Skip to main content
AfterDuty

This job is no longer available.

See live security jobs in Bristol or register your CV below and we'll match you to the next one.

Security Assurance Analyst

Zellis · Bristol, South West England

Type
Full-time
Posted
10 days ago

Overview

The Security Assurance Analyst supports security risk and assurance activity across Zellis Group, which comprises Zellis, Moorepay, Benifex and Hastee. The role helps protect the Group’s services, data and customers by identifying and assessing security risks, testing the maturity and…

About this role

The Security Assurance Analyst supports security risk and assurance activity across Zellis Group, which comprises Zellis, Moorepay, Benifex and Hastee. The role helps protect the Group’s services, data and customers by identifying and assessing security risks, testing the maturity and effectiveness of controls, and providing assurance that the Group’s security posture is sound and well evidenced.

Reporting to the Security Risk Manager, this is a broad, hands-on role spanning security risk management, control assessments, policy and standards, supplier assurance, threat modelling and security awareness. The analyst works across all of the Group’s brands and business units, contributing to the security risk register, control maturity assessments, and the evidence that underpins certifications and customer assurance.

The role takes a strong “AI first” approach, using approved AI tooling (such as Microsoft Copilot and Claude) to automate evidence gathering, accelerate risk and control reporting, and help move assurance from periodic, point-in-time reviews towards continuous, data-led insight.

Key responsibilities

Security Risk Management

  • Contribute to the development and ongoing maintenance of the Group’s security risk register.
  • Identify, analyse and evaluate strategic and operational security risks.
  • Conduct policy exception reviews and track risk treatment through to closure.

Controls, Policies & Standards

  • Help design, develop and document security controls, policies, standards and guidance.
  • Design and conduct control maturity assessments to test control effectiveness.
  • Support annual policy reviews and keep the control framework current.

Supplier & Third-Party Assurance

  • Conduct security control assessments of suppliers and other third parties.
  • Identify and help manage weaknesses within the supply chain.
  • Track supplier remediation actions and contractual security requirements.

Certification & Customer Assurance

  • Contribute to internal and external audit activity across certification programmes, including ISO 27001:2022, Cyber Essentials Plus and SOC 2.
  • Support customer assurance activity, responding to security questionnaires, due-diligence and audit requests with accurate evidence.
  • Create and maintain knowledge articles and assurance collateral.

Threat Modelling & Incident Support

  • Contribute to threat modelling and data-flow analysis, evaluating changes for threats, vulnerabilities and countermeasures.
  • Analyse and process threat intelligence to inform risk and assurance activity.
  • Support security incident reviews and root-cause analysis.

Security Awareness & Training

  • Support security awareness campaigns, including phishing simulations and policy awareness.
  • Produce engaging awareness material and track completion across the Group.

AI, Automation & Reporting

  • Take a strong “AI first” approach, using approved AI tooling (such as Microsoft Copilot and Claude) to automate evidence gathering and analysis.
  • Contribute to security metrics, and develop and maintain risk and assurance dashboards.
  • Help move assurance from point-in-time reviews towards continuous, data-led insight.

Skills & experience

  • Good working knowledge of information security practices and standards, including ISO 27001:2022, Cyber Essentials Plus and NIST principles.
  • Practical experience of, or a solid working knowledge of, security risk management, control assessments or security assurance.
  • Understanding of supplier and third-party (supply chain) security assessment.
  • Experience contributing to certifications and responding to customer security requests.
  • Familiarity with risk assessment methodologies and security metrics reporting.
  • Experience using AI tools such as Microsoft Copilot and Claude.
  • Excellent analytical, organisational and written communication skills.

Essential Functional / Technical Skills

  • A recognised qualification in a relevant discipline, or equivalent training, together with around 1–2 years’ experience in a security, risk, assurance or related IT role.
  • Working knowledge of current and emerging security practices and standards (e.g. ISO 27001:2022, Cyber Essentials Plus, NIST).
  • General understanding of network, infrastructure and cloud security concepts.
  • Confident user of AI productivity tools (e.g. Microsoft Copilot, Claude) to accelerate analysis, drafting and evidence handling.
  • Experience of business tooling such as Microsoft Teams, ServiceNow, Azure DevOps and Jira would be advantageous.

Desirable Qualifications & Certifications

  • A relevant certification such as CompTIA Security+, CISMP or ISO 27001 Foundation / Internal Auditor (held or working towards); progress towards ISO 27001 Lead Auditor / Lead Implementer would be an advantage.
  • Experience in a regulated, data-rich or SaaS environment – ideally payroll, HR, financial services or similar.
  • Familiarity with operational resilience and continuity expectations (e.g. DORA, NIS2) is an advantage.

Personal Attributes / Competencies

  • Detail-oriented and disciplined in maintaining documentation and evidence.
  • Proactive and accountable, following through on risk and assurance actions.
  • Strong analytical and investigative skills, able to evaluate risk objectively.
  • Clear communicator, able to engage effectively with both technical and business stakeholders.
  • Collaborative team player, promoting consistency and knowledge sharing across business units.
  • Integrity, reliability and commitment to high standards of security assurance.
  • Curious and improvement-minded, keen to adopt new tools and automation to work smarter.
  • Adaptable and comfortable working in a fast-paced, evolving environment.

Benefits & culture

At Zellis Group (Zellis, Moorepay, Benifex, and Hastee) we power exceptional employee experiences by creating AI-enabled products and services within HR, workforce management, payroll, and benefits. Our vision is to be the clear leader in pay, reward, analytics, and people experiences. With over 3,500 colleagues across the UK, Europe, India and the Philippines, we have a significant ambition for growth (organically and through M&A).

Our vision is to be the clear leader in pay, reward, analytics, and people experiences. We're passionate about creating an environment where people want to join, belong to, and be part of a progressive organisation. Our values, which were defined with input from of our colleagues, we live and breathe every day:

  • Unstoppable together.
  • Always learning.
  • Make it count.
  • Think scale.

Our people are critical to our ongoing success; we’re proud of our inclusive culture that gives you the platform to grow, challenge the status quo and play a crucial role in further enhancing our market position as the leading provider of HR & Payroll software and services. With Zellis you’ll have the chance to stretch and challenge yourself in an environment that’s varied, flexible and hugely supportive.

We also love to reward and recognise our brilliant colleagues. As part of your benefits package, you’ll receive:

  • A competitive base salary, cash car allowance and bonus package.
  • 25 days annual leave, plus your birthday off and the opportunity to buy additional holiday.
  • Private medical insurance.
  • Life assurance 4x salary.
  • Enhanced pension scheme with company contributions up to 8.5%.
  • A huge range of additional flexible benefits across financial & personal wellbeing, lifestyle & leisure.

About security roles for ex-police

Security management, operations and consultancy roles. Years of operational policing — command, incident response, public order — translate directly into corporate security, and employers in this sector actively rate police experience.

See all security jobs in Bristol

Why this fits a police background — match score 93/100

  • Evidence & case files
  • Intelligence & OSINT
  • Investigative casework
  • Risk & threat assessment

What security roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Security officer (SIA)£24,000–£29,000
Security supervisor / team leader£28,000–£34,000
Site / security manager£38,000–£52,000
Regional / operations security manager£50,000–£65,000
Full security salary guide →

More security jobs for ex-police

  • Contract

    Security Officer - Bath BID Night Marshal Pay: £15.64 per hour (inclusive of holiday pay) This role is offered on a relief basis, giving you the flexibility to choose shifts that fit around your availability and lifestyle.

    Posted 3 days ago

  • Security Officer

    MBDA UK Ltd · Bristol

    Full-time

    This Security Officer opportunity is a great opportunity to be part of a multi-skilled Security Team working at our Bristol site! Security Clearance: British Citizen or a Dual UK national with British citizenship .

    Posted 7 days ago

  • Full-time

    Who we are VIVO provides facilities management and accommodation maintenance for the UK military and its partners. VIVO embodies both experience and innovation. What we do We put our Customers and Families First. They are the driving force behind everything we do.

    Posted 31 days ago

  • Security Officer

    Merc Securitry · London

    Part-time

    £13 – £15 an hourEstimated

    About Us We are a reputable local security company based in South East London, providing professional security services across licensed venues and events. We are currently looking for a reliable, experienced, and professional Security Officer / Door Supervisor to join our growing team.

    Posted Yesterday