- Salary
- £60k – £65k/yr
- Location
- London, UK
- Type
- Full-time
- Department
- Security
- Visa
- Not sponsored
- Source
- Pinpoint
Description
Information Security Analyst
Department: Operations
Employment Type: Full Time
Location: London, UK
Compensation: £60,000 - £65,000 / year
Description
This role has a broad scope, as you will work across security operations, access reviews, vulnerability management, supplier assurance, security awareness, audits, incident response, risk management and the day-to-day running of our Information Security Management System.
As an Information Security Analyst, you will help operate and improve the controls that support our ISO 27001 and SOC 2 programmes, while also getting involved in the real security work that happens across a growing SaaS business. You will not be expected to know everything on Day 1, but you will be expected to learn quickly, ask good questions, follow through on details and help make security easier for everyone at FundApps.
What you will own
- Working with Engineering, IT, Legal, Finance and People to make security a helpful, trusted partner in the way FundApps builds, buys and operates technology.
- Taking full, end-to-end ownership of FundApps’ ISO 27001 and SOC 2 controls operation, managing every stage from initial evidence collection and control checks through to remediation tracking and comprehensive audit preparation.
- Organising and chairing monthly review meetings.
- Partnering with Legal and Revenue to address security questionnaires and RFPs, ensuring our clients and prospects receive accurate, transparent, and timely answers about our security posture.
- Directing the end-to-end planning and execution of penetration testing campaigns.
- Managing and facilitating annual business continuity planning (BCP) exercises.
- Assessing our vendors to ensure we accurately identify, evaluate, and mitigate any security risks brought in by outside partners.
- Supporting vulnerability management across our estate, helping teams understand, prioritise and remediate issues rather than just logging them.
- Monitoring security alerts, incidents and internal security events, escalating where needed and helping ensure issues are properly investigated, understood and closed out.
- Supporting security awareness activities, including onboarding, refresher training, phishing reporting and practical guidance for colleagues.
- Helping improve security documentation and processes so that our controls are easy to follow, repeatable and genuinely useful.
- Recurring access reviews across key business systems, checking that permissions are correct and following up when something looks off.
- Helping maintain FundApps’ Information Security Management System, including security objectives, risk registers, management review inputs and follow-up actions.
What You'll Bring To The Team
Hands-on and thorough: You don't settle for the easy or convenient answer. If an access review throws up something odd, or a vulnerability report doesn't quite add up, you'll get into the detail, ask the awkward questions and follow the thread until you genuinely understand what's going on.
Work-with-purpose: You can articulate the value of your own work in the bigger picture. You understand that a third party review isn't just a task, it’s a way to surface risks and it's part of keeping FundApps and its clients safe. You're comfortable with ambiguity and evolving requirements.
Have-courage: You're comfortable asking for and giving feedback, and you're not afraid to say "I don't understand this, can you explain it" in front of others. You participate in debates, brainstorms and team conversations, and you build strong relationships with colleagues across the wider company.
Be-transparent: As a company, we value and aspire to transparency at all levels; you'll provide work updates to communicate regularly about progress and blockers and reach out for help when needed.
Raise-the-bar: You seek out opportunities to improve our workflows, processes and practices; 1% improvements over time improve things for everyone. You're the type of person who asks "why do we do it this way?" rather than just following a checklist.
Do-more-with-less: You identify and help implement improvements to processes and standards within the team, seek to optimise our workflows, and share ideas for how to automate manual tasks. As a company, we try to minimise meetings (we have meeting-free Wednesdays) and default to asynchronous written communication over long, multiple-person meetings.
A Few Things To Know Before You Apply
After that, our policy is at least 2 days per week in the office to collaborate, connect and enjoy our shared space and team activities.