About this role
We are looking for a curious and hands-on Information Security Analyst to help keep FundApps secure, resilient and trustworthy as we continue to grow. This role has a broad scope, as you will work across security operations, access reviews, vulnerability management, supplier assurance, security awareness, audits, incident response, risk management and the day-to-day running of our Information Security Management System. As an Information Security Analyst, you will help operate and improve the controls that support our ISO 27001 and SOC 2 programmes, while also getting involved in the real security work that happens across a growing SaaS business. You will not be expected to know everything on Day 1, but you will be expected to learn quickly, ask good questions, follow through on details and help make security easier for everyone at FundApps. Support the operation of FundApps’ ISO 27001 and SOC 2 controls, contributing to every stage from initial evidence collection and control checks through to remediation tracking and comprehensive audit preparation. Assessing our vendors to ensure we accurately identify, evaluate, and mitigate any security risks brought in by outside partners. Partnering with Legal and Revenue to address security questionnaires and RFPs, ensuring our clients and prospects receive accurate, transparent, and timely answers about our security posture. Organising monthly review meetings. Directing the end-to-end planning of penetration testing campaigns. Supporting security awareness activities, including onboarding, refresher training, phishing reporting and practical guidance for colleagues. Helping improve security documentation and processes so that our controls are easy to follow, repeatable and genuinely useful. Recurring access reviews across key business systems, checking that permissions are correct and following up when something looks off. Helping maintain FundApps’ Information Security Management System, including security objectives, risk registers, management review inputs and follow-up actions. Working with Engineering, IT, Legal, Finance and People to make security a helpful, trusted partner in the way FundApps builds, buys and operates technology.