Rodeo
Get started

Lancashire Insurance Group

Principal Cyber Security Analyst

London
Posted about 19 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Application Deadline: 11 September 2026

Department: IT

Location: London


Description

Purpose

Information security is critical to maintaining Lancashire’s operational resilience, regulatory compliance, and protection of Group assets.

Reporting to the Head of Cyber Security & Risk, the Principal Information Security Analyst is responsible for the day-to-day delivery and continuous improvement of the information security function, with a primary focus on technical assurance, control validation, and cyber risk management.

The role acts as the primary technical subject matter expert within a flat team structure, leading complex assurance activities, providing technical challenge across business and technology initiatives, and supporting high-quality risk and assurance outcomes. The role works collaboratively with the Senior Information Security Analyst to embed technical assurance into day-to-day delivery activities and strengthen overall security capability across the team.

The role supports the Head of Cyber Security & Risk, working collaboratively with other Information Security team members to provide technical expertise and challenge across risk and assurance activities, while supporting the development of Information Security Analysts through knowledge sharing and involvement in complex assurance work.


Specific Responsibilities

  • Lead and contribute to the delivery and continuous improvement of the Information Security Management System (ISMS), ensuring alignment with regulatory requirements and recognised frameworks (e.g. NIST CSF, NYDFS, ISO 27001).
  • Translate strategic direction into operational assurance activities, ensuring effective tracking, governance, and reporting of security activities, control performance, and key risk indicators.
  • Own the day-to-day management of cyber risk, including maintenance of the risk register and oversight of remediation activities.
  • Undertake and drive cyber risk and control assessments across business operations, change initiatives, and third parties.
  • Deliver technical assurance activities, including control testing, validation, and evidence gathering, ensuring outputs are robust, consistent, and defensible.
  • Manage and coordinate responses to internal and external audit findings, ensuring timely and effective remediation.
  • Support regulatory reporting and maintain appropriate documentation and evidence to demonstrate compliance.
  • Act as the primary technical subject matter expert, providing guidance and challenge across IT infrastructure, applications, cloud, and third-party environments.
  • Provide technical validation and challenge through governance forums (e.g. CAB), ensuring security implications of changes are understood and addressed.
  • Assess and challenge new systems, services, and application onboarding to ensure compliance with security standards and control requirements.
  • Develop and apply threat modelling and technical assurance approaches to support secure design and risk identification.
  • Provide challenge and input into third-party security assurance activities where required, ensuring third-party risks are appropriately assessed and managed.
  • Support response and investigation of cybersecurity incidents through technical analysis and control validation, contributing to effective response and continuous improvement.
  • Work with the SOC provider to support the effectiveness of monitoring, detection, and response controls.
  • Provide technical guidance and knowledge sharing to support team capability and development.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.


Essential Skills & Requirements

  • Solid experience in an Information Security role, with experience operating at a senior or specialist level.
  • Strong hands-on experience in cyber risk management, control assessment, and assurance delivery.
  • Demonstrable experience in technical security assurance across infrastructure, applications, and cloud environments.
  • Strong working knowledge of recognised frameworks such as NIST CSF and ISO 27001.
  • Experience supporting regulatory compliance obligations (e.g. FCA, PRA, NYDFS, or equivalent).
  • Experience supporting audit activities and remediation tracking.
  • Experience in third-party risk and supplier assurance processes.
  • Ability to interpret and apply technical security controls in practical environments.
  • Experience supporting or mentoring team members in technical and assurance activities.
  • Strong analytical, organisational, and stakeholder communication skills.
  • Strong organisational and coordination skills.
  • Strong analytical and problem-solving capability.
  • Ability to provide effective technical challenge and oversight.
  • Collaborative working style and team-oriented mindset.
  • Ability to translate strategy into operational delivery and assurance.
  • Proactive, delivery-focused, and continuous improvement mindset.
  • Ability to support, guide, and mentor team members.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

The Lancashire Way

At Lancashire, we believe our culture sets us apart. The way we behave and approach our work day-to-day is what makes us unique and creates a positive experience for our people, business partners, and other stakeholders. Honesty and integrity in all we do is a given, and The Lancashire Way reflects our true character and spirit.

Straight-talking

We feel empowered to share thoughts and ideas, because everyone’s voice matters.

Collaborative

We work together towards common goals, share knowledge, and support each other.

Hard-working

We all have a stake in the company’s success and are proactive in contributing to our goals and vision.

Responsible

We focus on achieving tangible results with consistent standards across the Group.

Positive

We engage with brokers, clients, communities, stakeholders, and colleagues professionally and passionately as proud ambassadors of Lancashire.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Cyber Risk Management
Technical Security Assurance
Control Validation
NIST CSF
ISO 27001
Regulatory Compliance
Threat Modelling
Third-Party Risk Management
Incident Response
Audit Remediation
Cloud Security
Stakeholder Communication
ISMS Management
Technical Challenge
Mentoring
Analytical Problem Solving

Location

London, England, United Kingdom

Sign up to applySee more jobs like this