Interact Software
Information Security and Data Protection Analyst

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Interact
Interact provides enterprise-grade intranet software that connects over three million employees to leading global names like Levi's, Domino’s, Teva Pharmaceuticals, and Technicolor.
Our team of customer-focused problem solvers are passionate about helping organizations to communicate better. We do this together by constantly working to improve every service and product we offer. With offices in Manchester, New York, Dubai, Tulsa, and Warsaw, we operate across North America, EMEA, and Australia.
Click on any of our vacancies and you’ll see one thing in common – they all begin with this message. Why? Because at Interact we treat everyone with the same respect and honesty. Whether you’re a developer fresh out of college or a seasoned salesperson, we live the motto that we uphold for our customers: our people are our most valuable assets.
Your Objective
Your objective will be to support and strengthen the organisation's information security and data protection framework by maintaining compliance with recognised security standards and regulatory requirements, including ISO 27001, SOC 2, Cyber Essentials and UK GDPR.
The role is responsible for identifying, assessing and mitigating security and privacy risks, managing certification and audit activities, supporting incident response and remediation, and promoting a culture of security awareness across the business. Working closely with technical and business stakeholders, the Information Security & Data Protection Analyst will balance security and compliance requirements with commercial priorities, driving continuous improvement in governance, risk management and data protection practices while helping to safeguard the organisation's information assets and reputation.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Role Responsibilities
- Creating, reviewing and improving the security policies.
- Implement and maintain Information Security Management System (ISO27001 certification)
- Contribute to activities towards certification/compliance to security standards and regulations (ISO 27001, SOC 2, Cyber Essentials, etc.)
- Experience of undergoing audits
- Support progress on business continuity plans and policy
- Build and maintain relationships with technical and business stakeholders.
- Leading regular risk assessments and internal process audits.
- Working with internal teams and stakeholders to manage risks, suggest solutions, and resolving issues.
- Support and lead with evidence collation for audits.
- Conduct vendor/supplier reviews in line with Internal Policy.
- Experience in completing client security questionnaires for prospects and customers
- Maintain and improve information security awareness within the business.
- Conduct monitoring activities as required with the UK GDPR and other data protection laws, again our data protection policies
- Work with regulator investigations as required in Article 36
- Point of contact to our employees and individuals about data processing activities.
- Supporting the business maintaining the Security tickets through prompt follow-up and resolution, in collaboration with teams and other stakeholders.
- Management of penetration testing remediations.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Skills, Knowledge & Expertise
- 2–3 years minimum in an information security or data protection role
- Hands-on experience with at least two certification cycles (ISO 27001, SOC 2, etc.) from start to finish.
- Demonstrable experience managing or influencing stakeholders at a senior level.
- Involvement in penetration testing activities and remediations.
- Experience handling real security incidents or data breaches.
- Ability to pragmatically balance security risk against business need
- Maintenance and creation of the Risk Register, ROPA & DPIAs
- Strong awareness of the GDPR, either through training from working within a business that processes personal data or independent learning.
- Strong practical understanding of security and compliance frameworks, such as ISO27001, SOC 2 type II and Cyber Essentials Plus.
- Practical working knowledge of Defender, Intune, Entra, Purview, AWS and Azure
Desirable But Not Essential
- Knowledge of GRC tools such as Drata and Safebase.
- Knowledge of Security and Awareness training tools, campaign creation etc.
- SaaS background
- Good understanding of Risk Management and continuous improvement practices.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills