About us
Headquartered in London, we operate internationally and at Lloyd’s. With a global team of over 1000 people and 10 international offices, we’re able to advise from Brussels to Bermuda. As an independent (re)insurance broking firm we work with intermediaries, direct insureds and reinsurers. For over 120 years we’ve been industry leaders in a variety of specialist areas.
Working here
A career with us means the freedom to flourish. Whether you’re beginning your journey or ready to make your next move you’ll find a team of talented, inspirational people who care about their work and each other.
What really sets us apart is our people. We’re a diverse range of passionate advocates for doing things differently. We work together as one team, and our aim is always the outcome that will benefit everyone.
What you’ll do
The Information Security Analyst will help protect the confidentiality, integrity and availability of Miller’s systems, data and technology services.
This is a hands-on, varied role for an information-security professional who wants broad exposure across cyber security, technology risk, governance, supplier assurance, security awareness and incident support within a regulated business.
The role will take ownership of day-to-day security activities, maintain accurate security records and reporting, coordinate follow-up actions, and work closely with colleagues across Technology, Risk, Compliance, Legal, HR and Operations. They will be trusted to manage assigned work independently, identify potential issues early and escalate material risks or incidents appropriately.
Role Responsibilities
Security governance, documentation and assurance
- Maintain information-security policies, procedures, standards, guidance and supporting documentation, ensuring these remain current and accessible.
- Support the collection, organisation and maintenance of evidence for internal reviews, external audits, client due-diligence requests and regulatory assurance activity.
- Maintain security risk registers, action trackers, control records, exception logs and incident documentation.
- Produce clear, accurate and timely reports and dashboards covering security risks, outstanding actions, vulnerabilities, supplier assurance and control status.
- Support the ongoing improvement of security processes, templates, documentation and reporting.
Security risk
- Assist with information-security risk assessments for systems, business processes, technology projects, suppliers and change initiatives.
Supplier and third-party assurance
- Support security due diligence for suppliers and third parties, including reviewing completed questionnaires, policies, certifications, audit reports and supporting evidence.
- Track outstanding supplier actions and follow up with internal stakeholders and suppliers where required.
- Help maintain an accurate record of supplier-security assessments, risks, exceptions and remediation plans.
Operational security and vulnerability management
- Monitor security alerts, vulnerabilities, control exceptions and security-related tasks assigned through relevant tools or processes.
- Triage straightforward issues, gather relevant information and escalate potential incidents or higher-risk findings promptly.
- Assist with access-control, endpoint-security, email-security, identity-management or other security-control reviews as required.
Incident support
- Support the investigation, documentation and coordination of information-security incidents.
- Contribute to lessons-learned activity and help ensure improvement actions are followed through.
Security awareness and stakeholder engagement
- Support security-awareness communications, training activity and phishing-simulation exercises.
- Help create clear and engaging security guidance for employees and other stakeholders.
General responsibilities
- Handle confidential and sensitive information with discretion, integrity and care.
- Comply with relevant internal policies, regulatory obligations and professional standards.
- Undertake reasonable ad hoc tasks and projects that support the objectives of the information-security function.
Qualifications, knowledge and experience
Qualifications
- A relevant degree, professional qualification or equivalent practical experience in information security, cyber security, IT, technology risk, compliance, audit or a related discipline.
Knowledge
- Understanding of core information-security principles, including confidentiality, integrity, availability, risk management and data protection.
- Familiarity with common cyber-security threats, including phishing, social engineering, malware, ransomware, credential compromise and cloud-security risks.
- Awareness of security controls and technologies such as multi-factor authentication, endpoint protection, email security, identity and access management, vulnerability scanning and security monitoring.
- Familiarity with recognised information-security frameworks and requirements, such as Cyber Essentials, GDPR, ISO/IEC 27001 and the NIST Cybersecurity Framework.
- Awareness of the relationship between information security, technology risk, operational resilience, business continuity and data protection.
Experience
- Experience gained in an information-security, cyber-security, IT operations, IT risk, compliance, audit, assurance or related technology role.
- Experience supporting risk assessments, control reviews, audit activity, compliance evidence gathering, remediation tracking or operational-security processes.
- Experience maintaining accurate documentation, such as risk registers, action trackers, procedures, reports, ticket records or incident logs.
- Experience working collaboratively with both technical and non-technical stakeholders.
- Strong written and verbal communication skills, with the ability to present information clearly and professionally.
Benefits
On top of a competitive salary we offer a fantastic benefits package including:
- 10% pension contribution from Miller. In addition, Miller will match any employee contributions up to 5%.
- Private Medical Insurance
- Medicare cash plan
- Minimum of 25 days annual leave (with flexibility to buy more)
- Life Assurance
- Income Protection
- Critical Illness cover
- Enhanced Maternity, Paternity Adoption and Shared Parental Leave
At Miller, we are committed to creating an inclusive and supportive environment for all candidates. If you require any adjustments or accommodations to support you during the application process, please don’t hesitate to let us know.