About this role
We are looking for a curious and hands-on Information Security Analyst to help keep FundApps secure, resilient and trustworthy as we continue to grow. This role has a broad scope, as you will work across security operations, access reviews, vulnerability management, supplier assurance, security awareness, audits, incident response, risk management and the day-to-day running of our Information Security Management System. As an Information Security Analyst, you will help operate and improve the controls that support our ISO 27001 and SOC 2 programmes, while also getting involved in the real security work that happens across a growing SaaS business. You will not be expected to know everything on Day 1, but you will be expected to learn quickly, ask good questions, follow through on details and help make security easier for everyone at FundApps. Working with Engineering, IT, Legal, Finance and People to make security a helpful, trusted partner in the way FundApps builds, buys and operates technology. Taking full, end-to-end ownership of FundApps’ ISO 27001 and SOC 2 controls operation, managing every stage from initial evidence collection and control checks through to remediation tracking and comprehensive audit preparation. Organising and chairing monthly review meetings. Partnering with Legal and Revenue to address security questionnaires and RFPs, ensuring our clients and prospects receive accurate, transparent, and timely answers about our security posture. Directing the end-to-end planning and execution of penetration testing campaigns. Managing and facilitating annual business continuity planning (BCP) exercises. Assessing our vendors to ensure we accurately identify, evaluate, and mitigate any security risks brought in by outside partners. Supporting vulnerability management across our estate, helping teams understand, prioritise and remediate issues rather than just logging them. Monitoring security alerts, incidents and internal security events, escalating where needed and helping ensure issues are properly investigated, understood and closed out. Supporting security awareness activities, including onboarding, refresher training, phishing reporting and practical guidance for colleagues. Helping improve security documentation and processes so that our controls are easy to follow, repeatable and genuinely useful. Recurring access reviews across key business systems, checking that permissions are correct and following up when something looks off. Helping maintain FundApps’ Information Security Management System, including security objectives, risk registers, management review inputs and follow-up actions.