Senior InfoSec Analyst FTC
Team: Engineering & Data
Location: Depop - London
Company Description
Life is about creating. That's why we're home to over 30 million artists, stylists, designers, sneakerheads — and you? We're the community-powered, circular-minded marketplace changing the world of online fashion. Now it's time to get inspired at Depop.
Responsibilities
As part of the Information Security team, this role will be responsible for leading and supporting Depop's information security program, conducting risk assessments, developing and implementing security policies, and responding to security incidents.
FTC: May 2025 to March 2026
Responsibilities
Support the Head of Information Security in defining and delivering upon a broad, company-wide security roadmap, including training, physical/cyber/information security, compliance, policies, etc.
Monitor logging and alerting tooling for security issues
Investigate security breaches and other cybersecurity incidents
Install security measures and operate software to protect systems and information infrastructure
Document security incidents and breaches and assess the damage they cause
Work with the Engineering teams to respond to tests and uncover vulnerabilities
Work with teams to fix detected vulnerabilities to maintain a high-security standard
Develop and maintain company-wide best practices, policies and processes for Information Security
Research security enhancements and make recommendations to management
Stay up-to-date on information technology trends and security standards
Ensure compliance with relevant regulations and standards, such as PCI DSS, HIPAA, and SOX
Knowledge of risk assessment tools, technologies and methods
Knowledge of disaster recovery, computer forensic tools, technologies and methods
Contribute to the security incident response process and play an active role in it
The role involves participation in an on-call rotation, during which the analyst will be responsible for monitoring and responding to security alerts and potential incidents.
Qualifications:
Knowledge of CyberSecurity Frameworks (NIST, CIS, ISO27001)
Experience with detection and remediation of security vulnerabilities
Knowledge of risk assessment tools, technologies and methods
Experience planning, researching and developing security policies, standards and procedures
Experience in privacy and cyber governance, risk and compliance frameworks and controls
Proven ability to identify and assess complex risks and understand the mechanisms (people, process, technology) available to manage those risks
Non-technical
Exemplary communication skills, especially in dealing with multiple stakeholders
Able to take a risk-based approach and effectively prioritise many competing demands
Desirable
People management and mentoring experience; we want you to help shape and develop our Information Security Awareness
Understand compliance, legal and ethical obligations organisations should have with respect to logical and physical security, personally identifiable information and data protection
How we work
MyMode is our new hybrid-working model, designed to empower our employees to choose a working mode that works for them.
MyMode is composed of 3 working modes: Flex, Office Based and Remote.
Flex (Default)
Tell me more +Show me less -Flex is our default working mode, meaning all employees will automatically enrol in this mode and there is no application required to enter this mode. Flex employees will be expected to work from the office at least 4 days per month. Teams will determine whether there are set weekly or monthly in-office days based on their operating rhythms and practices. You will need to work with your manager to determine your in-office schedule for your team.
Office Based
Tell me more +Show me less -This option is for employees who are committing to work from the office for a minimum of 4 days per week. As part of taking on the Office Based working mode you will be able to apply for a permanent desk in the office if you need one, but you won’t need to apply to become an Office Based employee.
Remote
Tell me more +Show me less -Under the Remote working mode you are able to work anywhere within the country you are employed in. This mode requires around 2- 4 days per year in the office, depending on organisational guidance. You will be able to expense travel if you are asked to attend the office, but not for office attendance by your choice.
*Remote working is not applicable for all roles at Depop, please check with our Talent Team.
Application Process
Our DNA encompasses the central reasons that people are proud to work at Depop and unites us with a shared language and sense of community.
It guides our daily interactions and empowers individuals, teams, departments and our company as a whole to have a greater impact and achieve our mission.
Show up for the community
Tell me more +Show me less -We go above and beyond. When they succeed, we succeed.
We’re changing how millions of people buy, sell and explore their style, so we do everything we can to create a safe space in a community where you can learn, grow and succeed on your own terms.
Have each other's backs
Tell me more +Show me less -We empower each other with kindness and respect our differences.
Everyone at Depop is seen, heard, valued and encouraged. Our genius is born from our diversity of thought, so we celebrate our wins together and hold each other up when things get tough.
Act with purpose
Tell me more +Show me less -We take conscious risks, deliver efficiently and learn from our mistakes.
Our mission is to be the world’s most diverse and progressive home of fashion. We have the conviction to succeed, the patience to learn and the confidence to fail and try again - being open all the way.
Think thrift
Tell me more +Show me less -We’re resourceful, seek out opportunities and we hustle.
We’re powering a future that is more thoughtful, circular and better for people and planet. To do it, we stay curious, savvy, resourceful and empowered to get the job done – effectively and responsibly.
At the heart of our mission...
At the heart of our mission...