Harrington Starr are seeking a Senior Security Analyst Officer to perform an all-rounder role as the company’s first cyber hire.
The client are a growing fintech with a global presence with offices in the UK and North America.
The role will be a mixture of GRC, technical and strategic work.
The role is based in Bristol with one day a week required in the office.
Some of the key activities will include:
- Managing the ISO 27001 program including evolving the policy framework, gathering control evidence, managing internal
- stakeholders, and maintaining the ISMS for successful annual audits.
- Helping to promote a DevSecOps culture by encouraging 'Secure by Design' principles
- Responding and triaging to any security alerts
- Working on all risk management processes and security controls
- Evolving the company's security strategy to align with business change and product requirements.
- Working on all RFIs and third party/ customer questionnaires
Key skills needed are:
- Experience in GRC ideally including managing/ maintaining an ISO27001 programme
- Experience in security cloud controls
- Experience in implementing security policy and standards
- Experience of some of the following: Microsoft Entra ID, Microsoft Defender, Microsoft InTune, JAMF Pro, and AWS Security Hub
- A passion for cyber security and the desire to help drive and improve an organisation's security posture
Please send your CV for immediate review.
The role will be a mixture of GRC, technical and strategic work.
The role is based in Bristol with one day a week required in the office.
Some of the key activities will include:
- Managing the ISO 27001 program including evolving the policy framework, gathering control evidence, managing internal
- stakeholders, and maintaining the ISMS for successful annual audits.
- Helping to promote a DevSecOps culture by encouraging 'Secure by Design' principles
- Responding and triaging to any security alerts
- Working on all risk management processes and security controls
- Evolving the company's security strategy to align with business change and product requirements.
- Working on all RFIs and third party/ customer questionnaires
Key skills needed are:
- Experience in GRC ideally including managing/ maintaining an ISO27001 programme
- Experience in security cloud controls
- Experience in implementing security policy and standards
- Experience of some of the following: Microsoft Entra ID, Microsoft Defender, Microsoft
InTune, JAMF Pro, and AWS Security Hub
- A passion for cyber security and the desire to help drive and improve an organisation's security posture
Please send your CV for immediate review.