Creative Artists Agency
28/07/2026
Full time
Overview This is a hands on security position within the Information Security group, focused on ensuring consistent, measurable end to end delivery of security services. The successful candidate will develop and deploy capabilities that protect enterprise systems and data through the necessary security controls and tools, supporting a fast paced, technology forward environment that includes early adoption of cloud services. Responsibilities Support a Technology Vendor Management program, ensuring technology risk reviews across multiple disciplines, monitoring renewals and savings opportunities. Participate in risk reviews of the IT control framework (NIST CSF, CIS, ITIL, ISO 270001, etc.). Conduct thorough vendor, product and application security assessments in partnership with systems owners to integrate security early during the project lifecycle. Partner with business groups to review workflows, producing output to enhance security processes in support of those workflows. Coordinate, across service owners, the implementation of core security integrations (SSO, event logs, secrets, alerting, threat modeling and backup/recovery) with applications developed in house and in externally/SaaS hosted environments. Ensure the security considerations identified are implemented and solutions are configured securely. Coordinate with IRM leadership to develop and deliver key security metrics, ensuring technical security controls meet desired objectives and demonstrating measurable effectiveness. Qualifications At least 3+ years' experience in Information Technology. At least 2 years' experience in cybersecurity risk management. Bachelor's or master's degree in a relevant field. Strong analytical skills in conducting due diligence to identify, assess and prioritise vendor risks. Familiarity with information security frameworks (NIST, ISO27001), data privacy regulations (GDPR, CCPA), and information security certifications (SOC, ISO, PCIDSS, FedRAMP). Experience coordinating technical integrations for security tooling and processes. Ability to review complex systems architectures to identify key security integration opportunities. Produce comprehensive written security assessments of vendor security postures. Experience using security analytics tooling to produce operational metrics and dashboards. Strong understanding of the fundamental operations of servers, operating systems, cloud applications and infrastructure. Core skills in cybersecurity fundamentals and third party risk management. Familiarity with third party risk management tools/processes such as One Trust, SIG or similar GRC platforms. Hands on experience in Azure, AWS cloud environments and familiarity with core cloud services and architecture. Familiarity with core security concepts of single sign on (e.g., PingFed, SAML), identity and access administration (Active Directory, Azure AD, AWS IAM), event management (Splunk). Expertise in Microsoft Office suite and JIRA. Equal Opportunity Employer Creative Artists Agency ("CAA") is committed to promoting equal opportunities in employment and creating a workplace culture in which diversity and inclusion is valued and everyone is treated with dignity and respect. As part of its zero tolerance approach to discrimination in any form, applicants will receive equal treatment regardless of age, disability, gender reassignment, marital or civil partner status, pregnancy or maternity, race, colour, nationality, ethnic or national origin, religion or belief, sex or sexual orientation, or any other legally recognised protected basis under UK law.