Senior Information Security Analyst (6 month FTC)
AI in this role
Manages information security risks, controls, and compliance frameworks within financial services retirement and investment business areas.
Legal & General (L&G) is a leading UK financial services group and major global investor.
We’ve been safeguarding people’s financial futures since 1836, and strive to build a better society, while improving the lives of our customers and creating value for shareholders.
We are one of the world’s largest asset managers and provide powerful asset origination capabilities. Together, these underpin our retirement and protection solutions: we are an international player in pension risk transfer, in UK and US life insurance, and in UK workplace pensions and retirement income.
L&G Institutional Retirement looks after around 700,000 institutional customers who have their retirement benefits secured with us. Operating continuously in the UK market from our entrance in 1987, we are the UK’s longest-running insurer.
Our Institutional Retirement business is the UK’s longest-serving active bulk annuity provider.
Who we are
Institutional Retirement is the only insurer to have been operating continuously in the UK market from our entrance in 1987 to the present day. Our UK retirement annuity book stands at an estimated £86.1 billion at 31 December 2023.
Across our retail and institutional retirement businesses, we look after more than 1 million customers, around c.700,000 of whom are institutional customers who have had their retirement benefits secured with us.
We’re looking for an Information Security GRC Analyst to help strengthen our approach to information and cyber security across our Retirement Retail and Investment business areas. Working collaboratively with technology teams and business stakeholders, you’ll support the effective management of security risks and controls, drawing on recognised frameworks including ISO 27001 and NIST.
This is an excellent opportunity for someone who enjoys analysing complex information, developing practical solutions and contributing to a supportive and inclusive team. You don’t need to meet every requirement listed below. If you have relevant transferable skills and are motivated to develop your career in information security, we’d love to hear from you.
What you'll be doing:
- Interpreting security policies, standards and control requirements and translating them into practical architecture patterns and solution designs
- Advising project managers, developers and other stakeholders on security controls and good practice
- Monitoring current and emerging security risks and recommending proportionate solutions
- Supporting the assessment of vulnerabilities identified through application and infrastructure security scans
- Collaborating with technical teams to review findings, compensating controls and risk ratings
- Evaluating third-party suppliers’ security maturity and supporting due diligence, tender and contract reviews
- Reviewing system and solution configurations, identifying security issues and recommending improvements
- Supporting the scoping of penetration tests and assessing and documenting the resulting findings
Who we're looking for:
- An understanding of information security principles and controls, including areas such as encryption, identity and access management and security information and event management
- Experience gained within an IT, technology, information security, risk or business-focused environment
- Strong analytical and judgement skills, with the ability to assess information and recommend practical solutions
- Clear written and verbal communication skills, with confidence working collaboratively with a range of stakeholders
- Good organisational skills, including the ability to prioritise work, manage deadlines and use time effectively
- Experience of report writing, producing metrics, risk management or security engineering and design would be beneficial
- An adaptable and creative approach, with curiosity and a willingness to learn new technologies and solutions
- A relevant degree or equivalent practical experience in computer science, IT, business or a related discipline
Whatever your role, we reward performance and behaviour with a package that looks after all the things that are important to you. Here are some of the benefits we offer:
- The opportunity to participate in our annual, performance -related bonus plan and valuable share schemes
- Generous pension contribution
- Life assurance
- Healthcare Plan (permanent employees only)
- At least 25 days holiday, plus public holidays, 26 days after 2 years’ service. There’s also the option to buy and sell holiday
- Competitive family leave
- Participate in our electric car scheme, which offers employees the option to hire a brand-new electric car through tax efficient salary sacrifice (permanent employees only)
- There are many discounts we offer – both for our own products and at a range of high street stores and online
- We’re creating net‑zero carbon workplaces by 2030 by investing in our sustainable, modern offices across the UK, all designed to bring people together and elevate the in‑person experience
#LI-NH1
At L&G, we believe it's possible to generate positive returns today while helping to build a better future for all.
If you join us, you’ll be part of a welcoming, inclusive culture, with opportunities to collaborate with people of diverse backgrounds, views, and experiences. Guided by leaders with integrity who care about your future and wellbeing. Empowered through initiatives which support people to develop their careers and excel.
We care passionately about outcomes rather than attendance and are therefore open to discussing all kinds of flexible working options including part-time and job shares. Although some roles have limited flexibility due to customer demand, we accommodate requests when we can.
It doesn’t matter if you don’t meet every single criterion in this advert. Instead, think about what you excel at and what else you can bring in terms of strengths, potential and connection to our purpose.
How we rate this
Senior Information Security Analyst (6 month FTC) at Legal & General rates 10 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.
Little AI. AI is not part of the work.
- ●●●● Builds AI80 to 100
- ●●●○ Works on AI60 to 79
- ●●○○ Uses AI40 to 59
- ●○○○ Little AI0 to 39
Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.
Prepare for this job
A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.
Skills and AI tools this role asks for
Questions you could be asked
- Tell me about a project where information security was part of your work. What did you do?
- Tell me about a project where grc was part of your work. What did you do?
- Tell me about a project where risk management was part of your work. What did you do?
- Tell me about a project where cyber security was part of your work. What did you do?
- Walk me through how you've used Iso 27001 in your day-to-day work.
Adapt your resume
- List these exact terms on your resume: Information Security, Grc, Risk Management, Cyber Security, and Iso 27001. An applicant tracking system matches the wording, not the idea.
- Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.
Want an expert to read your CV for this job?
Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.
Get a free CV reviewGet new remote cybersecurity jobs by email
One email a week with the new remote cybersecurity jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.
Free. One email a week. Unsubscribe in one click.
Similar roles
Security roles that involve little AI, at other companies.
What kind of AI work fits you?
Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.
Find my next step