Information Security Analyst
Legal, London
Information Security Analyst
Legal, London

The team you'll be working with:

NTT DATA is looking for an Information Security Analyst to join our Governance, Risk & Compliance team.

This is a broad Information Security role with additional responsibility for supporting Business Continuity and Operational Resilience. You'll help us maintain and continually improve our Information Security Management System (ISMS), support security risk and compliance activities, and help ensure the organisation is prepared to respond effectively to disruption.

You'll be joining a small team and will have exposure to a varied range of activities across information security governance, risk management, audit and assurance, incident management, business continuity and resilience.

We are open to candidates at different stages of their career. You may already be working in Information Security or GRC, or you may have developed relevant experience through risk, compliance, audit, business continuity or operational resilience. You don't need to be an expert in every area – we're particularly interested in people with a good grounding in information security, strong analytical and organisational skills, and an interest in developing their knowledge further.

What you'll be doing:

  • Your primary focus will be Information Security, including:
  • Supporting the operation and continual improvement of our Information Security Management System (ISMS), aligned with ISO 27001.
  • Assisting with security risk assessments, control reviews and remediation activities.
  • Maintaining information security policies, standards, procedures and supporting documentation.
  • Supporting internal and external audits, customer assessments and wider compliance activities.
  • Assisting with information security incidents, investigations and root cause analysis.
  • Tracking security risks, vulnerabilities, corrective actions and improvement plans.
  • Supporting third-party security due diligence and supplier assurance.
  • Contributing to security awareness and training activities.
  • Producing security metrics, dashboards and reports for governance forums and leadership teams.
  • Acting as a point of contact for information security queries from stakeholders across the business.
  • You'll also support our Business Continuity and Operational Resilience activities, including:
  • Supporting the maintenance and improvement of our Business Continuity Management framework, aligned with ISO 22301.
  • Coordinating Business Impact Assessments (BIAs) with different business functions.
  • Helping teams develop, review and maintain Business Continuity Plans and recovery procedures.
  • Supporting crisis management, major incident and recovery activities when required.
  • Coordinating business continuity and resilience exercises, including tabletop exercises and simulations.
  • Tracking testing, lessons learned and resulting corrective actions.
  • Supporting reviews of continuity documentation and recovery arrangements.
  • Contributing to resilience risk assessments, reporting and compliance activities.
  • Helping promote business continuity awareness across the organisation.
  • You'll also help maintain risk registers and action trackers, prepare materials for governance meetings, support client and regulatory assurance requests, and contribute to the development and measurement of KPIs and KRIs.

 

What experience you'll bring:

We're looking for someone with experience or relevant exposure in one or more of the following areas:

  • Information Security
  • Governance, Risk & Compliance (GRC)
  • Risk or audit
  • Business Continuity
  • Operational Resilience

You'll bring:

  • A good understanding of information security principles, controls and risk management.
  • An understanding of ISO 27001 and information security governance.
  • An understanding of Business Continuity and Operational Resilience concepts, including ISO 22301.
  • The ability to produce clear reports, metrics and governance documentation.
  • Strong analytical, organisational and problem-solving skills.
  • Good attention to detail.
  • The confidence to engage and communicate effectively with stakeholders across the business.
  • Good working knowledge of Microsoft 365.
  • Practical experience supporting an ISMS or Business Continuity programme would be useful, but isn't essential.

Nice to have

  • NIS2
  • DORA
  • Cyber Essentials
  • GDPR
  • Security or Business Continuity audits and certification activities
  • ISO 27001 Foundation or Lead Implementer, ISO 22301 Foundation, CISSP, CISM, CRISC or CBCI.

 

What will help you succeed

You'll enjoy working with detail while still being able to see the bigger picture. You'll be comfortable managing several activities at once, working collaboratively with colleagues and following issues through to resolution.

We're particularly interested in people who bring a risk and control mindset, strong communication skills and a continuous-improvement approach.

This could be a good opportunity for someone looking to broaden their Information Security and GRC experience, with exposure not only to security governance and risk but also to Business Continuity and Operational Resilience.

The role is UK-based and predominantly remote, with an expectation of attending London approximately once a month.

Who we are:

At NTT DATA, you have endless opportunities to think big, act bold and take ownership. As a $30+ billion business and technology services, AI and digital infrastructure leader, we co-innovate solutions with clients and partners globally for business and societal impact. Serving 75% of the Fortune Global 100, with experts in over 70 countries, we encourage experimentation and recognize great work. Proudly a Global Top Employer, NTT DATA is part of NTT Group, which invests over $3 billion annually in R&D. Make this the place where you belong, learn, and build your network. Make this the place where you grow.

what we'll offer you:

We offer a range of tailored benefits that support your physical, emotional, and financial wellbeing. Our Learning and Development team ensure that there are continuous growth and development opportunities for our people. We also offer the opportunity to have flexible work options.

You can find more information about NTT DATA UK & Ireland here: https://uk.nttdata.com/

We are an equal opportunities employer. We believe in the fair treatment of all our employees and commit to promoting equity and diversity in our employment practices. We are committed to creating a diverse and inclusive workforce. We actively collaborate with individuals who have disabilities and long-term health conditions which have an effect on their ability to do normal daily activities, ensuring that barriers are eliminated when it comes to employment opportunities. In line with our commitment, we guarantee an interview to applicants who declare to us, during the application process, that they have a disability and meet the minimum requirements for the role. If you require any reasonable adjustments during the recruitment process, please let us know. Join us in building a truly diverse and empowered team.

Back to search Email to a friend Apply now

Location
Epworth House, London

“Upon joining the NTT DATA UK family, you will experience a culturally diverse organisation living our values of Clients First, Teamwork and Foresight as we partner with our customers every day.

At NTT DATA UK, we are proud to support and invest in our people. We offer a variety of rewarding career paths and opportunities to develop professionally - with access to cutting edge innovation.”

Niccolo Spataro, CEO, NTT DATA UK

NTT DATA
#loveyourwork
Apply
Jobs at NTT DATA

Browse all