
Cyber Assurance Analyst London, England
Job description
- Determining that correct measures of governance and controls are in place to validate identified cyber risks and vulnerabilities are prioritised correctly and remediated based on agreed C&IR SLAs
- Validate operational decisions with stakeholders (such as BTS Product Groups) are made in accordance with our policies and standards and do not increase the overall risk exposure of the FCA
- Assess, measure and report findings of our key applications and security and information assurance controls
- Facilitate the identification and proportionate management of risk to our suppliers
- Directly support the development and operation of the systems and infrastructure assurance frameworks, helping ensure they remain aligned to the C&IR strategy
- Represent the C&IR assurance framework where required to promote clear and measurable security assurance requirements and decisions
- Drive secure testing and remediation of our critical applications with key stakeholders such as IT product groups, including red team testing
- Supporting the development of the cloud assurance regime, within our cloud environments (i.e. AWS)
- Tracking and planning of vulnerability prioritisation and remediation
- Operating the running & development of security assessments & assurance testing activities
- Operation of the pen testing process, including threat assessments and breach attacking simulations in conjunction with our third-party security testers
- Ensure adequate monitoring capability is incorporated into solutions and feed into information and cyber risk metrics and key risk and performance indicators
- Solid awareness of cyber and information security threats and their mitigations
- Monitoring compliance with cyber policies, standards and frameworks, in particularly ISO 27001 and NIST 800, OWASP and MITRE
- Build strong working relationships with key contacts, stakeholders and business colleagues
- Assist in setting the scope for assurance activities and setting risk tolerance with regards to identified issues
- Collate and produce (and automate where possible) assurance reporting and metrics that is appropriate for the relevant audience
- 25 days holiday per year
- Private healthcare with Bupa
- A non-contributory Pension of at least 8% of your basic salary each month (there are several contribution levels that increase depending on your age – up to 12% a month once you reach the age of 35)
- Life assurance of eight times your basic salary
- Income protection
- We support hybrid working which means you will be able to work from home up to 60% of the time over a month with the remainder of your time in one of our three office locations
- An opportunity to tackle a challenging, interesting and varied portfolio of work, working with key stakeholders and senior members across the FCA
- An opportunity to own and drive the cyber assurance testing agenda
- An opportunity to be innovative and contribute to an evolving team within the FCA
- Broadening of existing technical skills and knowledge
- Involvement in the development of cyber and information assurance activities within the FCA
- Interesting and fast moving work in a friendly, goal-orientated environment
- Involvement in a team that is making a difference to the way the FCA operates
Minimum
- A technical degree or relevant professional cyber security qualification (e.g. CISSP, CISM, CCSP or CEH)
- Demonstrable expertise working with ISO 27001/2, NIST 800-53, NIST CSF, CIS Top 20 , CIS benchmarks and/or ISF security frameworks
- Possesses relevant expertise and qualifications in applying principles driven by industry best practice
- Demonstrable experience within the design, implementation and management of systems and/or assurance frameworks
- Detailed understanding of information security, particularly security testing and vulnerability management
- Relevant experience in cyber security
- Experience of a technical business change work stream
- Ability to develop effective relationships with internal and external stakeholders
Desirable
- Keen desire to keep up to date with online technologies and trends
- Experience of a hands-on role involving pen testing and vulnerability assessment activities of complex applications and operating systems
- Knowledge of COBIT or other recognised risk management frameworks
The FCA's Values & Diversity
Flexible working
Multilocation & hybrid working
Useful information
Got a question?
Please note that all applications must be submitted through our online portal before the closing date, applications sent via email will not be accepted.
