The Security Assurance Analyst supports security risk and assurance activity across Zellis Group, which comprises Zellis, Moorepay, Benifex and Hastee. The role helps protect the Group’s services, data and customers by identifying and assessing security risks, testing the maturity and effectiveness of controls, and providing assurance that the Group’s security posture is sound and well evidenced.
Reporting to the Security Risk Manager, this is a broad, hands-on role spanning security risk management, control assessments, policy and standards, supplier assurance, threat modelling and security awareness. The analyst works across all of the Group’s brands and business units, contributing to the security risk register, control maturity assessments, and the evidence that underpins certifications and customer assurance.
The role takes a strong “AI first” approach, using approved AI tooling (such as Microsoft Copilot and Claude) to automate evidence gathering, accelerate risk and control reporting, and help move assurance from periodic, point-in-time reviews towards continuous, data-led insight.
Key responsibilities
Security Risk Management
- Contribute to the development and ongoing maintenance of the Group’s security risk register.
- Identify, analyse and evaluate strategic and operational security risks.
- Conduct policy exception reviews and track risk treatment through to closure.
Controls, Policies & Standards
- Help design, develop and document security controls, policies, standards and guidance.
- Design and conduct control maturity assessments to test control effectiveness.
- Support annual policy reviews and keep the control framework current.
Supplier & Third-Party Assurance
- Conduct security control assessments of suppliers and other third parties.
- Identify and help manage weaknesses within the supply chain.
- Track supplier remediation actions and contractual security requirements.
Certification & Customer Assurance
- Contribute to internal and external audit activity across certification programmes, including ISO 27001:2022, Cyber Essentials Plus and SOC 2.
- Support customer assurance activity, responding to security questionnaires, due-diligence and audit requests with accurate evidence.
- Create and maintain knowledge articles and assurance collateral.
Threat Modelling & Incident Support
- Contribute to threat modelling and data-flow analysis, evaluating changes for threats, vulnerabilities and countermeasures.
- Analyse and process threat intelligence to inform risk and assurance activity.
- Support security incident reviews and root-cause analysis.
Security Awareness & Training
- Support security awareness campaigns, including phishing simulations and policy awareness.
- Produce engaging awareness material and track completion across the Group.
AI, Automation & Reporting
- Take a strong “AI first” approach, using approved AI tooling (such as Microsoft Copilot and Claude) to automate evidence gathering and analysis.
- Contribute to security metrics, and develop and maintain risk and assurance dashboards.
- Help move assurance from point-in-time reviews towards continuous, data-led insight.
- Good working knowledge of information security practices and standards, including ISO 27001:2022, Cyber Essentials Plus and NIST principles.
- Practical experience of, or a solid working knowledge of, security risk management, control assessments or security assurance.
- Understanding of supplier and third-party (supply chain) security assessment.
- Experience contributing to certifications and responding to customer security requests.
- Familiarity with risk assessment methodologies and security metrics reporting.
- Experience using AI tools such as Microsoft Copilot and Claude.
- Excellent analytical, organisational and written communication skills.
Essential Functional / Technical Skills
- A recognised qualification in a relevant discipline, or equivalent training, together with around 1–2 years’ experience in a security, risk, assurance or related IT role.
- Working knowledge of current and emerging security practices and standards (e.g. ISO 27001:2022, Cyber Essentials Plus, NIST).
- General understanding of network, infrastructure and cloud security concepts.
- Confident user of AI productivity tools (e.g. Microsoft Copilot, Claude) to accelerate analysis, drafting and evidence handling.
- Experience of business tooling such as Microsoft Teams, ServiceNow, Azure DevOps and Jira would be advantageous.
Desirable Qualifications & Certifications
- A relevant certification such as CompTIA Security+, CISMP or ISO 27001 Foundation / Internal Auditor (held or working towards); progress towards ISO 27001 Lead Auditor / Lead Implementer would be an advantage.
- Experience in a regulated, data-rich or SaaS environment – ideally payroll, HR, financial services or similar.
- Familiarity with operational resilience and continuity expectations (e.g. DORA, NIS2) is an advantage.
Personal Attributes / Competencies
- Detail-oriented and disciplined in maintaining documentation and evidence.
- Proactive and accountable, following through on risk and assurance actions.
- Strong analytical and investigative skills, able to evaluate risk objectively.
- Clear communicator, able to engage effectively with both technical and business stakeholders.
- Collaborative team player, promoting consistency and knowledge sharing across business units.
- Integrity, reliability and commitment to high standards of security assurance.
- Curious and improvement-minded, keen to adopt new tools and automation to work smarter.
- Adaptable and comfortable working in a fast-paced, evolving environment.
At Zellis Group (Zellis, Moorepay, Benifex, and Hastee) we power exceptional employee experiences by creating AI-enabled products and services within HR, workforce management, payroll, and benefits. Our vision is to be the clear leader in pay, reward, analytics, and people experiences. With over 3,500 colleagues across the UK, Europe, India and the Philippines, we have a significant ambition for growth (organically and through M&A).
Our vision is to be the clear leader in pay, reward, analytics, and people experiences. We're passionate about creating an environment where people want to join, belong to, and be part of a progressive organisation. Our values, which were defined with input from of our colleagues, we live and breathe every day:
- Unstoppable together.
- Always learning.
- Make it count.
- Think scale.
Our people are critical to our ongoing success; we’re proud of our inclusive culture that gives you the platform to grow, challenge the status quo and play a crucial role in further enhancing our market position as the leading provider of HR & Payroll software and services. With Zellis you’ll have the chance to stretch and challenge yourself in an environment that’s varied, flexible and hugely supportive.
We also love to reward and recognise our brilliant colleagues. As part of your benefits package, you’ll receive:
- A competitive base salary, cash car allowance and bonus package.
- 25 days annual leave, plus your birthday off and the opportunity to buy additional holiday.
- Private medical insurance.
- Life assurance 4x salary.
- Enhanced pension scheme with company contributions up to 8.5%.
- A huge range of additional flexible benefits across financial & personal wellbeing, lifestyle & leisure.