Data and MI Specialist



This job posting expired and applications are no longer accepted.
Admiral
Published
20.04.2023
Location
Cardiff, United Kingdom
Job Type
Hybrid Working Opportunity
TELECOMMUTE

ABOUT THE JOB

Data Assurance is function of Data Enablement Services Department and includes Data Governance, Data Management, Data Minimisation, Data Confidentiality Assurance (Data Loss Prevention), Data Quality Management, Records Management and Information Risk as core components and service areas.

The Data Confidentiality Assurance Analyst (‘DCA Analyst’) supports the Data Assurance function in implementing the Admiral 2.0 Diversification Agenda, with respect to all matters relating to Data Confidentiality, Models and Principles. Ensuring across all EUI, compliance with Security Standards (NIST, CIS, ISO 27001), PCI DSS, DPA 2018, EU GPDR and other appropriate industry standards, and to support the overall organisational strategy. The DCA Analyst will work with the Information Security & IT departments with respect to control capability to ensure business requirements for all related risks are within tolerance.

Key duties and responsibilities:

Reporting to the DCA Manager, the DCA Analyst responsibilities will include:

  • Preparing documentation
    • Business Stakeholder, ownership and requirements for Data Confidentiality mitigating controls.
    • Control Capability configuration (Detection, Exception, Target Groups, Control Responses)
  • Ensure proper Governance is applied to all aspects of Data Confidentiality Assurance controls, including sign-off from all stakeholders.
  • To proactively work with the Security Operations Centre and outsource providers with respect to meeting business requirements for Service/incident Response and consequence management.
  • Liaise with Information Security & Technology Risk and Assurance teams to gather information relating to
    • Current Residual Risk Position
    • Security landscape with respect to Threat Actors & Data Confidentiality
    • What vulnerabilities (technology, people, process) are likely to utilised by threat actors, and the possible outcomes
  • Work with data risk owners to
    • Perform Data Confidentiality control assessments to identify control weaknesses, and assess the effectiveness of existing controls, and recommend remedial action.
    • Define requirement and testing criteria, both functional and non-functional, for Data Confidentiality controls
    • Develop, test (UAT) and promote to production Data Confidentiality control capability.
  • To report concerns about residual risk, vulnerabilities, and other risk exposures, including misuse of information assets and non-compliance.
  • Work with peers within the organisation to ensure all Data Confidentiality controls are implemented through project phases during application development or acquisitions.
  • To identify where Data Confidentiality controls are required, and ensure the technical implementation meets business requirements.
  • To ensure the security processes and procedures, and support service-level agreements (SLAs) meet the requirements of the business.
  • To research, evaluate, and recommend information security-related services, solutions and technologies that will align with future business objectives.
  • Review risk assessments and analyse the result of audits (performed by other groups) to produce recommendations of acceptable risk and risk mitigation strategies.
  • To provide support, analysis and assistance with the resolution of security incidents, as and when necessary.
  • To participate in security investigations and compliance reviews when requested.
  • To assist in the development of security architecture and security policies, principles, and standards.

Accountabilities:

Primary customers and stakeholders Internal:

  • Other internal IT functions
  • All non-IT business units
  • Corporate Governance and Performance Team
  • Outsources providers.

External:

  • Core IT Partner (CITP)
  • Crisis management teams for HEPs
  • Awarding bodies
  • External auditors, Customer Experience and Marketing, EUI Media, and Technology and Operations

Person specification:

  • Have a relevant foundational qualification such HND, BSc or equivalent professional certification.
  • Experience liaising with Business & IT peers delivering Data Confidentiality controls is mandatory.
  • CIS, NIST, COBIT, ISO 27001, PCI DSS knowledge & experience highly desired.

Knowledge of Data Loss Prevention controls will be very desirable.

Our Commitment to You

At Admiral, we are committed to being a diverse and inclusive workplace. Admiral is proud to be an equal opportunities employer and does not discriminate on the basis of race, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), national origin, gender, gender identity, sexual orientation, disability, age, or any other legally protected status.

All qualified applicants will receive equal consideration for employment.

Benefits and Work-Life Balance

At Admiral, we are proud to be a diverse business where we put our people and customers first. We have great benefits to ensure employees have a great work-life balance; it's one of the reasons we’re consistently voted one of the Sunday Times Best Big Companies to Work For in the UK.

All colleagues will receive 33 days holiday (including banks holidays) when they join us, and this will increase with length of service, up to a maximum of 38 days (including banks holidays). You also have the option to buy or sell up to five days of annual leave in addition to your allocation.

You can also view some of our other key benefits here.

We are proud supporters of Women in Data®.  Connect, engage and belong to the largest free female data community in the UK – visit: www.womenindata.co.uk to join our community.

<< Back to Search

Related Jobs

Meteorologist   London, United Kingdom new
10.01.2025
Marketing Effectiveness Client Services Director   London, United Kingdom new
09.01.2025
Scope 3 Data Manager, Supplier Sustainability   London, United Kingdom new
09.01.2025
Senior Data Scientist, Moderation   Billund, Denmark new
09.01.2025
09.01.2025
was shared 0 times
00