UL Solutions

Global Cybersecurity Compliance Analyst

UL Solutions United Kingdom

Professional Services · 10,001+ employees

8 h ago
security Mid (2-5 yrs) Full-time United Kingdom
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The analyst will identify, document, and conduct compliance assessments to validate the effectiveness of ISO, NIST, and TISAX requirements across the organization. They will also partner with IT and legal stakeholders to address control deficiencies and manage internal and external audit processes.

What they look for

Cybersecurity Compliance ISO 27000 NIST TISAX Risk Assessment Information Security Audit Management Compliance Reporting Control Deficiency Analysis Information Governance Regulatory Compliance Key Risk Indicators ISMS Management Stakeholder Management Technical Risk Analysis

Requirements

Candidates must hold a Bachelor's or Master's degree in a relevant field and possess at least two years of experience in cybersecurity compliance auditing and risk management. A strong understanding of information security frameworks and the ability to interpret operational risks are essential for this role.

Full description

The Global Cybersecurity Compliance Analyst will be responsible for identifying, analyzing, reporting, and ensuring security processes and controls are designed, managed, and assessed for effectiveness to reduce overall compliance risks across the organization. Specializing specifically in ISO, NIST and TISAX based assessments.

Responsibilities

  • Identify, document, and conduct compliance assessments and validate the effectiveness of applicable ISO, NIST and TISAX requirements across the organization
  • Communicates assessment issues to team owners and custodians of information risk “Business Partners,” or information governance teams and information security teams.
  • Partner with IT teams and other key stakeholders (e.g., Legal), advising both on applicable control requirements and potential solutions to address compliance issues
  • Identify control deficiencies and maintain records of deficiency details including management response documentation and exposure check evidence
  • Stay abreast of and proactively informed on changes and revisions to ISO, NIST and TISAX frameworks
  • Assists with the evaluation of the effectiveness of the information security program by developing, monitoring, gathering, and analyzing information security and compliance metrics for management.
  • Assist with developing and maintaining compliance and risk monitoring mechanisms such as Key Risk Indicators (KRI), reports on status of risk assessment, control effectiveness issues remediation and internal audit findings
  • Train ISMS managers on ISO compliance requirements and how to prepare and conduct ISO audits
  • Coordinate with internal and external auditors and manage audit schedules

Qualifications

  • BS or MA in Business, Computer Science, Information Security, or a related field
  • [2+] years as a Certified Cybersecurity Compliance Auditor
  • [2+] years of work experience in information security, especially in an information cybersecurity risk role
  • [2+] years of experience in managing risk and compliance issues, or similar experience managing applications, projects or systems that require identification, evaluation, and remediation if risk
  • Technical background or demonstrable understanding of a range of operational and IT risks and operations
  • Strong business background; experience gathering and interpreting risks and associated impacts in the context of financial and operational concerns
  • Strong understanding of compliance and risk-related issues through demonstrated experience managing, information security or regulatory compliance programs, and audits
  • [4+] years of experience with regulatory compliance and information security management frameworks (e.g., International Organization for Standardization [IS0] 27000, COBIT, National Institute of Standards and Technology [NIST] 800)

Desired, but not required:

  • Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), and/or Certified Information Systems Auditor (CISA)

What we offer:

Total Rewards: We understand that rewards are an important consideration as you plan the next step in your career. Salary range varies by location and local market conditions and is based on multiple factors, including job-related knowledge/skills, experience, geographical location, and other factors.

Disclaimer: This role is gender-neutral and open to all qualified applicants, regardless of gender identity or expression.

What you’ll experience working for ULS:

UL Solutions has been pioneering change since 1894 and we’re still leading the way. From day one, we’ve blazed a trail protecting the planet and everyone on it. Our teams have influenced billions of products, plus services, software offerings and more. We break things, burn things and blow things up. All in the name of safety science. Join UL Solutions to be at the center of safety. To learn more about us and the work we do, visit https://www.ul.com

#LI-Hybrid

Similar roles