Back to all jobs

Information Security Analyst

G MASS

LondonHybridContract5-10 years
Posted 4 hours ago

G MASS is seeking to deploy one of our own Information Security Analysts into a specialist Lloyd's / London Market insurance engagement, on a fixed-term contract (FTC) running to the end of November 2026. The consultant will be embedded within the client's Information Security function, providing hands-on support across third-party risk management, day-to-day security operations, incident support, and compliance and assurance activity. This is a client-facing, delivery-focused role suited to a consultant comfortable operating independently within a regulated financial services environment.

Key Responsibilities:

  • Complete and progress supplier security due diligence, risk assessments and periodic reviews, clearly documenting findings, required remediation, and escalation points.
  • Support Triage, conduct threat intelligence, and respond to day-to-day Information Security requests from the business, providing clear, risk-based advice and escalating material matters promptly.
  • Support the assessment, coordination, documentation and follow-up of Information Security incidents and enquiries in accordance with established processes.
  • Assist with evidence gathering, control validation, audit and regulatory requests, and remediation tracking against relevant obligations and frameworks, including ISO 27001, NIST CSF, NYDFS, FCA, and PRA where applicable.
  • Assessments Conduct structured risk and control assessments across third parties, business activities, and projects, ensuring identified risks and actions are accurately recorded and tracked.
  • Proven experience in an Information Security, Cyber Risk, or IT Risk role within financial services, insurance, or another regulated sector
  • Practical experience of third-party / supplier security risk assessment and due diligence processes
  • Working knowledge of ISO 27001, NIST CSF, and awareness of NYDFS Cybersecurity Regulation
  • Familiarity with UK regulatory expectations relevant to information security, including FCA and PRA requirements
  • Experience supporting security incident response, including documentation and post-incident follow-up
  • Confident engaging directly with business stakeholders, translating technical risk into clear, actionable advice
  • Strong documentation and record-keeping discipline, comfortable maintaining risk registers and audit evidence
  • Relevant certification desirable (e.g. CISSP, CISM, ISO 27001 Lead Auditor/Implementer, or equivalent)
  • Able to work independently as a deployed consultant within a client's existing Information Security team and governance structure

Length: Initial 2 month contract

About the Engagement

This role is a G MASS-managed consultant deployment: the successful candidate will remain a G MASS employee, working on-site or hybrid with our client under a fixed-term or ongoing statement of work. G MASS provides specialist Lloyd's and London Market resourcing and technology advisory, placing experienced consultants into insurance sector engagements across governance, risk, and technology functions.