Rodeo
Get started

Oyster IMS - Information Management Solutions

Information Security Analyst

London
Posted about 16 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

At Oyster IMS we pride ourselves on our ability to create, develop and nurture a world-class business that we can all be proud of and which is enjoyable, worthwhile and fruitful for our staff, our customers, our partners and our community.

Our commitment is to exceed client expectations by understanding their unique needs, providing proactive solutions, and fostering open communication.

We are genuinely interested and invested in our client success and will excel in providing transformational services to give them peace of mind.

We strive to establish long-term partnerships, ensuring client satisfaction through continuous improvement, innovation, and dedicated focus on delivering exceptional value at every transaction.

For our people we provide a pleasant and supportive environment, where positive things happen, we are rewarded in line with our expectations, and we all have a voice.

Fundamentally we are all able to do meaningful work that provides us with autonomy, complexity and a direct connection between effort and reward.

All members of Oyster IMS live and breath our values of Excellence, Fairness, Trust and Transparency, Smart and Enjoyment.

The Opportunity

We are looking for an Information Security Analyst to join our Information Security team.

Working closely with our Head of Information Security, consultants, and clients, this is a varied role combining information security and GRC consultancy with hands-on configuration and implementation of the OneTrust platform.

You will work across a range of client engagements, helping organisations understand and manage their information security risks, implement effective controls and get real value from their GRC technology.

A particular focus will be on IT Risk Management, Third Party Risk Management and ISO 27001, alongside opportunities to work more broadly across information security, data protection and information governance.

This isn't a role where you'll simply produce reports and recommendations. We are looking for someone who can understand a client's problem, work out what needs to happen and help make it happen.

Key Responsibilities

Information Security and GRC Consulting

  • Support the delivery of client information security, GRC, IT Risk Management and Third Party Risk Management engagements.
  • Support clients with the implementation and ongoing operation of ISO 27001 Information Security Management Systems.
  • Understand client issues and requirements and translate them into practical, proportionate solutions.
  • Help clients develop, implement and maintain appropriate information security policies, controls and procedures.
  • Provide clear, practical information security, risk and GRC advice to both technical and non-technical stakeholders.
  • Deliver training, presentations and education on information security topics.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

OneTrust

  • Configure and implement OneTrust GRC solutions to meet client requirements.
  • Build and configure assessments, attributes, workflows and related platform functionality.
  • Support the delivery of IT Risk Management and Third Party Risk Management solutions through OneTrust.
  • Work with clients to translate their processes and requirements into effective OneTrust configurations.
  • Maintain relevant OneTrust learning and certifications and keep your platform knowledge current.

Risk, Assurance and Compliance

  • Support clients in identifying, assessing, documenting and treating information security and cyber risks.
  • Undertake supplier security reviews and third-party risk assessments as part of client managed services.
  • Evaluate supplier security posture and support decisions around remediation, risk acceptance or supplier rejection.
  • Carry out and document ISMS reviews, audits and spot checks to determine whether controls are operating effectively.
  • Help clients understand and respond to relevant information security regulatory and compliance requirements, including DORA where applicable.
  • Maintain appropriate records and evidence to demonstrate compliance with relevant standards, regulatory requirements and good practice.

Client and Stakeholder Relationships

  • Build effective relationships with client stakeholders, internal teams and third-party suppliers.
  • Explain complex security, risk and regulatory requirements clearly to technical and non-technical audiences.
  • Work confidently with senior stakeholders and constructively challenge assumptions or decisions where needed.
  • Manage multiple projects and pieces of work simultaneously while maintaining quality and meeting priorities.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Supporting Information Security at Oyster IMS

Alongside client work, you will also help us maintain and continuously improve our own information security environment. This will include:

  • Maintaining Oyster IMS Policy Management processes through OneTrust, including policy publication and attestation.
  • Supporting administration of our Phished platform, including phishing simulations and security awareness activities.
  • Helping test and improve our internal information security processes and controls.
  • Keeping your technical knowledge, OneTrust learning and relevant certifications current.

Who we're looking for

Essential

  • Around three to five years' relevant experience in information security, GRC, IT risk, third-party risk management, data protection or a related discipline.
  • Practical, hands-on experience using OneTrust GRC, ideally including the creation or configuration of assessments, attributes and workflows.
  • Practical experience supporting information security risk assessments, supplier assurance or third-party risk management activities.
  • Experience supporting ISO 27001 ISMS implementation, operation or compliance activities.
  • Experience applying information security policies, controls and risk management practices within an organisation.
  • Recent and relevant OneTrust certification(s), or equivalent evidence of current OneTrust capability.
  • Able to explain complex security, risk and regulatory requirements clearly and practically.
  • Confident working with senior stakeholders and able to influence decisions appropriately.
  • Strong problem-solving skills with the judgement to propose proportionate, workable solutions.
  • Collaborative and able to work effectively with individuals and teams on both planned and ad-hoc activities.
  • Resilient and comfortable challenging assumptions or decisions constructively when required.
  • Well organised, able to manage competing priorities and committed to delivering high-quality work.

Desirable

  • Experience configuring OneTrust Third Party Risk Management, IT Risk Management, Compliance Automation and/or Enterprise Policy Management modules.
  • Practical experience applying DORA or comparable regulatory requirements within a client or organisational environment.
Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Information Security
GRC Consulting
OneTrust
ISO 27001
IT Risk Management
Third Party Risk Management
Data Protection
Information Governance
Risk Assessment
Compliance Auditing
Stakeholder Management
Policy Management
DORA
Security Awareness
Supplier Security Reviews
ISMS

Location

London, England, United Kingdom

Sign up to applySee more jobs like this