Security Analyst
Listed on 2026-09-12
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Trans Union's Job Applicant Privacy Notice Team Overview
At Trans Union, a leader in information and risk management services, we are committed to protecting the integrity, confidentiality, and availability of the information entrusted to us. As cyber threats continue to evolve, we are seeking an Information Security Analyst to strengthen our security operations, governance, risk management, compliance, and assurance capabilities. This role will become a key contributor to our Information Security program, supporting both operational security initiatives and regulatory obligations across the organisation.
This is a hybrid position and involves regular performance of job responsibilities virtually as well as in-person at an assigned TU office location for a minimum of two days a week.
And Core Responsibilities
ResponsibilitiesSecurity Operations (SOC) Support incident response activities including identification, analysis, containment, eradication, recovery, and lessons learned. Develop and improve detection use cases, alerting mechanisms, playbooks, runbooks, and operational procedures. Collaborate with internal technology teams and external security service providers during security incidents. Maintain awareness of emerging cyber threats, vulnerabilities, attack techniques, and industry trends.
Vulnerability ManagementAssist in day-to-day vulnerability management activities across servers, endpoints, applications, databases, and network infrastructure. Perform vulnerability assessments and coordinate remediation activities with technology, application, and infrastructure teams. Track vulnerabilities through resolution and provide management reporting on remediation performance and compliance. Assist in maintaining vulnerability management standards and reporting against defined remediation SLAs.
Governance, Risk & Compliance (GRC)Support the continued operation, maintenance, and improvement of the Information Security Management System (ISMS). Assist with ISO 27001 and SOC 2 certification, surveillance audits, recertification audits, and control reviews. Support internal and external audits through evidence collection, compliance validation, and remediation tracking. Assist with enterprise security risk assessments and risk treatment activities. Support compliance with ISO 27001, ISO 27002, CIS Controls, regulatory requirements, and internal policies.
Track audit findings, corrective actions, and compliance initiatives.
Support identity governance initiatives, including:
Privileged Access Management (PAM) Role-Based Access Control (RBAC) Multi-Factor Authentication (MFA) Access reviews and certification processes. Participate in security assessments of new technologies, systems, and services.
Support security awareness programmes, phishing simulations, and employee education initiatives. Promote a strong security culture across the organisation. Assist business stakeholders in understanding security risks and control requirements. Contribute to awareness campaigns, security communications, and policy adoption initiatives.
Reporting & MetricsProduce security dashboards, reports, and key performance indicators (KPIs). Report on:
Security incidents;
Vulnerability management;
Risk management; ISO 27001 compliance;
Audit findings;
Third-party risk;
Security operations effectiveness. Support management reporting and governance forums through meaningful security metrics and analysis. Drive improvements in security reporting through automation and continuous enhancement initiatives.
Minimum Qualifications:
Degree or Diploma in Information Security, Computer Science, Information Technology, Engineering, or related field. Relevant cybersecurity certifications will be advantageous.
Experience 3-5 years' experience in Information Security, Cyber Security, Security Operations, Infrastructure, Cloud Security, or Technology Risk. Experience supporting ISO 27001 and SOC 2 implementation, maintenance, or certification activities. Experience with incident response and security event investigation. Experience with vulnerability management and remediation tracking. Experience conducting security assessments, audits, or compliance activities. Experience working with cloud technologies and security controls. Experience in Identity and Access Management principles.
Experience with Application security principles and OWASP Top 10.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).