Download as pdf or txt
Download as pdf or txt
You are on page 1of 3

1 Hills Road

Cambridge CB1 2EU


United Kingdom
Telephone + 44 1223 553311
Fax + 44 1223 460278
www.cambridgeassessment.org.uk

JOB DESCRIPTION

Job Title: Information Security Analyst

Department / Business Unit: Group Security, CSD

Location: Cambridge

Reports to (job title): Head of Information Security Services

JOB PURPOSE
To provide technical security support and consultancy for the Group’s infrastructure and business
operations ensuring compliance to industry security standards including (ISO27001).

PRINCIPAL ACCOUNTABILITIES
 Respond to and resolve 1st and 2nd line information security incidents within time periods
specified in SLAs, including unplanned emergency calls which may require out of office working
hours
 Provide day to day support of Information Security deployed technologies, including Identity
Management, Security Intelligence and Prevention initiatives
 Coordinate security vulnerability assessments
 Provide technical security consultancy to projects, ensuring appropriate controls are in place
 Provide technical assistance with routine security and compliance audits
 Provide input into the development of security processes and procedures
 Recommend, evaluate and implement security technologies to address security vulnerabilities
and to ensure compliance with Cambridge Assessment’s IT security objectives
 Complete and maintain all relevant technical and procedural documentation to improve
efficiency
 To review and approve Change Requests which may have a security impact as part of the
Technical Change Approval Board

Cambridge Assessment is the brand name of the University of Cambridge Local Examinations Syndicate,
a non-teaching, not-for-profit department of the University of Cambridge.
KNOWLEDGE, SKILLS AND EXPERIENCE

Qualifications

 Security qualification - CISSP, CISM or SSCP (desirable)


 ITILv3 qualification(s) encompassing the full lifecycle of the ITIL process (desirable)

Experience

 Experience within a large operational networking and security environment


 Management and support of security related technology platforms
 Handling security operational issues
 Experience with Role Based Access Control
 Management of Active Directory in large operational setting
 Knowledge of industry best practice and standards with respect to information security, e.g. ISO
27001, PCI DSS, COBIT
 Experience of PC environments, LAN/WAN, Routing, VPN, Remote Access and Wireless
technologies (desirable)
 Experience of vulnerability scanning, security monitoring, system log auditing, security and
process auditing and risk analysis (desirable)
 Security Risk Management (desirable)
Behaviours

 Security minded
 Highly self-motivated and directed.
 Customer focused and strong interpersonal skills at all levels of business organisation
 Team-oriented and skilled in working within a collaborative environment
 Excellent communication, influencing and negotiation skills
 Communicates openly, clearly and effectively, using different styles and forms of
communication depending on audience
 Quickly absorbs processes and business needs and integrate/convert them into processes
 Keen attention to detail and a can do attitude

You might also like