Senior IT Assurance Analyst
Department: IT
Employment Type: Permanent - Full Time
Location: London UK
Reporting To: Thom Turner
Description
The Senior IT Assurance Analyst plays a key role in strengthening Asta's cyber resilience by identifying and assessing risks across internal and client IT environments.
The role evaluates and enhances security controls, supports regulatory and standards-based compliance (including ISO 27001, NIST, SOC2 and Lloyd's requirements), and provides expert cyber consultancy on emerging technology risks.
The position supports and conducts IT audits, manages supplier assurance, and ensures timely remediation of findings.
Operating as part of the Second Line of Defence, the analyst provides independent oversight and challenge to IT risk management, contributing to Asta's Cyber Assurance Framework and overall security strategy.
Key Responsibilities
Risk Identification and Assessment: Identify and assess risks in Asta and client IT systems and supply chain, including security gaps, weak controls, and operational risks. This involves conducting thorough risk assessments through IT attestations and developing strategies to mitigate identified risks
Control Evaluation: Oversee cyber security governance controls in line with Asta's Cyber Assurance Framework by conducting audits, control testing, and evidence reviews, recommending improvements to ensure Asta and client's policies and standards are effectively implemented.
Regulatory Compliance: Assist with compliance activities such as policy and process assessments and improvements, Lloyd's Principle 12, ISO27001, NIST and SOC2 re-certifications and audits. This involves staying up to date with regulatory changes and implementing necessary adjustments to maintain compliance
Cyber Consultancy: Offer cyber consultancy services to support client initiatives, ensuring compliance and risk appetite requirements are met. Conduct thematic reviews and deep-dive assessments on emerging technology risks (e.g., cyber resilience, AI, cloud security, identity and access management).
Audit Support: Support or conduct IT audits, testing, and reporting on controls. Track and validate remediation of IT risk issues and audit findings, ensuring timely and effective closure.
Supplier Assurance: Manage supplier assurance processes to ensure third-party vendors comply with security and regulatory requirements. This includes conducting vendor assessments, monitoring vendor performance, and addressing any compliance issues
Second Line of Defence: Provide independent oversight and challenge of IT risk management and control practices across the organisation. Challenge risk assessments, control self-assessments, and key risk indicators (KRIs) produced by the 1st line. Contribute to incident management processes. Collaborate with Risk and internal audit teams by acting as a subject matter expert on IT risk and control frameworks.
Skills, Knowledge & Expertise
MNCJobs.co.uk will not be responsible for any payment made to a third-party. All Terms of Use are applicable.