Job description
We are looking for an individual who is professional, enthusiastic, and a self-starter who is eager to develop their career in Information Security. This is an ideal role for someone who wants to lead our information security assurance programme to standards such as Cyber Essentials and ISO27001.
Whilst you will be asked to get involved in other work from time to time, this is an ideal role for someone who excels in security auditing and would like this to be the main focus of their day to day role.
This is a Governance, Risk and Compliance (GRC) role, reporting to the Head of Information Security, and working in collaboration with the Security Operations and IT teams to develop and improve the information security framework in place.
Role: Information Security Assurance Analyst
Location: Primarily home based with 1 day a week in the Liverpool office. More days in the office can be accommodated if preferred.
Working hours: 37.5 hours, Monday to Friday from 9am to 5:30pm
Salary: £35,000 - £45,000 DOE
What you will be doing:
- Proactively review and assess the control framework through security assurance audits, and produce reports that highlight good practice, risks and improvements.
- Help to design, develop and deliver the information security assurance programme and plan to ensure it covers key controls and risks that are specific to our business and the industry.
- Work with the business to align, maintain and develop the information security framework to recognised standards such as Cyber Essentials, ISO27001, PCI-DSS.
- Engage both technical and non-technical stakeholders across the business to ensure findings are agreed and tracked through to completion.
- Keep trackers and documentation up to date and produce monthly and quarterly MI packs that identify key findings, trends, KPIs and KRIs.
- Support and participate in working groups to steer information security.
- Keep up to date with the latest changes in industry standards, emerging threats, news and guidance
- Assist with other cyber and information security risk management and governance initiatives.
- Assist with the delivery of information and cyber security training and awareness to colleagues.
- Provide practical help and advice to the business on information security matters.
- Assist with information security incident management, from triage to resolution.
- Work with business change projects to ensure security risks are identified, including the assessment of third party supplier security frameworks and controls.
What we’re looking for:
- Experience in an information security role, with a good understanding of information security governance, risk and compliance principles. A good level of technical security knowledge is desirable.
- A suitable audit qualification such as ISO27001 Lead Auditor or similar is desirable.
- Practical experience of carrying out security assurance audits from start to finish against security standards such as ISO27001 and Cyber Essentials and making practical recommendations through clear report writing.
- Experience of assisting with or leading the accreditation process to ISO27001. Clear ability to engage with technical and non-technical stakeholders across the business.
- The ability to apply a range of research techniques to gather relevant information and up to date information on latest changes in industry standards, emerging threats, news and guidance.
- Ability to offer considered and practical advice to the business and have strong verbal and written communication skills.
- Strong administrative skills.
- Drive and determination to complete work to a high standard with attention to detail.
- Plan, organise and manage time effectively.
About Acorn Insurance
We have over 40 years of experience helping people secure competitive car, taxi, van, motor trade and home insurance, across the UK. As a specialist insurance provider, we offer a wide range of competitive insurance policies that can are tailored to our customers unique insurance needs. In 2020 we were in the Sunday Times top 30 Profit Track companies for private companies with fastest growing profits.
Why Acorn Insurance?
Acorn want to give you more than a job, we want to give you a purpose and a career. So, what can we offer you as an employer? Some of the benefits you will receive include:
- Enhanced Annual Leave entitlement starting at 31 days and potentially increasing to 35 days per year depending on grade & length of service (including bank holidays)
- Additional Buy & Sell Holidays
- Company Sick Pay Scheme
- Company Paid Maternity & Paternity Leave
- Enhanced Company Pension Scheme
- Perk Box Online & High Street vouchers and discounts
- Fresh fruit Deliveries twice a week*
- £250 bonus for every new colleague you recommend to the business
- Free monthly Café Nero Coffee
- Cycle to work scheme
- Free eye test vouchers and a contribution towards the frames
- Clearly defined progression paths with training and support
- National vocational qualifications
- Free self-development & qualifications via Magpie Learning
- A comprehensive Mental Health support network including:
- A wide Network of Mental Health First Aiders 4 free counselling sessions
- CBT programmes available with a trained Therapist Mentor
- Unlimited access to a councillor 365 days a year, 24/7
- Free Hot Drinks*
- Dress Down Days
- Regular Employment Engagement including ongoing competitions with fantastic prizes
- Charity fundraising events
- on selected sites
If you would like any further information, please call our Talent Acquisition Department who will be happy to assist you with any queries on 01704 336 012 or alternatively email [email protected]
All roles are subject to DBS and Financial checks, any offer made will be conditional until checks are completed to satisfactory standard.