InfoTrack UK
Information Security and Assurance Analyst

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Location: Woking (hybrid after probation)
Salary: Up to £35,000, depending on your skills and experience
Do you have a keen eye for detail and an interest in information security, assurance, and governance?
Are you confident working with both technical and non-technical stakeholders, and enjoy making sure information is accurate, evidence-based, and properly documented?
We're looking for an Information Security and Assurance Analyst to join our IT and Governance team and play an important role in supporting customer security assurance and the continued operation of InfoTrack’s ISO/IEC 27001:2022 Information Security Management System.
This is an excellent opportunity for a methodical and proactive IT or information security professional to coordinate customer assurance activities, maintain ISMS records and evidence, track risks and corrective actions, and support security controls, awareness activities, and audit readiness across a growing technology business.
About InfoTrack
InfoTrack is a market-leading provider of technology solutions for the conveyancing industry, helping law firms deliver a best-in-class service to people buying and selling homes.
As our market share continues to grow, so does the importance of maintaining reliable, secure, and well-governed technology services. Our UK IT and Governance team plays a key role in supporting our security framework, meeting customer assurance requirements, and ensuring we continue to operate to high standards.
This role offers exposure across technical operations, governance, customer assurance, and organizational stakeholders, with opportunities to broaden your existing skills and take on increasingly varied assurance work.
What you’ll be doing
In this role, you will:
- Coordinate and complete customer Due Diligence Questionnaires, security questionnaires, and Site Security Surveys
- Gather, organize, and maintain supporting assurance evidence, ensuring information is accurate and up to date
- Work with internal subject-matter experts to obtain accurate technical, security, and governance information
- Ensure customer assurance responses are consistent with approved policies, controls, and implemented practices
- Maintain approved assurance responses and supporting evidence, and support customer assurance meetings and assessments where required
- Support the operation and maintenance of InfoTrack’s ISO/IEC 27001:2022 Information Security Management System
- Maintain ISMS records, registers, documentation, and control evidence, including the information security risk register and associated risk-treatment actions
- Monitor scheduled ISMS reviews and recurring governance activities, following up with responsible owners to ensure actions are completed within the required timescales
- Coordinate and track periodic user access reviews and scheduled security control and log-review activities
- Maintain evidence demonstrating completion of recurring security controls and identify missed, incomplete, or overdue activities
- Coordinate information security awareness and training activities, monitor participation and completion, and maintain associated records and reporting
- Support internal, external, certification, and surveillance audit activity, including coordinating evidence and information requests
- Maintain records of audit findings, observations, corrective actions, and preventative actions, tracking actions through to completion
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
What we're looking for
Essential:
- Experience within information security, assurance, compliance, or IT controls; or at least two years’ experience in first-line, second-line, service desk, infrastructure support, or a comparable technical IT role
- A working understanding of common IT services, security controls, and operational processes
- Awareness of ISO 27001, information security risk, and evidence-based assurance
- Strong written communication skills and excellent attention to detail
- The ability to understand technical or control-based information, identify logical inconsistencies, and seek appropriate clarification or evidence
- Confidence working with technical and non-technical stakeholders at different organizational levels
- Strong organizational, record-keeping, and follow-up skills
- The ability to manage recurring activities, actions, and deadlines effectively
- Sound judgment when handling confidential or sensitive information
Desirable (but not essential):
- Experience completing customer security questionnaires, DDQs, or assurance assessments
- Exposure to Site Security Surveys or customer security reviews
- Experience supporting ISO 27001 certification or audit activity
- Experience maintaining information security risk registers and risk-treatment actions
- Understanding of corrective action, preventative action, and root-cause analysis
- Experience coordinating user-access reviews or recurring security-control checks
- Experience administering information security awareness programmes
- Knowledge of Cyber Essentials, UK GDPR, or related security requirements
- Broad understanding of end-user computing, identity and access, networks, systems, and common IT operational controls
- Experience within technology, SaaS, legal services, or another regulated environment
- A relevant security qualification, such as ISO 27001 Foundation or Internal Auditor, CISMP, Security+, or equivalent


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Working Hours
- Your working week will be full time, generally 9 am – 5.30 pm, with the role primarily based in our Woking office
- Occasional travel will be required to other UK offices, including Waterloo, Maidstone, Southport, and Leeds
- Following successful completion of the six-month probation period, you’ll have the opportunity to work from home for up to two days per week, subject to operational and departmental requirements
Salary and Progression
- Salary of up to £35,000, aligned with your experience and skills
- You’ll have the opportunity to develop your knowledge across information security, assurance, governance, and customer security requirements
- Guidance and mentoring will be available from the Head of UK IT and Governance to support development in areas where you may have less experience, including ISO 27001, customer assurance, risk management, ISMS maintenance, and audit activity
- The role provides exposure across technical operations, governance, customer assurance, and organizational stakeholders, with opportunities to broaden your existing capability and take on increasingly varied assurance work
Benefits and Rewards
At InfoTrack, we believe in rewarding our people and creating a positive workplace culture.
You’ll benefit from:
- 25 days annual leave, plus bank holidays
- Flexible working options, including hybrid working after probation
- Private health insurance, including dental, optical, and hearing cashback
- Life assurance (worth x4 your base salary)
- 24/7 health advice line and access to virtual GP appointments
- In-house barista: enjoy freshly brewed drinks throughout the day
- Office snacks, including fruit and refreshments
- Regular team breakfasts and lunches
- Recognition awards: £100 spot prizes for going above and beyond
- “Work From Anywhere” weeks: work remotely from a location of your choice
- Referral bonus: earn up to £2,000 for successful referrals
- Birthday and work anniversary gifts
- Regular social events including summer and Christmas parties, hikes, pub quizzes, and more
If you’re looking to develop your career in information security and assurance while gaining exposure to customer security, governance, risk, and ISO 27001 in a growing technology business, we’d love to hear from you.
If you have any questions about the role or require any reasonable adjustments as part of the recruitment process, please let us know at careers@infotrack.co.uk.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location