Now hiring

Security Analyst @ Digital Science

RemoteRemoteFull-timeRemote applicants: GB
Apply with ResuMinder

Opens on the employer's site

About this role

About us We are Digital Science and we are advancing the research ecosystem. We are a pioneering technology company, and our vision is of a future where a trusted and collaborative research ecosystem drives progress for all. We believe in better, open, collaborative and inclusive research. In creating the next generation of tools and working in partnership with the community we tackle some of the biggest challenges to research. In order to achieve our vision, we need innovative, inspiring and dynamic people to join our team. Want to join us? Your new role As our Information Security Analyst, you will be a core member of our Group Information Security team, working closely with the Security Operations Lead and Senior Analyst to keep our governance, risk and compliance programme running smoothly. You will work across assessments, audits, penetration tests and tabletop exercises, making sure findings have owners, owners have deadlines and deadlines are met. This Group Information Security team partners all areas of Digital Science and adds value through delivering all aspects of Information Security, contributing to our strategic growth plans. In this role, you will work closely with the Security Operations Lead and Senior Analyst and alongside our Technology, Legal and Operations teams with contact across all functional units within Digital Science. The successful candidate will get direct exposure to a range of security certifications and frameworks and the full audit lifecycle and does not need to have done everything on this list before, but does need to be organised, persistent and comfortable holding people to account. Please note - due to business need, we can only accept applications from candidates who reside in the following locations where we have established legal entities: UK, Spain, Germany and Romania. If you apply from outside of these areas, your application will not be considered. Please be aware that we may close this position early if we receive a high volume of applications, so we encourage you to apply promptly. Track and drive remediation of all information security related findings from internal audits, external audits, penetration tests and tabletop exercises. Maintain accurate registers, hold action owners to deadlines and escalate issues based on risk exposure. Coordinate information security evidence and inputs across multiple business areas. Chase and track all information security compliance deliverables, making sure requests from regulators compliance and audit are answered accurately and on time. Prepare progress updates on open findings, compliance deliverables and regulatory action items for stakeholders. Run and analyse phishing simulation campaigns, using the results to shape targeted awareness activity. Support the development and maintenance of information security metrics, dashboards and reporting to governance forums and senior management. Support the production of quarterly metrics and GRC assessments reports. Support internal audits and drive corrective actions through to closure, keeping registers current and accurate. Support ongoing alignment with information security frameworks including ISO 27001, Cyber Essentials, NIST 800-218 and TISAX and assess security controls against them, providing recommendations for improvement. Administer GRC tooling supports the security team and wider business areas with tracking and reporting that give clear visibility of where things stand. Build solid working relationships with action owners, compliance, risk and audit so that chasing things down does not become adversarial. Provide support for security monitoring and incident handling. Partner with technical teams to support investigations and analysis of security issues.

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores