Technology and Information Security Policy Analyst
WTW Information & Cyber Security (ICS) requires an Information Security Policy Analyst to work within the ICS GRC function. An experienced information security professional you will be responsible for assisting in the maintenance of the Technology and Information Security Policies and supporting standards.You will be reporting to the ICS and Technology Policy and standards lead. The role location is within the UK.The RoleThis role will support the maintenance of the Technology and IS Policy and Standards and will therefore include activities such as: Support operating of the annual and other additional review cycle process for the WTW Technology and Information Security Policies & StandardsLead the design and updates to related operating proceduresRun the process of identifying and managing changes as well as driving development of new details of the standards whilst working with standards owners and other SMEs Reflect the changes in the overall technology and cyber controls framework Assist in pro-actively managing all the communication as it pertains to the Policy & Standards lifecycleEnsure the clarity and accuracy of the information in the Tech. and Information security Policies and standardsLiaise with subject matter experts and stakeholders of the standards domain.Document and track all changes request ensuring quality details are capture for all decisionsWork with Exception to Policy and Risk management teams to ensure transparency of planned changesWork with Regulatory team to understand all regulatory driven change requirementsEnsure accurate and clear communication with all stakeholders.Provide appropriate MI to all stakeholder levels The RequirementsSkills: Knowledge and understanding of Information Security Frameworks and standards (FFIEC, NIST, ISO etc)Knowledge and understanding of Regulatory Risk and Compliance policies and programsKnowledge and understanding of policy and standards governance and oversight processesAbility to work as part of a team as well as an individual contributorExcellent Communication skills, especially written EnglishStrong Stakeholder managementThe ability to foster and grow relationshipsExperience of working in a live operational environment with an understanding of the impact of policy adherence is desirable. Qualifications: Educated to degree level or equivalent Hold professional qualifications in a related subject for example, CRISC, CISSP, CISM, CISAExperience in an information security role Experience of working within a Global Financial organisation Behaviours: Resourcefulness and organizational agilityGlobal team player with good interpersonal and influencing skillsConflict Management Resolution (Options Analysis)Customer Focus & Integrity and TrustPersonal Learning & development Equal Opportunity Employer At WTW, we believe difference makes us stronger. We want our workforce to reflect the different and varied markets we operate in and to build a culture of inclusivity that makes colleagues feel welcome, valued and empowered to bring their whole selves to work every day. We are an equal opportunity employer committed to fostering an inclusive work environment throughout our organisation. We embrace all types of diversity.At WTW, we trust you to know your work and the people, tools and environment you need to be successful. The majority of our colleagues work in a ”hybrid” style, with a mix of remote, in-person and in-office interactions dependent on the needs of the team, role and clients. Our flexibility is rooted in trust and “hybrid” is not a one-size-fits-all solution.
read more