurance
- Coordinate and support internal and external cyber security and information security audits.
- Prepare documentation and evidence required for security audits and assessments.
- Coordinate responses to auditor queries and evidence requests.
- Record audit findings, observations and improvement opportunities.
- Coordinate corrective and remediation activities.
- Track audit actions through to satisfactory completion.
- Support customer and third party security assurance activities where required.
- Assist with security questionnaires and information security assurance requests.
- Maintain an appropriate audit trail demonstrating the operation of security controls.
Security Policies, Standards and Processes
- Develop, document, review and maintain information security policies and procedures.
- Translate security and compliance requirements into practical operational processes.
- Maintain detailed security processes covering areas such as vulnerability management, patching, incident management, security audits and compliance.
- Ensure processes clearly define activities, responsibilities, escalation routes and evidence requirements.
- Review policies and procedures periodically to ensure they remain appropriate and effective.
- Communicate changes to security policies and processes to relevant employees.
- Monitor compliance with security policies and identify areas requiring improvement.
- Support the development of new security controls and processes as organisational requirements evolve.
Security Operations Automation
- Identify opportunities to automate repetitive security and compliance activities.
- Design and implement automation to improve the efficiency and consistency of security operations.
- Develop automated workflows for security monitoring, reporting, alerts and notifications where appropriate.
- Support automation of vulnerability management and patch compliance activities.
- Automate collection and preparation of security and compliance evidence where appropriate.
- Develop or configure automated security checks and compliance monitoring.
- Use appropriate scripting, workflow and security tooling to improve security processes.
- Integrate security tools and organisational systems where appropriate.
- Document automated security processes and their operation.
- Monitor automated processes and continuously improve their reliability and effectiveness.
Security Risk Management
- Identify and assess cyber security and information security risks.
- Record security risks within appropriate organisational risk registers.
- Assess the potential business impact and likelihood of identified risks.
- Work with relevant stakeholders to identify appropriate risk treatments and mitigating controls.
- Monitor agreed risk treatment actions.
- Escalate significant security risks to management.
- Support periodic reviews of security risks and associated controls.
- Maintain appropriate evidence of security risk decisions and remediation activities.
Security Awareness and Employee Briefings
- Develop and deliver cyber security awareness briefings to employees.
- Produce security guidance, communications and awareness material.
- Communicate relevant threats, vulnerabilities and security requirements to employees.
- Support induction and ongoing security awareness activities.
- Promote secure working practices throughout the organisation.
- Provide practical guidance to employees on security policies and procedures.
- Coordinate security awareness campaigns where appropriate.
Continuous Security Improvement
- Monitor developments in cyber security threats, vulnerabilities and industry practices relevant to Shivom.
- Identify opportunities to strengthen organisational security.
- Recommend improvements to security controls, processes and tooling.
- Support implementation of agreed security improvements.
- Review security incidents, audit findings, vulnerabilities and compliance results to identify recurring issues.
- Work collaboratively with other business functions to embed security into organisational processes and technology.
Qualifications and Experience
Essential
The successful candidate should demonstrate:
- A degree, postgraduate qualification, relevant professional qualification or equivalent practical experience in Cyber Security, Information Security, Computer Science or a related discipline.
- Practical knowledge of cyber security principles and security controls.
- Experience or knowledge of vulnerability management and remediation.
- Understanding of security patch management.
- Knowledge of security incident management and response.
- Understanding of information security governance and compliance.
- Experience developing or maintaining security policies, processes and procedures.
- Understanding of security risk management.
- Ability to analyse security issues and recommend appropriate corrective actions.
- Strong documentation and evidence management skills.
- Ability to communicate cyber security requirements to both technical and non technical stakeholders.
Desirable
Experience or knowledge in one or more of the following would be advantageous:
- ISO 27001 and Information Security Management Systems.
- Cyber Essentials and Cyber Essentials Plus.
- Security audits and assurance.
- Endpoint and device security.
- Vulnerability scanning and remediation tooling.
- Security monitoring and alerting.
- Security operations automation.
- Scripting or workflow automation.
- Identity and access security.
- Cloud security.
- Microsoft security technologies or equivalent enterprise security tooling.
- Security risk and compliance management.
Skills and Competencies
The role requires:
- Strong analytical and problem solving skills.
- Good understanding of cyber security threats, vulnerabilities and controls.
- Ability to investigate security issues methodically.
- Strong attention to detail.
- Ability to interpret technical and compliance requirements.
- Strong written documentation skills.
- Ability to communicate effectively with technical and non technical stakeholders.
- Ability to manage multiple security actions and priorities.
- Good organisational and record keeping skills.
- Ability to work independently within defined responsibilities.
- Ability to identify opportunities for process improvement and automation.
- Sound judgement when handling confidential or security sensitive information.
- Commitment to continuous professional development in cyber security.
Accountability and Scope
The Cyber Security & Compliance Analyst is a hands on professional role and does not carry responsibility for managing a cyber security team.
The role is responsible for carrying out and coordinating defined organisational security and compliance activities, escalating significant security risks, incidents and decisions to the appropriate management authority.
The role works collaboratively with other teams and stakeholders to ensure that security controls and processes are implemented effectively throughout Shivom.
Performance Expectations
Performance in the role will be assessed against areas including:
- Effective management and remediation of identified vulnerabilities.
- Compliance with agreed security patching requirements.
- Effective management and documentation of security incidents.
- Maintenance of ISO 27001 requirements and supporting evidence.
- Maintenance of Cyber Essentials Plus requirements.
- Timely completion of audit and security remediation actions.
- Quality and currency of security policies and processes.
- Effectiveness of employee security awareness activities.
- Accuracy and completeness of security compliance evidence.
- Improvements achieved through security process and operational automation.
- Identification and timely escalation of material security risks.
- Continuous improvement of Shivom's overall cyber security posture.
Review of Responsibilities
The responsibilities of the role will be reviewed periodically to reflect changes in Shivom's technology environment, security risks, regulatory and contractual obligations, recognised security standards and organisational requirements.
Pay: £36,000.00 per year
Work Location: In person