Security Governance & Assurance Analyst - Flutter UKI, Hybrid
Listed on 2026-06-21
-
IT/Tech
Cybersecurity, Information Security, IT Consultant
Location: Greater London
This position is open across multiple Flutter UK & Ireland office locations. The benefits and package will be in line with the entity in your location. Your Talent Partner will discuss this in further detail.
An exciting opportunity has opened up for a Security Governance and Assurance Analyst to join the team, initially as a 6‑Month Fixed‑Term Contract covering maternity leave.
RoleReporting into the Senior Governance & Assurance Manager – UKI, the Security Governance and Assurance Analyst will be responsible for the day to day delivery of the tech workstream for Flutter UKI’s audits and assessments. This may include ISO 27001, Sarbanes‑Oxley (SOX), NIST, PCI DSS in addition to other 2nd and 3rd line internal assessments. This position will work with stakeholders to ensure the regulatory demands upon the Tech teams are delivered, working closely with key internal and external stakeholders including auditors to ensure compliance.
The Security Governance and Assurance Analyst will independently manage the assessments, working with 2nd and 3rd‑line teams to ensure requests are sent out in a timely manner, evidence is received and meets the standard required for evidential assurance. They will facilitate conversations between 2nd and 3rd line stakeholders and Flutter UKI Tech teams and oversee the delivery of any remedial action.
The role will work closely with the ISMS & Policy Manager on the coordination of Compliance programmes and define and ope rationalise 1st line security controls and reporting within UKI. In addition, the role will help to drive the creation, review and adoption of Info Sec policies and standards.
The role requires a significant level of engagement across the UKI Infosec team and other stakeholders in the division & Group, some of which are in multiple global locations. Therefore, there is an expectation of travel with this role, as required.
What You'll Do- Responsible for day‑to‑day delivery of some of Flutter UKI's external compliance programmes, which may include ISO 27001, PCI DSS and SOX.
- Responsible for facilitation of some of our other second and third line audits e.g. NIST CSF 2.0, Internal Audit, UKI Risk & Assurance assessments.
- Assisting the ISMS & Policy Manager as required with the ISO 27001 audits and the creation, annual review cycle, withdrawal of policies and standards.
- Understands the UKI Tech & Infosec principles and supports the team in delivering on these.
- Solid understanding of regulatory compliance frameworks such as Sarbanes‑Oxley, PCI DSS, ISO 27001, NIST CSF 2.0, GDPR.
- Experienced in successfully delivering and facilitating multiple projects / pieces of work simultaneously, re‑prioritising as appropriate to meet deadlines with a pragmatic approach.
- Well versed in risk management and has a sound understanding of how controls are implemented in line with business risk appetite & regulatory need.
- Can demonstrate the communication of complex technical matters to both tech/non‑tech audiences, both internally and externally (auditors).
- Can easily navigate internal/external audit & compliance engagements, along with supporting controls testing & evidencing requirements.
- Ability to identify key issues & can communicate them to stakeholders leveraging colleagues as needed to find solutions.
- Understand the people & cultural aspects to information security.
- Assertive, results orientated and good attention to detail.
- Hungry for Results:
Achieves results at pace with energy and drive; consistently achieves and exceeds expectations; takes accountability and always delivers on what has been promised; action orientated, agile in approach, calls out when things go wrong; sets stretch goals and holds self and others to high standards of performance; demonstrates rigour and commitment to activities; always acts with integrity and invests in building trust with all stakeholders. - Wins Together:
Is a team player – by working collaboratively is able to establish and engage networks to achieve shared objectives; acting as a key support whenever possible; effectively communicates and shares information to ensure others are fully informed; praises…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: