Digital Security - Security Assurance Analyst
About the role
Here at DS Smith, a multi-national sustainable packaging provider, we are looking for a Security Assurance Analyst to join our growing Security Team.
The mission of the I&T Digital Security organisation is to deliver an efficient and effective service that has scalability and flexibility to support the demands of a FTSE 100 business.
Supporting Head of Information Security Architecture and Assurance as well as working closely with key stakeholders including Head of Governance, Risk and Compliance, Digital Security, IT and business teams, you will focus on core areas such as risk management and security due-diligence reviews ensuring compliance with legal, regulatory and relevant security policies and best practices.
In this position, you will provide assurance and guidance that the security features, practices, procedures, and architecture of an information system accurately mediate and enforce the security policies.
Visibility and the ability to build close working relationships with Information & Technology (I&T) team members, business stakeholders as well as external partners is essential. This will require some 'on site' visits, on a planned basis.
The role demands business insight, technical acuity, and the ability to think, communicate and write at various levels of abstraction.
About you
You will have experience in:
1. Interpreting information assurance and security policies and applying these to manage risks.
2. Providing advice and guidance to ensure adoption of and adherence to information assurance architectures, strategies, policies, standards and guidelines.
3. Planning, organising and conducting information assurance and accreditation of complex domains areas, cross-functional areas, and across the supply chain.
4. Validating operating systems, networks, software, and hardware are protected and compliant with the organisation's policies.
5. Identifying security risks and producing effective reports to articulate and report those risks along with proposed remediations in appropriate risk forums.
6. Engaging with information security operations to maintain acceptable levels of control and risk throughout the business.
7. Contributing to the development and implementation of a robust set of policies, standards and guidelines.
8. Maintaining relevant documentation related to information security.
9. Supporting monitoring of the external environment and assessment of emerging technologies.
10. Identifying risks and vulnerabilities, assessing their impact and probability, developing mitigation strategies and reporting to the business.
11. Conducting formal assessments or reviews for given domain areas, suppliers, or parts of the supply chain. Collating and examining records, analysing the evidence and drafting all or part of formal compliance reports.
12. Determining the risks associated with findings and non-compliance and proposing corrective actions.
Benefits
* Competitive salary
* Company bonus
* Pension scheme
* Life assurance
* Income protection
* 25 days holiday plus bank holidays
* Electric car scheme
* Annual Cycle to Work Scheme
#J-18808-Ljbffr