Hiring.Camp

Information Security and Data Protection Analyst

Interact Software

·

Today

Location
Manchester, UK
Type
Full-time
Department
Security

Description

Information Security and Data Protection Analyst

Department: Engineering

Employment Type: Full Time

Location: Manchester, UK

Reporting To: Zack King



Description

Interact provides enterprise-grade intranet software that connects over three million employees to leading global names like Levi's, Domino’s, Teva Pharmaceuticals, and Technicolor.

Our team of customer-focused problem solvers are passionate about helping organizations to communicate better. We do this together by constantly working to improve every service and product we offer. With offices in Manchester, New York, Dubai, Tulsa, and Warsaw, we operate across North America, EMEA, and Australia.

Click on any of our vacancies and you’ll see one thing in common – they all begin with this message. Why? Because at Interact we treat everyone with the same respect and honesty. Whether you’re a developer fresh out of college or a seasoned salesperson, we live the motto that we uphold for our customers: our people are our most valuable assets.

Your objective will be to support and strengthen the organisation's information security and data protection framework by maintaining compliance with recognised security standards and regulatory requirements, including ISO 27001, SOC 2, Cyber Essentials and UK GDPR. 
The role is responsible for identifying, assessing and mitigating security and privacy risks, managing certification and audit activities, supporting incident response and remediation, and promoting a culture of security awareness across the business. Working closely with technical and business stakeholders, the Information Security & Data Protection Analyst will balance security and compliance requirements with commercial priorities, driving continuous improvement in governance, risk management and data protection practices while helping to safeguard the organisation's information assets and reputation


Role Responsibilities

  • Creating, reviewing and improving the security policies.  
  • Implement and maintain Information Security Management System (ISO27001 certification) 
  • Contribute to activities towards certification/compliance to security. standards and regulations (ISO 27001, SOC 2, Cyber Essentials, etc.) 
  • Experience of undergoing audits  
  • Support progress on business continuity plans and policy  
  • Build and maintain relationships with technical and business stakeholders.  
  • Leading regular risk assessments and internal process audits.  
  • Working with internal teams and stakeholders to manage risks, suggest solutions, and resolving issues.  
  • Support and lead with evidence collation for audits.  
  • Conduct vendor/supplier reviews in line with Internal Policy.  
  • Experience in completing client security questionnaires for prospects and customers  
  • Maintain and improve information security awareness within the business.  
  • Conduct monitoring activities as required with the UK GDPR and other data protection laws, again our data protection policies  
  • Work with regulator investigations as required in Article 36 
  • Point of contact to our employees and individuals about data processing activities.  
  • Supporting the business maintaining the Security tickets through prompt follow-up and resolution, in collaboration with teams and other stakeholders. 
  • Management of penetration testing remediations. 



Skills, knowledge & expertise

  • 2–3 years minimum in an information security or data protection role  
  • Hands-on experience with at least two certification cycles (ISO 27001, SOC 2, etc.) from start to finish. 
  • Demonstrable experience managing or influencing stakeholders at a senior level. 
  • Involvement in penetration testing activities and remediations. 
  • Experience handling real security incidents or data breaches. 
  • Ability to pragmatically balance security risk against business need  
  • Maintenance and creation of the Risk Register, ROPA & DPIAs   
  • Strong awareness of the GDPR, either through training from working within a business that processes personal data or independent learning. 
  • Strong practical understanding of security and compliance frameworks, such as ISO27001, SOC 2 type II and Cyber Essentials Plus. 
  • Practical working knowledge of Defender, Intune, Entra, Purview, AWS and Azure 
 
Desirable but not essential  
  • Knowledge of GRC tools such as Drata and Safebase. 
  • Knowledge of Security and Awareness training tools, campaign creation etc. 
  • SaaS background 
  • Good understanding of Risk Management and continuous improvement practices.  
 


Benefits

  • 25 days annual leave (with the option to buy and sell additional days)
  • Cycle to work scheme
  • Access to Learning & Development platform
  • ‎Life Insurance
  • Auto Enrolment Pensions
  • ‎Healthshield (Cashback on dental check-ups and fillings, eye tests, physiotherapy, prescriptions and much more
  • Reimburse for usage of personal mobile phone
  • ‎Free Gym membership and Free Friday lunch for office based staff

Skills

AWSAzurePenetration TestingSOCRisk ManagementComplianceSOC 2GDPRISO 27001

Similar Jobs

30

Security Information and Event Management Tester (AU Citizen with Security Clearance)

Accenture · Canberra, Brindabella Business Park, Australia · Onsite

Today

INFORMATION SECURITY AND PRIVACY SPECIALIST

Braskem · Rotterdam, Zuid-Holland, Netherlands, NL

2 days ago

Security and Information Risk Advisor

Scottish Government Recruitment · Glasgow, United Kingdom, GB · Hybrid

2 days ago

Head of the Regional Governance Unit for Information Security and Data Protection - Bosch Switzerland 100% (f/m/div.) REF290730T

Robert Bosch · Zuchwil, SO, Switzerland · Hybrid

2 days ago

Associate Data Privacy and Information Security Officer

Harvard University · Cambridge, MA, United States · Hybrid

3 days ago

Vice President & Chief Information and Security Officer-Executive

Person Centered Services · 560 Delaware Ave, Buffalo, NY 14202, USA

6 days ago

Director , Information Security and IT

Luna Physical Therapy · REMOTE · Remote

1 week ago

Information Security and Data Privacy Manager - Band 1

Pg · MUMBAI GENERAL OFFICE, India

1 week ago

VP, Information Security and Compliance

JOIN THE TEAM · United States of America - Remote · Remote

2 weeks ago

Senior Compliance Advisor - Technology, Cybersecurity, Information Security, and AI ("TCIA")

Vanguard · Malvern, PA, United States of America +1

3 weeks ago

Senior Compliance Advisor - Technology, Cybersecurity, Information Security, and AI ("TCIA")

Vanguard · Malvern, PA, United States of America +1

3 weeks ago

Vice President, Information Security and Digital Risk Management

Ocbc · Hong Kong · Onsite

1 month ago

Information Security and Assurance Advisor

Data Careers · GB · Onsite

1 month ago

Information Security and Compliance Analyst Intern

Interac Corp. · Interac Corp. Head Office, Canada

1 month ago

Senior Strategic Advisor - Information Security and Infrastructure

CVS Health · Hartford-Farmington Ave Atrium, United States of America · Remote

2 months ago

Associate Information Security and Compliance

Datavail Infotech Pvt. Ltd. · Mumbai, Maharashtra, India · Onsite

2 months ago

Trainee, IT Service Delivery and Information Security (1 year contract)

Transamerica · Hong Kong TLB, Hong Kong

2 months ago

Manager — Information Security and Compliance

Apexanalytix · Noida, India

3 months ago

AVP, Information Security and Digital Risk Management

Ocbc · SGP-Head Office, Singapore · Hybrid

4 months ago

Information Security and Compliance Lead

Hitachi Solutions · Sofia, Sofia City Province, Bulgaria · Hybrid

4 months ago

Cybersecurity and Information Security Manager

duPont REGISTRY · Miami, Florida

8 months ago

Sr Manager, Information Security and Compliance

Tarro · Dumaguete +1 · Onsite

1+ year ago

Information Security and Compliance Consultant - Future Availability

CoNetrix

1+ year ago

Chief Information Security Officer and Privacy Officer

Lvs1 · Calgary +3 · Hybrid

Today

Director, Third-Party Risk Management and Technical Information Security Lead

Pfizer · USA - NY - Headquarters, United States of America +1

1 week ago

Director, Third-Party Risk Management and Technical Information Security Lead

Pfizer · USA - NY - Headquarters, United States of America +1

1 week ago

Director, Third-Party Risk Management and Technical Information Security Lead

Pfizer · USA - NY - Headquarters, United States of America +1

1 week ago

Head of Governance, Risk and Compliance (Information Security)

Leonardocompany · GB - Basildon - Home Based, United Kingdom +9 · Hybrid, Remote

1 week ago

Manager Information Technology and Security Operations

"Olivine, Inc." · Chicago, IL

2 weeks ago

Student Internship - Information Security Awareness and Education

Abb · Krakow, Malopolskie, Poland · Hybrid

4 weeks ago