×
Register Here to Apply for Jobs or Post Jobs. X

Information Security Analyst

Job in London, Greater London, W1B, England, UK
Listing for: FundApps
Full Time position
Listed on 2026-09-03
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
We are looking for a curious and hands-on Information Security Analyst to help keep Fund Apps secure, resilient and trustworthy as we continue to grow.

This role has a broad scope, as you will work across security operations, access reviews, vulnerability management, supplier assurance, security awareness, audits, incident response, risk management and the day-to-day running of our Information Security Management System.

As an Information Security Analyst, you will help operate and improve the controls that support our ISO 27001 and SOC 2 programmes, while also getting involved in the real security work that happens across a growing SaaS business. You will not be expected to know everything on Day 1, but you will be expected to learn quickly, ask good questions, follow through on details and help make security easier for everyone t you will own Working with Engineering, IT, Legal, Finance and People to make security a helpful, trusted partner in the way Fund Apps builds, buys and operates technology.

Taking full, end-to-end ownership of Fund Apps’ ISO 27001 and SOC 2 controls operation, managing every stage from initial evidence collection and control checks through to remediation tracking and comprehensive audit preparation.

Organising and chairing monthly review meetings.

Partnering with Legal and Revenue to address security questionnaires and RFPs, ensuring our clients and prospects receive accurate, transparent, and timely answers about our security posture.

Directing the end-to-end planning and execution of penetration testing campaigns.

Managing and facilitating annual business continuity planning (BCP) exercises.

Assessing our vendors to ensure we accurately identify, evaluate, and mitigate any security risks brought in by outside partners.

Supporting vulnerability management across our estate, helping teams understand, prioritise and remediate issues rather than just logging them.

Monitoring security alerts, incidents and internal security events, escalating where needed and helping ensure issues are properly investigated, understood and closed out.

Supporting security awareness activities, including onboarding, refresher training, phishing reporting and practical guidance for colleagues.

Helping improve security documentation and processes so that our controls are easy to follow, repeatable and genuinely useful.

Recurring access reviews across key business systems, checking that permissions are correct and following up when something looks off.

Helping maintain Fund Apps’ Information Security Management System, including security objectives, risk registers, management review inputs and follow-up actions.

What You'll Bring To The Team This role has a lot of freedom to solve problems in ways that achieve our outcomes and align with our values. You will be expected to take ownership of your work from Day 1, while being supported by experienced members of the Information Security team. To thrive at Fund Apps, you will need to be comfortable with uncertainty and embrace change as it comes.

We value people who take charge of their destiny and help make things better for everyone around them Background:
You don't need deep experience with any particular security tool. We care far more about how you think and work than what you've used before. What matters is that you're genuinely curious: when something doesn't look right, you dig into it rather than accepting the first explanation. You ask questions until you actually understand a situation, rather than settling for a surface-level answer because it's quicker or easier.

You’re comfortable saying "I don't know, let me find out" and you’re comfortable learning new ways of doing things.

Hands-on and thorough:
You don't settle for the easy or convenient answer. If an access review throws up something odd, or a vulnerability report doesn't quite add up, you'll get into the detail, ask the awkward questions and follow the thread until you genuinely understand what's going on.

Work-with-purpose:
You can articulate the value of your own work in the bigger picture. You understand that a third party review isn't just a task, it’s a way to surface risks and it's…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary