Information Security Analyst - Audit, Compliance & Cybersecurity

NICE Logo

NICE

πŸ“Remote - United Kingdom

Summary

Join NICE, a global leader in innovative software solutions, as an Information Security Analyst. This role ensures compliance with key information security frameworks, including ISO 27001, GDPR, and DORA. You will conduct internal audits, prepare for external audits, and contribute to the Cybersecurity Operations Center (CSOC). Responsibilities include identifying control deficiencies, recommending remediation actions, and drafting audit reports. The ideal candidate possesses strong expertise in audit and compliance frameworks and experience in internal and external audits. NICE offers a flexible hybrid work model (NICE-FLEX) and a collaborative work environment.

Requirements

  • Strong expertise in audit and compliance frameworks, including ISO 27001, ISO 27701, ISO 42001, GDPR, DORA, Cyber Essentials, and Cyber Essentials Plus
  • Familiarity with CSOC tools such as Rapid7 InsightIDR or other SIEM solutions
  • Hands-on experience in internal and external audits, compliance assessments, and process improvement
  • Basic understanding of incident response frameworks and cybersecurity best practices
  • Exceptional analytical, organizational, and communication skills
  • Commitment to continuous learning and professional development in audit, compliance, and security

Responsibilities

  • Conduct internal audits to evaluate and enhance IT controls, compliance with standards, and risk management processes
  • Assist internal control owners in scoping appropriate evidence and preparing for external audits
  • Facilitate and/or conduct internal gap assessments and audit readiness evaluations for frameworks such as ISO 27001, GDPR, and DORA
  • Monitor updates to Cyber Essentials, ISO, and regulatory frameworks and ensure internal alignment
  • Develop and maintain control narratives, walkthroughs, and documentation of compliance processes
  • Identify control deficiencies and work with stakeholders to recommend cost-effective, value-added remediation actions
  • Draft audit reports and present findings to management during status updates and closing meetings
  • Collaborate with external audit teams to streamline processes and provide requested documentation and evidence
  • Use tools such as Rapid7 InsightIDR or other SIEM solutions to assist with security monitoring and incident detection
  • Participate in incident response efforts, documenting security incidents and assisting in containment and recovery actions
  • Contribute to analyzing cybersecurity threats and implementing recommendations to improve the security posture
  • Assist in creating and refining cybersecurity policies and operational procedures to align with audit and compliance objectives
  • Support the tracking and remediation of vulnerabilities in coordination with IT and Security Operations teams

Preferred Qualifications

  • A Master’s degree in Cybersecurity, Risk Management, or related fields is a plus
  • Certified Information Systems Auditor (CISA)
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Security Professional (CISSP)
  • ISO 27001 Lead Auditor or Implementer
  • Cyber Essentials Assessor (or equivalent)
  • GIAC certifications (e.g., GIAC Certified Incident Handler - GCIH or GIAC Security Essentials - GSEC)

Benefits

  • Enjoy NICE-FLEX!
  • At NICE, we work according to the NICE-FLEX hybrid model, which enables maximum flexibility: 2 days working from the office and 3 days of remote work, each week

Share this job:

Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.

Similar Remote Jobs