Lancashire Insurance Group
Principal Cyber Security Analyst

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Application Deadline: 11 September 2026
Department: IT
Location: London
Description
Purpose
Information security is critical to maintaining Lancashire’s operational resilience, regulatory compliance, and protection of Group assets.
Reporting to the Head of Cyber Security & Risk, the Principal Information Security Analyst is responsible for the day-to-day delivery and continuous improvement of the information security function, with a primary focus on technical assurance, control validation, and cyber risk management.
The role acts as the primary technical subject matter expert within a flat team structure, leading complex assurance activities, providing technical challenge across business and technology initiatives, and supporting high-quality risk and assurance outcomes. The role works collaboratively with the Senior Information Security Analyst to embed technical assurance into day-to-day delivery activities and strengthen overall security capability across the team.
The role supports the Head of Cyber Security & Risk, working collaboratively with other Information Security team members to provide technical expertise and challenge across risk and assurance activities, while supporting the development of Information Security Analysts through knowledge sharing and involvement in complex assurance work.
Specific Responsibilities
- Lead and contribute to the delivery and continuous improvement of the Information Security Management System (ISMS), ensuring alignment with regulatory requirements and recognised frameworks (e.g. NIST CSF, NYDFS, ISO 27001).
- Translate strategic direction into operational assurance activities, ensuring effective tracking, governance, and reporting of security activities, control performance, and key risk indicators.
- Own the day-to-day management of cyber risk, including maintenance of the risk register and oversight of remediation activities.
- Undertake and drive cyber risk and control assessments across business operations, change initiatives, and third parties.
- Deliver technical assurance activities, including control testing, validation, and evidence gathering, ensuring outputs are robust, consistent, and defensible.
- Manage and coordinate responses to internal and external audit findings, ensuring timely and effective remediation.
- Support regulatory reporting and maintain appropriate documentation and evidence to demonstrate compliance.
- Act as the primary technical subject matter expert, providing guidance and challenge across IT infrastructure, applications, cloud, and third-party environments.
- Provide technical validation and challenge through governance forums (e.g. CAB), ensuring security implications of changes are understood and addressed.
- Assess and challenge new systems, services, and application onboarding to ensure compliance with security standards and control requirements.
- Develop and apply threat modelling and technical assurance approaches to support secure design and risk identification.
- Provide challenge and input into third-party security assurance activities where required, ensuring third-party risks are appropriately assessed and managed.
- Support response and investigation of cybersecurity incidents through technical analysis and control validation, contributing to effective response and continuous improvement.
- Work with the SOC provider to support the effectiveness of monitoring, detection, and response controls.
- Provide technical guidance and knowledge sharing to support team capability and development.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Essential Skills & Requirements
- Solid experience in an Information Security role, with experience operating at a senior or specialist level.
- Strong hands-on experience in cyber risk management, control assessment, and assurance delivery.
- Demonstrable experience in technical security assurance across infrastructure, applications, and cloud environments.
- Strong working knowledge of recognised frameworks such as NIST CSF and ISO 27001.
- Experience supporting regulatory compliance obligations (e.g. FCA, PRA, NYDFS, or equivalent).
- Experience supporting audit activities and remediation tracking.
- Experience in third-party risk and supplier assurance processes.
- Ability to interpret and apply technical security controls in practical environments.
- Experience supporting or mentoring team members in technical and assurance activities.
- Strong analytical, organisational, and stakeholder communication skills.
- Strong organisational and coordination skills.
- Strong analytical and problem-solving capability.
- Ability to provide effective technical challenge and oversight.
- Collaborative working style and team-oriented mindset.
- Ability to translate strategy into operational delivery and assurance.
- Proactive, delivery-focused, and continuous improvement mindset.
- Ability to support, guide, and mentor team members.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
The Lancashire Way
At Lancashire, we believe our culture sets us apart. The way we behave and approach our work day-to-day is what makes us unique and creates a positive experience for our people, business partners, and other stakeholders. Honesty and integrity in all we do is a given, and The Lancashire Way reflects our true character and spirit.
Straight-talking
We feel empowered to share thoughts and ideas, because everyone’s voice matters.
Collaborative
We work together towards common goals, share knowledge, and support each other.
Hard-working
We all have a stake in the company’s success and are proactive in contributing to our goals and vision.
Responsible
We focus on achieving tangible results with consistent standards across the Group.
Positive
We engage with brokers, clients, communities, stakeholders, and colleagues professionally and passionately as proud ambassadors of Lancashire.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location