- Company Name
- Hays
- Job Title
- Information Security Compliance Analyst
- Job Description
-
**Job Title:** Information Security Compliance Analyst
**Role Summary:**
Responsible for ensuring all corporate and subsidiary operations adhere to internal security policies, regulatory mandates, and recognized standards (ISO27001, NIST, SOX, GDPR, CMMC, etc.). Supports the development, execution, and continuous improvement of the global information security compliance program.
**Expections:**
- Minimum 3 years of direct experience in information security compliance, risk management, or audit.
- Proven track record with ISO27001, GDPR, NIST, SOX, SOC 2, HIPAA, CCPA, LGPD, or similar frameworks.
- Ability to work across multiple jurisdictions and collaborate with cross‑functional teams.
**Key Responsibilities:**
- Execute and enhance the global information security compliance program.
- Conduct internal audits, third‑party risk assessments, and due diligence reviews.
- Align policies and controls with ISO27001, NIST, SOX, GDPR, SOC 2, HIPAA, CCPA, LGPD and emerging regulations.
- Identify gaps in security controls and recommend corrective actions.
- Maintain, update, and document security policies, procedures, and evidence.
- Monitor regulatory changes worldwide and assess impact on operations.
- Engage stakeholders to promote compliance and provide status reporting.
**Required Skills:**
- In‑depth knowledge of international regulatory frameworks and security standards.
- Hands‑on experience with ISO27001 audits, GDPR compliance, NIST Cybersecurity Framework, SOX, SOC 2, HIPAA, CCPA, LGPD.
- Strong analytical, problem‑solving, and risk‑assessment capabilities.
- Excellent communication, stakeholder engagement, and documentation skills.
- Ability to interpret complex regulations and translate them into actionable controls.
**Required Education & Certifications:**
- Bachelor’s degree in Information Technology, Cybersecurity, Business, or related field (or equivalent experience).
- Industry certifications such as CISSP, CISA, CISM, ISO27001 Lead Auditor, or equivalent are highly preferred.
West midlands, United kingdom
Hybrid
Junior
30-10-2025