HCUK Information Security Assurance Analyst
Join to apply for the HCUK Information Security Assurance Analyst role at Santander UK
HCUK Information Security Assurance Analyst
1 day ago Be among the first 25 applicants
Join to apply for the HCUK Information Security Assurance Analyst role at Santander UK
Get AI-powered advice on this job and more exclusive features.
Company Background And Job Purpose
Hyundai Capital Services UK Ltd (HCUK), a joint venture between Santander Consumer UK and Hyundai Capital Services Korea, operates under multiple finance brands providing funding solutions for retailers and consumers. The
Country: United Kingdom
Company Background And Job Purpose
Hyundai Capital Services UK Ltd (HCUK), a joint venture between Santander Consumer UK and Hyundai Capital Services Korea, operates under multiple finance brands providing funding solutions for retailers and consumers. The Information Security Assurance Analyst reports to the CISO, Head of Information Security & IT and is tasked with supporting the effective operation, reporting, and evidencing of the company’s technology and information security controls and Information Security Management System (ISMS).
What You’ll Be Doing
Key Accountabilities
* Information Security
* Maintain and improve the ISMS.
* Review and update ISMS policies, procedures, standards, and guidance.
* Coordinate internal ISMS reviews and audits.
* Facilitate supplier onboarding and conduct annual security assessments.
* Develop and deliver security awareness initiatives.
* Monitor security alerts and incidents, escalating when necessary.
* Prepare reports on security incidents, risks, and vulnerabilities.
* Schedule penetration tests and vulnerability scans, supporting remediation efforts.
* Technology
* Analyse external vulnerability bulletins and coordinate remediation.
* Assist in evaluating cybersecurity tools.
* Use third-party assessment platforms for risk and compliance.
* Operate and improve the online ISMS platform ensuring data quality.
* Project Delivery
* Support Senior Information Security Analyst with project delivery including research, coordination, and documentation.
* Participate actively in project teams to implement security initiatives.
* Framework Management & Monitoring
* Monitor and maintain evidence of control effectiveness.
* Support audits by coordinating evidence collection.
* Evaluate controls and document nonconformities.
* Respond to audit findings ensuring timely remediation.
* Stakeholder Engagement
* Build relationships with internal and external stakeholders to support security objectives.
* Collaborate with IT teams to prioritize and track remediation of vulnerabilities.
* Communication and Reporting
* Produce clear reports on security activities and projects.
* Document and report incidents with root cause analysis.
* Generate ISMS reports using defined metrics for governance.
* Communicate risks effectively tailored to audience technical levels.
* Insight and Continuous Improvement
* Support ongoing ISMS review and enhancement.
* Research and recommend new security tools and practices.
* Keep colleagues and managers informed of security issues and implications.
* Risk and Compliance
* Assist in targeted information security risk assessments.
* Participate in risk meetings and prepare reports.
* Report risks, incidents, and breaches in line with policies.
What We’re Looking For
Key Competencies
* Documentation & Attention to Detail: Ability to translate complex technical information into business-relevant language with strong accuracy.
* Communication: Excellent verbal and written skills for technical and non-technical audiences.
* Teamwork: Collaborative and professional in building strong working relationships.
* Time Management: Effective multitasking and independent work with minimal supervision.
* Influencing & Negotiating: Builds trust and uses interpersonal skills to influence and build consensus.
* Problem Solving: Applies initiative and critical thinking with adaptability and curiosity.
Key Expertise
* Understanding of information security principles, frameworks (e.g., ISO/IEC 27001), and risk management.
* Familiarity with ISMS maintenance and security incident response.
* Knowledge of regulatory requirements such as GDPR, NIS2, and Cyber Essentials.
* Experience with third-party security assessment platforms and GRC tools is desirable.
* Exposure to vulnerability management and audit involvement is advantageous.
* Relevant education or professional qualifications in risk, compliance, or information security.
What We Offer
Key Information, Benefits and Remuneration
* Hybrid working model with a minimum of two days per week at the Reigate, Surrey office.
* Occasional domestic travel may be required.
* Salary range between £40,000 - £45,000 depending on experience.
* Eligibility for an annual bonus of up to 15%.
* 25 days holiday plus bank holidays, with flexible holiday options and additional leave after five years.
* Company pension with generous contributions.
* Voluntary benefits allowance of £500 per annum.
* Family support benefits including death in service and income protection.
* Discounted voluntary healthcare benefits and company-sponsored private medical insurance after one year.
* Employee car scheme.
* Employee assistance program.
Enhanced family-friendly policies and flexible working opportunities
Seniority level
* Seniority level
Entry level
Employment type
* Employment type
Full-time
Job function
* Job function
Finance and Information Technology
* Industries
Financial Services, IT Services and IT Consulting, and Software Development
Referrals increase your chances of interviewing at Santander UK by 2x
Sign in to set job alerts for “Information Assurance Analyst” roles.
Information Security Analyst - Audit, Compliance & Cybersecurity
London, England, United Kingdom 2 weeks ago
Information Security Analyst - Audit, Compliance & Cybersecurity
London, England, United Kingdom 1 week ago
Staines-Upon-Thames, England, United Kingdom 2 months ago
Cyber Security Business Information Systems Officer
City Of London, England, United Kingdom 2 months ago
Information Security Analyst (GRC) - Engine by Starling
London, England, United Kingdom 4 days ago
City Of London, England, United Kingdom 1 week ago
Greater London, England, United Kingdom 5 months ago
London, England, United Kingdom 6 days ago
London, England, United Kingdom 2 days ago
London, England, United Kingdom 2 days ago
Information Security & Cyber Security Analyst - Banking - £60,000-£75,000 + Bonus
Information Security (Technical) Analyst
Greenford, England, United Kingdom 2 weeks ago
Information Security Analyst – Data Protection (DLP)
Governance & Risk Information Security Analyst
Guildford, England, United Kingdom 3 days ago
Assistant Vice President - Information Security Analyst
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-Ljbffr