Skip to Main Content
Location icon
London

Senior Associate – Information Security

WTW
Office & Professional
Office & Professional
Negotiable
Company logo image
Description

Location
London

Hours
Full Time

Salary
Negotiable

About the Role
This role will directly support the Global Information and Cyber Security (ICS) Group within WTW. You will leverage your skills and experience to support the ICS team in delivering technology and cyber regulatory engagements. Working closely with ICS subject matter experts, your engagement will extend across WTW, including Technology, Business Operations, Internal Audit, Compliance, Risk, Privacy, and Legal teams. You will support and monitor remediation activities where gaps have been identified across multiple regulated environments related to Information and Cyber Security and IT regulatory requirements.

The role involves executing regulatory deliverables such as Requests for Information (RFIs), audits, and regulatory questionnaire submissions with a focus on ICS and Technology Risk within defined schedules. You will define communications and engagement plans with stakeholders including regulators, control owners, and senior management. Collaboration with the ICS Policies and Standards team to map ICS and Technology standards to regulatory requirements is essential.

You will coordinate and develop high-quality, timely responses to information requests, ensuring consistency and leveraging evidence where possible. Engagement with the ICS controls testing team will be required when application controls testing is necessary. Additionally, you will support and monitor identified issues and gaps, managing remediation in line with WTW controls and regulatory requirements. Collaboration with the ICS Risk Team will ensure identified risks are reported and managed appropriately.

Supporting management reporting on engagement status and issue management, you will assist the wider team throughout regulatory engagements. You will contribute to the creation and delivery of presentations and briefings for key stakeholders and generate reports for both technical and non-technical audiences. A broad understanding of ICS functions and their roles and responsibilities will support effective delivery.

Cross-Functional Collaboration: You will collaborate with other regulatory compliance functions such as Audit, Compliance, and Privacy, as well as technology partners, to track compliance across the organization and pool expertise on complex regulatory requirements. Working with business units, you will ensure controls are effective and appropriately address relevant regulatory requirements. You will facilitate attestation and demonstration of compliance with authorities, regulators, and auditors during assessments and audits.

Technology and Cybersecurity Regulatory Engagement Programs: You will contribute to developing and shaping the regulatory engagement operating model and standard processes. This includes devising and maintaining templates and tools to support ICS Regulatory Engagement programs and reporting. You will support the implementation, alignment, maintenance, and monitoring of controls following Information Security standards and frameworks.

Requirements

Experience
- Experienced in identifying and managing risk and compensating controls.
- Demonstrable experience analyzing and applying regulatory requirements to security practices.
- Proven ability to support business implementation of controls to meet and maintain compliance in a complex global organization.
- Strong project management skills and experience.
- Experience working autonomously, managing workload, and delivering within tight timescales.
- Familiarity with technology, cybersecurity, and privacy regulations is beneficial.
- Excellent analytical and problem-solving skills.
- General knowledge of IT operations.
- Holistic understanding of risk processes and functions.

About you
- Strong communication skills and a global team player with good interpersonal and influencing abilities.
- Customer-focused with excellent relationship management skills.
- Delivery-oriented with high resilience and determination.
- Ability to manage multiple and changing priorities.
- Strong desire for continuous learning.
- Good analytical skills with the ability to review and challenge materials produced by colleagues.

Qualifications
- Ideally qualified to degree level in IT or a security-related subject.
- Extensive work experience in Information Security, Information Technology, or Risk is preferred.
- Information security certifications such as CISSP, CCSP, CISA, CRISC, CISM, or ISO 27001 Lead Auditor are preferable.
- Project Management certification (e.g., PMP) is also preferable.

Expiry date: 09/09/2026
Senior Associate – Information Security
Company:
WTW
Job Type:
Full-time
Location:
London