Principal Cyber Security Analyst
London, England, United Kingdom Full-time Posted 1 hour ago
Application Deadline: 11 September 2026
Department: IT
Location: London
Description
Purpose
Information security is critical to maintaining Lancashire’s operational resilience, regulatory compliance and protection of Group assets.
Reporting to the Head of Cyber Security & Risk, the Principal Information Security Analyst is responsible for the day-to-day delivery and continuous improvement of the information security function, with a primary focus on technical assurance, control validation and cyber risk management.
The role acts as the primary technical subject matter expert within a flat team structure, leading complex assurance activities, providing technical challenge across business and technology initiatives, and supporting high-quality risk and assurance outcomes. The role works collaboratively with the Senior Information Security Analyst to embed technical assurance into day-to-day delivery activities and strengthen overall security capability across the team.
The role supports the Head of Cyber Security & Risk, working collaboratively with other Information Security team members to provide technical expertise and challenge across risk and assurance activities, while supporting the development of Information Security Analysts through knowledge sharing and involvement in complex assurance work.
Specific Responsibilities
At Lancashire, we believe our culture sets us apart. The way we behave and approach our work day-to-day is what makes us unique and creates a positive experience for our people, business partners and other stakeholders. Honesty and integrity in all we do is a given and The Lancashire Way reflects our true character and spirit.
Straight-talking
We feel empowered to share thoughts and ideas, because everyone’s voice matters.
Collaborative
We work together towards common goals, share knowledge and support each other.
Hard-working
We all have a stake in the company’s success and are proactive in contributing to our goals and vision.
Responsible
We focus on achieving tangible results with consistent standards across the Group.
Positive
We engage with brokers, clients, communities, stakeholders and colleagues professionally and passionately as proud ambassadors of Lancashire.
Department: IT
Location: London
Description
Purpose
Information security is critical to maintaining Lancashire’s operational resilience, regulatory compliance and protection of Group assets.
Reporting to the Head of Cyber Security & Risk, the Principal Information Security Analyst is responsible for the day-to-day delivery and continuous improvement of the information security function, with a primary focus on technical assurance, control validation and cyber risk management.
The role acts as the primary technical subject matter expert within a flat team structure, leading complex assurance activities, providing technical challenge across business and technology initiatives, and supporting high-quality risk and assurance outcomes. The role works collaboratively with the Senior Information Security Analyst to embed technical assurance into day-to-day delivery activities and strengthen overall security capability across the team.
The role supports the Head of Cyber Security & Risk, working collaboratively with other Information Security team members to provide technical expertise and challenge across risk and assurance activities, while supporting the development of Information Security Analysts through knowledge sharing and involvement in complex assurance work.
Specific Responsibilities
- Lead and contribute to the delivery and continuous improvement of the Information Security Management System (ISMS), ensuring alignment with regulatory requirements and recognised frameworks (e.g. NIST CSF, NYDFS, ISO 27001).
- Translate strategic direction into operational assurance activities, ensuring effective tracking, governance and reporting of security activities, control performance and key risk indicators.
- Own the day-to-day management of cyber risk, including maintenance of the risk register and oversight of remediation activities.
- Undertake and drive cyber risk and control assessments across business operations, change initiatives and third parties.
- Deliver technical assurance activities, including control testing, validation and evidence gathering, ensuring outputs are robust, consistent and defensible.
- Manage and coordinate responses to internal and external audit findings, ensuring timely and effective remediation.
- Support regulatory reporting and maintain appropriate documentation and evidence to demonstrate compliance.
- Act as the primary technical subject matter expert, providing guidance and challenge across IT infrastructure, applications, cloud and third-party environments.
- Provide technical validation and challenge through governance forums (e.g. CAB), ensuring security implications of changes are understood and addressed.
- Assess and challenge new systems, services and application onboarding to ensure compliance with security standards and control requirements.
- Develop and apply threat modelling and technical assurance approaches to support secure design and risk identification.
- Provide challenge and input into third-party security assurance activities where required, ensuring third-party risks are appropriately assessed and managed.
- Support response and investigation of cyber security incidents through technical analysis and control validation, contributing to effective response and continuous improvement.
- Work with the SOC provider to support the effectiveness of monitoring, detection and response controls.
- Provide technical guidance and knowledge sharing to support team capability and development.
- Solid experience in an Information Security role, with experience operating at a senior or specialist level.
- Strong hands-on experience in cyber risk management, control assessment and assurance delivery.
- Demonstrable experience in technical security assurance across infrastructure, applications and cloud environments.
- Strong working knowledge of recognised frameworks such as NIST CSF and ISO 27001.
- Experience supporting regulatory compliance obligations (e.g. FCA, PRA, NYDFS or equivalent).
- Experience supporting audit activities and remediation tracking.
- Experience in third-party risk and supplier assurance processes.
- Ability to interpret and apply technical security controls in practical environments.
- Experience supporting or mentoring team members in technical and assurance activities.
- Strong analytical, organisational and stakeholder communication skills.
- Strong organisational and coordination skills.
- Strong analytical and problem-solving capability.
- Ability to provide effective technical challenge and oversight.
- Collaborative working style and team-oriented mindset.
- Ability to translate strategy into operational delivery and assurance
- Proactive, delivery-focused and continuous improvement mindset.
- Ability to support, guide, and mentor team members.
At Lancashire, we believe our culture sets us apart. The way we behave and approach our work day-to-day is what makes us unique and creates a positive experience for our people, business partners and other stakeholders. Honesty and integrity in all we do is a given and The Lancashire Way reflects our true character and spirit.
Straight-talking
We feel empowered to share thoughts and ideas, because everyone’s voice matters.
Collaborative
We work together towards common goals, share knowledge and support each other.
Hard-working
We all have a stake in the company’s success and are proactive in contributing to our goals and vision.
Responsible
We focus on achieving tangible results with consistent standards across the Group.
Positive
We engage with brokers, clients, communities, stakeholders and colleagues professionally and passionately as proud ambassadors of Lancashire.