FULL TIME - 37hrs
JOB PURPOSE
The Security and Governance Analyst role provides very important support to the IT team and the wider organisation. They would work closely with the IT Manager and our security partners to ensure the security and integrity of Two Saints information systems and infrastructure. Responsible for collaborating on policies, procedures, and administering controls to protect sensitive data from cyber threats and ensure compliance with regulatory requirements, reporting performance back to the IT Manager, Performance and Executive teams.
MAIN RESPONSIBILITIES
1. In conjunction with the IT Manager, build a constructive relationship with Two Saints’ principal IT suppliers to ensure that the contracted standards of service and support are met
2. Work together with these suppliers to ensure that Two Saints’ ICT Security policies are applied and followed correctly
3. Regularly review the security preparedness of our supply chain
4. Work with the Learning and Development Manager and the HR team to establish a minimum standard of cyber awareness skills for Two Saints’ staff – assess the quality of both internal and external trainers with the delivery of training and awareness through learning platforms and internal communication
5. In conjunction with Systems & Applications Support and Network Support colleagues, maintain accurate records of software licences, equipment types and locations etc.
6. Ensure the organisation maintains a good level of IT security by evaluating risks and solutions. Continue to implement and develop solutions in line with ongoing threats
7. Assist in ensuring the organisation remains GDPR compliant and provide support for subject access requests and destruction of data in line with data governance
8. Support the IT Manager to review and maintain data governance policies and Data Loss Prevention (DLP) using Microsoft compliance tools
9. Oversee daily security checks and carryout any follow up action required
10. Reporting to the IT Manager, maintain security standards by ensuring operating system patches and hardware/firmware updates are applied across the network
11. Ensure all documents, processes and procedures for the ICT team are kept updated
12. Create and develop required reports for the organisation, including producing monthly and quarterly reports for the senior management teams. Responsible for using the organisations preferred reporting tools to produce meaningful reports
13. Working with the IT Manager, support and implement risk management processes to identify and mitigate IT risks.
14. Regular auditing and monitoring of IT systems to ensure data integrity, security, and compliance.
15. Support the IT Manager to ensure that IT projects and operations comply with internal and external policies, regulations, and standards.
16. Work with the IT Manager to design and implement frameworks and procedures to ensure IT security and governance aligns with organisational objectives.
17. Staying informed about the latest IT trends and advancements to inform cyber strategies and policies.
18. This role has business continuity responsibilities
ROLE REQUIREMENTS
19. This role may require a standard disclosure and barring service check.
20. This role will require a full drivers’ licence and access to a vehicle
21. This role will require you to work flexibly across several sites
EXPERIENCE AND QUALIFICATIONS
ESSENTIAL CRITERIA
22. Achieving Cyber Essentials / CE+
23. Working with Security Frameworks
24. Awareness of Operational Risk Management Processes
25. Experience of Project Working
26. CompTIA Security+, Certified Information Security Manager or equivalent
Experience working with data protection and compliance
DESIRABLE CRITERIA
27. 3rd Party Management, particularly with MSP’s and CSOC’s
28. Designing Cyber Security Awareness Programmes for internal staff awareness
KNOWLEDGE AND SKILLS
ESSENTIAL CRITERIA
29. GDPR Compliance
30. Hardware firmware and Microsoft patching requirements
31. Asset Management
32. Management Reporting
33. Microsoft Defender
34. PCI-DSS
DESIRABLE CRITERIA (experience of)
35. NHS DSP Toolkit
36. NIS2
37. ISO27001
38. Microsoft Sentinel (or other SIEM solution)
39. Microsoft Purview
40. Strategy creation