About this role
Purpose Information security is critical to maintaining Lancashire’s operational resilience, regulatory compliance and protection of Group assets. Reporting to the Head of Cyber Security & Risk, the Principal Information Security Analyst is responsible for the day-to-day delivery and continuous improvement of the information security function, with a primary focus on technical assurance, control validation and cyber risk management. The role acts as the primary technical subject matter expert within a flat team structure, leading complex assurance activities, providing technical challenge across business and technology initiatives, and supporting high-quality risk and assurance outcomes. The role works collaboratively with the Senior Information Security Analyst to embed technical assurance into day-to-day delivery activities and strengthen overall security capability across the team. The role supports the Head of Cyber Security & Risk, working collaboratively with other Information Security team members to provide technical expertise and challenge across risk and assurance activities, while supporting the development of Information Security Analysts through knowledge sharing and involvement in complex assurance work. Lead and contribute to the delivery and continuous improvement of the Information Security Management System (ISMS), ensuring alignment with regulatory requirements and recognised frameworks (e.g. NIST CSF, NYDFS, ISO 27001). Translate strategic direction into operational assurance activities, ensuring effective tracking, governance and reporting of security activities, control performance and key risk indicators. Own the day-to-day management of cyber risk, including maintenance of the risk register and oversight of remediation activities. Undertake and drive cyber risk and control assessments across business operations, change initiatives and third parties. Deliver technical assurance activities, including control testing, validation and evidence gathering, ensuring outputs are robust, consistent and defensible. Manage and coordinate responses to internal and external audit findings, ensuring timely and effective remediation. Support regulatory reporting and maintain appropriate documentation and evidence to demonstrate compliance. Act as the primary technical subject matter expert, providing guidance and challenge across IT infrastructure, applications, cloud and third-party environments. Provide technical validation and challenge through governance forums (e.g. CAB), ensuring security implications of changes are understood and addressed. Assess and challenge new systems, services and application onboarding to ensure compliance with security standards and control requirements. Develop and apply threat modelling and technical assurance approaches to support secure design and risk identification. Provide challenge and input into third-party security assurance activities where required, ensuring third-party risks are appropriately assessed and managed. Support response and investigation of cyber security incidents through technical analysis and control validation, contributing to effective response and continuous improvement. Work with the SOC provider to support the effectiveness of monitoring, detection and response controls. Provide technical guidance and knowledge sharing to support team capability and development.