Qureos

FIND_THE_RIGHTJOB.

Information Security Assurance Analyst

JOB_REQUIREMENTS

Hires in

Not specified

Employment Type

Not specified

Company Location

Not specified

Salary

Not specified

Why join us?:
We are seeking a talented and customer-focused Information Security Analyst to join our global IT
delivery center at Pune office. This role will be supporting the overall security posture of the
organization by assisting in the development and execution of InfoSec governance, oversight of risks, control environment, and compliance activities. The ideal candidate should have experience in ISO 27001:2022 implementation and sustenance, worked on client Due Diligence.
Responsibilities:


Governance, Oversight, and MI reporting:
  • Assist the Information Security team in the management and maintenance of the InfoSec
accreditations and other frameworks like ISO 27001:2022, liaising with key stakeholders
to ensure compliance with their requirements.
  • Collect and analyze information security data to produce regular reports on security
incidents, trends, and the overall effectiveness of information security controls, including
senior management reporting.
Risk Management and Third-Party assessments:
  • Assist in the development and implementation of risk management strategies, controls,
and mitigation plans to address identified IT/ InfoSec risks.
  • Assist the InfoSec team by working with IT, business teams, and other risk functions to
assess information security risks or threats, identifying opportunities to reduce risk and
facilitate the remediation of identified vulnerabilities.
Audit & Assurance:
  • Assist to perform or coordinate ISMS Internal Audits in line with ISO 27001:2022
requirements.
  • Assist in the coordination of penetration tests, phishing simulations, and other
independent assessments to evaluate information security controls.
Business Engagement:
  • Participate in security awareness activities including the maintenance of Intranet content.
  • Champion information security and risk management concepts and the objectives of the
Information Security function.
Creation and Maintenance of Asset Register, BIA and Risk Register.
  • Create and maintain an asset inventory by coordinating and liaising with the global tech
team to maintain an asset inventory.
  • Create a global asset register to identify critical business systems and performing
business impact analysis based on ISO 27001:2022 standard.
  • Create and maintain an information security risk register to identify threats, vulnerabilities
and their impact and likelihood with annual reviews with relevant stakeholders.
Client Compliance:
  • In liaison with key stakeholders, contribute prompt responses to client and business
requests, including the completion of client questionnaires, bids, and contracts reviews.
What will help you succeed in this role?:

Essential


  • Bachelor’s/ master’s degree or academic qualification inclined towards Information
Technology, Computer Science, or a related field is preferred.
  • Proven experience of successfully working in IT/ Information Security roles, including at least
3 years of work experience in Information Security Assurance profile.
  • A relevant security qualification such as ISO 27001:2022 Lead Auditor.
  • Experience working in structured, analytical, or process-oriented environments.
  • Producing quality documentation including management information, security dashboards,
reports, policies, standards, and guidelines.
  • Strong analytical skills to analyze security requirements and relate them to appropriate
security controls within a business context.


Desirable


  • Proven experience and ability to successfully deliver results in accordance with deadlines.
  • Clear ability to engage with both technical and non-technical audiences at all levels to drive
the IT Security agenda and influence thinking.
  • Familiarity with relevant UK and international security and privacy regulation and legislations.
  • Strong written and verbal communication skills.
  • Demonstrable experience of working collaboratively with colleagues and aspiration to keep
increasing knowledge of security frameworks and industry standards.
  • Experience within a banking, financial, or professional services environment would be
beneficial.

What we offer:

At DWF, we deeply appreciate the significance of offering a comprehensive rewards package that extends beyond a basic salary. Our commitment is to ensure that each member of our team not only feels valued but is also duly rewarded throughout their tenure with us. Upon joining our organisation, you will have the opportunity to select from a diverse array of benefits, allowing you to carefully tailor a package that perfectly aligns with your individual needs and those of your family. In addition to our standard benefits, we offer a wide range of flexible benefits and robust well-being programs.


Our recruitment process upholds the highest standards of fairness and engagement. It includes comprehensive interviews and, at times, a written assessment, an assessment day, or presentation. We aim to create a positive experience for all candidates and offer any adjustments or additional support.

About us:

DWF is a global legal business providing Complex, Managed and Connected Services. We empower people to be themselves within an inclusive and supportive environment, enabling everyone to achieve their full potential in line with their abilities and career aspirations.

© 2025 Qureos. All rights reserved.