Position: Information Security Compliance Analyst
Based: Milton Park, Abingdon
Type: Permanent, Full Time
Salary: £30,000 - £35,000
RPS is going through an exciting period of transformation. The Global Technology Team is responsible for the delivery of Technology services to the REST of the company
An opportunity has arisen for an Information Security Compliance Analyst to join the established team. This role will ideally suit an ITIL certified IT professional who holds appropriate 3rd level qualifications in information systems, security and compliance. Suitable candidates will already have several years’ practical experience in information security compliance in addition to the ISO27000 lead auditor certification. Additional certifications in CISSP, CISM, CISA are desirable.
About the role
- Maintaining compliance to ISO2700 through coordination and completion of risk assessments, internal and external auditing, reviews and assessments for each applicable compliance scope.
- Defining and implementing security compliance policies and controls to minimise risks
- Contributing to data governance, privacy, risk and personal data protection activities across the business, including tasks essential for data protection legislation compliance.
- Communicating clearly our security posture by responding to security related questionnaires and other communications with our business partners and clients.
- Ensuring third parties, suppliers and partners have the same effective policies and controls in place to protect the confidentiality, integrity and availability of business data
- Reporting key risks and mitigating controls as well as the quality of compliance programmes to senior management on a regular basis and obtaining resulting feedback
Essential Skills
- Excellent knowledge of information security controls and standards including ISO27001/2, OWASP, CSA CCM, CIS, SOC.
- Strong knowledge and experience of IT and Information systems and cloud technologies
- Strong knowledge of key concepts of the information security portfolio and security operations principles, techniques and technologies.
- Ability to maintain regular, effective communications with stakeholders to ensure critical information is conveyed with appropriate detail
- Ability to articulate complex issues in a consumable manner to audiences, whilst maintaining confidentiality and sensitivity
- Confident in designing, implementing and operating controls including policies and procedures
- Good Understanding of regional data protection laws, e.g. EU GDPR.
- Confident writing and communication skills in process and control descriptions and security audit reports
What we offer you
We will provide you with a flexible, friendly and creative environment to develop your skills and challenge yourself.We support our people to innovate, collaborate and build meaningful careers. Our network of people and knowledge will expand your horizons and give you access to a variety of interesting projects.
Our employees are rewarded with competitive salaries, opportunities to invest and many other benefits including:25 days holiday + bank holidays, Option to purchase up to 5 extra days per year, Company pension scheme, Group Disability Scheme, Share Incentive Scheme, Life Assurance, Cycle to Work Scheme, Health Screening, Employee Assistance Programme, Professional Memberships
About RPS
RPS is a leading global professional services firm of 5,200 people. We define, design and manage projects that create shared value in a complex, urbanising and resource-scarce world. Connecting with our global expertise we make it easy for our clients to create winning solutions for their communities and their clients. By being confidently pragmatic we solve problems that matter. We make complex easy.