Information Security Analyst
G MASS is seeking to deploy one of our own Information Security Analysts into a specialist Lloyd's / London Market insurance engagement, on a fixed-term contract (FTC) running to the end of November 2026. The consultant will be embedded within the client's Information Security function, providing hands-on support across third-party risk management, day-to-day security operations, incident support, and compliance and assurance activity. This is a client-facing, delivery-focused role suited to a consultant comfortable operating independently within a regulated financial services environment.
Key Responsibilities:
- Complete and progress supplier security due diligence, risk assessments and periodic reviews, clearly documenting findings, required remediation, and escalation points.
- Support Triage, conduct threat intelligence, and respond to day-to-day Information Security requests from the business, providing clear, risk-based advice and escalating material matters promptly.
- Support the assessment, coordination, documentation and follow-up of Information Security incidents and enquiries in accordance with established processes.
- Assist with evidence gathering, control validation, audit and regulatory requests, and remediation tracking against relevant obligations and frameworks, including ISO 27001, NIST CSF, NYDFS, FCA, and PRA where applicable.
- Assessments Conduct structured risk and control assessments across third parties, business activities, and projects, ensuring identified risks and actions are accurately recorded and tracked.
Requirements
- Proven experience in an Information Security, Cyber Risk, or IT Risk role within financial services, insurance, or another regulated sector
- Practical experience of third-party / supplier security risk assessment and due diligence processes
- Working knowledge of ISO 27001, NIST CSF, and awareness of NYDFS Cybersecurity Regulation
- Familiarity with UK regulatory expectations relevant to information security, including FCA and PRA requirements
- Experience supporting security incident response, including documentation and post-incident follow-up
- Confident engaging directly with business stakeholders, translating technical risk into clear, actionable advice
- Strong documentation and record-keeping discipline, comfortable maintaining risk registers and audit evidence
- Relevant certification desirable (e.g. CISSP, CISM, ISO 27001 Lead Auditor/Implementer, or equivalent)
- Able to work independently as a deployed consultant within a client's existing Information Security team and governance structure
Benefits
Length: Initial 2 month contract
About the Engagement
This role is a G MASS-managed consultant deployment: the successful candidate will remain a G MASS employee, working on-site or hybrid with our client under a fixed-term or ongoing statement of work. G MASS provides specialist Lloyd's and London Market resourcing and technology advisory, placing experienced consultants into insurance sector engagements across governance, risk, and technology functions.
Sourced from a public career listing. Jobverse is an aggregator, not the employer.