33 Security Policy Development jobs in the United Kingdom
Lead_Analyst Information Security Governance Risk Compliance

Posted 5 days ago
Job Viewed
Job Description
**Title:** Lead Analyst, Information, Security, Governance, Risk and Compliance
**Location:** Remote-UK
**Salary:** £60,000 / annually
**About PSI**
We are PSI Services. We power world leading tests. Delivered with trusted science and the very best test taker experience. PSI supports test-takers on their journey to pursuing dreams and gaining certifications that are important to them. They believe that their dreams are worth working for; that their dreams are worth the effort. And we believe that too. This is our core purpose, to empower people to achieve their dreams. We do this by being the best provider of workforce solutions, which foster both technology and science to deliver the best solutions for our test takers.
We are searching for top talent to join our PSI team and help grow our products and services. We have a creative, supportive and inclusive culture where we empower people in their careers to be their authentic self and make the most of their great talent.
At PSI, we are committed to helping people meet their potential and we believe that promoting diversity, equity and inclusion is critical to our success. That's why you'll find these ideals are intrinsic to our company culture and applied throughout the employee lifecycle.
Learn more about what we do at: the Role**
The Lead Analyst, Information Security - GRC plays a key role in supporting PSI's commitment to data security, privacy, and compliance. This role is responsible for driving core activities across quality, risk management, Information Security, data protection, and audit readiness to ensure the organization meets ISO, PCI, SOC 2, and other relevant standards. The position helps deliver assurance to stakeholders that PSI prioritizes the security and privacy of its data and systems.
This is a full-time, permanent role, Monday to Friday, with flexible working hours around a standard 09:00 - 17:30 schedule. The role reports to the Snr Director of Information Security, Governance, Risk and Compliance and may be performed remotely, with occasional travel to offices and test centres as required for audits and assessments.
**Role Responsibilities**
+ Act as the primary point of contact for implementing and maintaining the security GRC framework.
+ Collaborate with internal teams to support an integrated end-to-end GRC approach across the organization.
+ Collaborate with internal teams to ensure documentation of security control in the form of system architecture diagrams, data flow diagrams and Information System Continuity Plans are in place.
+ Maintain and update security policies, standards, procedures, and guidelines, ensuring they align with current business and IT practices.
+ Monitor and assess the effectiveness of security controls across business systems and processes.
+ Ensure alignment with client, regulatory, and internal compliance requirements.
+ Support the automation and continual improvement of GRC processes and tools.
+ Generate and present GRC-related metrics and reports to internal stakeholders and executive leadership.
+ Support and coordinate internal and external audits (e.g., ISO27001, SOC2, etc.), including gathering evidence and managing responses.
+ Assist in third-party and entity-level risk assessments, identifying and mitigating risks through effective controls.
+ Build and maintain cross-functional relationships with teams such as Legal, IT, Audit, Finance, and Business Operations to ensure GRC practices support overall business objectives.
+ Support ongoing compliance initiatives, including security incident reviews, risk memos, and policy exceptions.
+ Deliver training and awareness programs related to information security, policies, and best practices.
+ Participate in the development of operational reports, metrics dashboards, and trend analysis related to security and compliance activities.
+ Prepare and support audit plans and compliance documentation for internal or external stakeholders.
+ Conduct vetting for access to sensitive systems and data, including continuous monitoring and clearance reviews.
**Knowledge, Skills and Experience Requirements**
+ Experience working within, achieving and/or maintaining ISO standards such as ISO 27001, 9001, 14001 and 2000 (essential).
+ Experience in implementing and maintaining externally awarded certifications such as ISO27001 is essential.
+ Proficient with MS Office
+ Solid understanding of common security tools (e.g., vulnerability scanners, firewalls, IDS/IPS, AV software) strongly recommended
+ Extensive training and experience in computer disciplines such as application and data security, systems programming, systems design, computer technology or software disciplines
+ Familiarity with OneTrust or ServiceNow GRC and Privacy tools desired
+ Certified training in security management, risk and compliance solutions and practices. CISSP, CISA, CISM, GSEC, CRISC, or related certification(s) desirable.
+ Experience in a fast-paced GRC/ISO function (desirable).
**Benefits & Culture**
At PSI, our culture is to be transparent and fair. That's why all of our roles have been benchmarked at a competitive rate against the local market they are based in. To be transparent all of our adverts now include the salary so you can see if we align with your expectations when looking for your next role.
In addition to a competitive salary, we offer a comprehensive benefits package and supportive culture when you join us. This includes:
+ 401k/Pension/Retirement Plan - with country specific employer %
+ Enhanced PTO/Annual Leave
+ Medical insurance - country specific
+ Dental, Vision, Life and Short-Term Disability for US
+ Flexible Spending Accounts - for the US
+ Medical Cashback plan covering vision, dental and income protection for UK
+ Employee Assistance Programme
+ Commitment and understanding of work/life balance
+ A culture of embracing wellness, including regular global initiatives
+ Access to supportive and professional mechanisms to help you plan for your future
+ Volunteer Day and a culture of giving back to our community and industry through volunteering opportunities
Security Governance Manager
Posted 515 days ago
Job Viewed
Job Description
Security Governance Manager
Reports to: Head of Information Security
Location: Hybrid (Newmarket) and or Remote
Hours: 32 hours across a 4-day week (no salary sacrifice)
Salary: £50,000 - £60,000
Product: Group level - Wonde, Evouchers & Secure Schools
Who we are and what is important to us:
Beyond unifies three technology-driven brands, Wonde, Evouchers and Secure Schools.
Each brand shares a vision to reduce the friction of adapting technology, to help customers navigate an often overwhelming area and provide powerful solutions that make their everyday life easier.
The three brands run independently with the autonomy to continue to prosper although as part of the Beyond team, you’ll join a wider, supportive environment where you’ll be able to pull on the expertise and capabilities of the group.
We do not limit ourselves to standing still. We look ahead and strive to disrupt the sector we operate in. We believe technology should not be complicated or overwhelming. It should do what it says - quickly, safely and efficiently.
Job snapshot:
As Security Governance Manager, you will be responsible for ensuring the effectiveness of security policies and control frameworks. You will support the group in adopting a security mindset using a combination of coaching, supporting and leading by example.
This is a newly created position where you will be provided with a genuine opportunity to create impact and drive the best security practices across the group.
What you’ll be doing:
- Management and maintenance of the central Information Security Management System
- Maintain and certify new products to ISO 270001
- Create, consult and operationalise security policies
- Organise, lead and manage all security-related audit activity
- Track and manage audit findings from conception through to delivery
- Coordinate, monitor and measure activities to ensure the ISMS continues to operate as expected
- Support and manage the supplier security assurance process
- Manage the security awareness and training programme
- Manage the continuous improvement process to ensure improvements and efficiencies within Security are achieved
Requirements
What we’re hoping you’ll bring:
- Previous experience in a security-focused role, particularly focusing on the implementation and management of an information security management system supporting ISO 270001
- A qualified ISO 27001 Lead Implementer or auditor (a nice to have)
- Excellent written and oral communication skills
- Natural capabilities to communicate with a diverse range of stakeholders
- Ability to influence and coach technical and non-technical stakeholders
- Ambition and initiative to drive change in an evolving sector
- Self-motivation with the confidence and enthusiasm to take the initiative and get things done
- Ability to prioritise workflow and ensure deadlines are met
- The willingness to learn and adapt in an ever-changing environment
Benefits
What you’ll get:
Beyond is much more than just a place to work. It is a place to grow, innovate, excel and learn. We have tech people, creative people and people people, all focused on providing a superior customer experience.
We value, support and champion those we work with - promoting personal growth and happiness. We get that our success is dependent on the collective energy, intelligence and contributions of all our team members and we are committed to ensuring our work environment is the best it can be.
We value your commitment and have worked hard to create adaptable and comprehensive benefits packages to suit individual needs, although you can expect the below as standard:
- 4-day working week
- Flexible working schedule/work-from-home opportunities
- Onsite gym and well-being (quiet room) facilities
- Buying and selling holiday scheme
- Additional holiday for length of service
- Annual allowance for volunteering days
- Onsite trained mental health and well-being champions
- Monthly lunch club (on us)
- Comprehensive wellness programmes (think meditation retreats and continuous access to well-being apps/initiatives)
- Enhanced maternity, paternity and adoption benefits
- Electric car scheme
- Cycle to Work Scheme
- Eye examination scheme
- Financial contribution to the set up of work-from-home environments
- Use of new and leading technology in the form of apple products
- Frequent company-funded social events
- Office closure between Christmas & New Year
- Access to continuous learning and development opportunities
- Comprehensive employee referral scheme
- Casual Dress Code
In addition to the above, you’ll have access to our ‘take your pick’ benefits scheme which is tailored specifically to you!
Beyond is an equal-opportunity employer. We encourage interest from all candidates and do not discriminate against any non-merit factors. If you require any adjustments to the application or selection process please call or email us so we can ensure you have the correct support: careers@wonde.com/ 01638 438094.
Head of Security Governance, Risk & Compliance
Posted 14 days ago
Job Viewed
Job Description
Head of Security Governance, Risk & Compliance
- Salary: 70,400 - 94,100
- Location: Cambridge/Hybrid Minimum 2 days a week in the office
- Contract: Permanent
TheHead of Security GRCis a senior leadership role within the Security SMT, tasked with driving the organisation's security governance, risk, and compliance strategy. This position engages across all levels of the business, ensuring regulatory compliance, effective risk management, and robust assurance processes to support decision-making by the Senior Leadership Team.
Youwill deliver a robust Security Assurance Framework, oversee supplier assurance activities, and maintain relevant ISO and Cyber Essentials certifications. Additionally, you'll drive the implementation of security standards, policies, governance reporting, and audit programmes to ensure robust controls are in place. You'll play a critical role in enabling informed decision-making and promoting a culture of security awareness across the organisation.
We areCambridge University Press & Assessment, a world-leading academic publisher and assessment organisation and a proud part of the University of Cambridge.
About the role
The position involves engaging atall organisational levels, managing security risks, ensuring regulatory compliance, and providing assurance on business practices to support informed decisions by the Senior Leadership Team and Security Board. Responsibilities include implementing and monitoring security standards, policies, AI governance, and audit programmes to ensure effective mitigations and controls. Additionally, the role entails designing and delivering the Security Assurance Framework, conducting supplier assurance activities and audits, leading the Awareness Community of Practice, and maintaining relevant ISO & Cyber Essentials certifications.
KeyAccountabilities:
- Develops security standards, policies, and guidelines and ensures compliance across Cambridge.
- Leads the delivery of approved projects and investments to reduce risk and security exposure.
- Proactively identifies new threats, risks, and trends; reports mitigation progress to the Security Board and SLT.
- Collaborates with key stakeholders to create customer-centric security policies for products and services.
- Coordinates audits, regulatory inquiries, and external vendor activities to align with industry standards.
- Responsible for leading and managing the GRC team to achieve compliance and team success in the organisation.
- Oversees vendor relationships to ensure protection of Cambridge global people and assets.
- Aligns attack surface management (ASM) process with GRC objectives and provides updates on mitigation progress.
- Integrates AI governance with relevant GRC frameworks to meet regulatory standards.
- Manages certifications like ISO 27001, 42001, Cyber Essentials, and HMG Security Policy Framework.
About you
We are looking for a highly skilled and experiencedprofessional with the following expertise:
- Proven experience managing an Information Security Management System (ISMS), including ISO 27001 certification.
- Strong working knowledge of security threats and proportionate mitigations, as well as supply chain security management systems.
- A minimum of 3 years' experience in a senior governance or risk management role.
- Active CRISC or ISO 27005 Risk Manager certification (or higher), with additional certifications such as ISO 27001/42001 Lead Auditor or Implementor being advantageous.
- Demonstrated experience in strategic governance of security, managing security risks in line with ISO 27005, and implementing ISO 27001 compliant systems.
- Expertise in auditing security controls for both internal operations and third parties.
- Exceptional stakeholder management skills, with the ability to build relationships across all organisational levels.
- Strong negotiation skills to influence decisions and achieve positive outcomes.
- Experience leading and developing teams, both within the UK and regionally.
If you would like to know more about thisopportunity and what will make you successful, please see the full job description attached to the bottom of this vacancy on our careers site.
Rewards and benefits
We will support you to be at your best in work and to live well outside of it. In addition to competitive salaries, we offer a world-class, flexiblerewards package, featuring family-friendly and planet-friendly benefits including:
- 28 days annual leave plus bank holidays
- Private medical and Permanent Health Insurance
- Discretionary annual bonus
- Group personal pension scheme
- Life assurance up to 4 x annual salary
- Green travel schemes
We are a hybrid working organisation, and we offer a range of flexible working options from day one. We expect most hybrid-working colleagues to spend 40-60% of their time at their dedicated office or location. We will also consider other work arrangements if you wish to work more flexibly or require adjustments due to a disability.
Ready to pursue your potential? Apply now.
We reviewapplications on an ongoing basis, with a closing date for all applications being 27th July although we may close it earlier if suitable candidates areidentified. Interviews are scheduled to take place shortly after it closes.
Please note that successful applicants will be subject to satisfactory background checks including DBS due to working in a regulated industry.
University Press & Assessment is an approved UK employer for the sponsorship of eligible roles and applicants under the Skilled Worker visa route. Please refer to thegovwebsite for guidance to understand your own eligibility based on the role you are applying for.
Head of Security Governance, Risk & Compliance
Head of Security Governance, Risk & Compliance
Posted 1 day ago
Job Viewed
Job Description
Head of Security Governance, Risk & Compliance
- Salary: 70,400 - 94,100
- Location: Cambridge/Hybrid Minimum 2 days a week in the office
- Contract: Permanent
TheHead of Security GRCis a senior leadership role within the Security SMT, tasked with driving the organisation's security governance, risk, and compliance strategy. This position engages across all levels of the business, ensuring regulatory compliance, effective risk management, and robust assurance processes to support decision-making by the Senior Leadership Team.
Youwill deliver a robust Security Assurance Framework, oversee supplier assurance activities, and maintain relevant ISO and Cyber Essentials certifications. Additionally, you'll drive the implementation of security standards, policies, governance reporting, and audit programmes to ensure robust controls are in place. You'll play a critical role in enabling informed decision-making and promoting a culture of security awareness across the organisation.
We areCambridge University Press & Assessment, a world-leading academic publisher and assessment organisation and a proud part of the University of Cambridge.
About the role
The position involves engaging atall organisational levels, managing security risks, ensuring regulatory compliance, and providing assurance on business practices to support informed decisions by the Senior Leadership Team and Security Board. Responsibilities include implementing and monitoring security standards, policies, AI governance, and audit programmes to ensure effective mitigations and controls. Additionally, the role entails designing and delivering the Security Assurance Framework, conducting supplier assurance activities and audits, leading the Awareness Community of Practice, and maintaining relevant ISO & Cyber Essentials certifications.
KeyAccountabilities:
- Develops security standards, policies, and guidelines and ensures compliance across Cambridge.
- Leads the delivery of approved projects and investments to reduce risk and security exposure.
- Proactively identifies new threats, risks, and trends; reports mitigation progress to the Security Board and SLT.
- Collaborates with key stakeholders to create customer-centric security policies for products and services.
- Coordinates audits, regulatory inquiries, and external vendor activities to align with industry standards.
- Responsible for leading and managing the GRC team to achieve compliance and team success in the organisation.
- Oversees vendor relationships to ensure protection of Cambridge global people and assets.
- Aligns attack surface management (ASM) process with GRC objectives and provides updates on mitigation progress.
- Integrates AI governance with relevant GRC frameworks to meet regulatory standards.
- Manages certifications like ISO 27001, 42001, Cyber Essentials, and HMG Security Policy Framework.
About you
We are looking for a highly skilled and experiencedprofessional with the following expertise:
- Proven experience managing an Information Security Management System (ISMS), including ISO 27001 certification.
- Strong working knowledge of security threats and proportionate mitigations, as well as supply chain security management systems.
- A minimum of 3 years' experience in a senior governance or risk management role.
- Active CRISC or ISO 27005 Risk Manager certification (or higher), with additional certifications such as ISO 27001/42001 Lead Auditor or Implementor being advantageous.
- Demonstrated experience in strategic governance of security, managing security risks in line with ISO 27005, and implementing ISO 27001 compliant systems.
- Expertise in auditing security controls for both internal operations and third parties.
- Exceptional stakeholder management skills, with the ability to build relationships across all organisational levels.
- Strong negotiation skills to influence decisions and achieve positive outcomes.
- Experience leading and developing teams, both within the UK and regionally.
If you would like to know more about thisopportunity and what will make you successful, please see the full job description attached to the bottom of this vacancy on our careers site.
Rewards and benefits
We will support you to be at your best in work and to live well outside of it. In addition to competitive salaries, we offer a world-class, flexiblerewards package, featuring family-friendly and planet-friendly benefits including:
- 28 days annual leave plus bank holidays
- Private medical and Permanent Health Insurance
- Discretionary annual bonus
- Group personal pension scheme
- Life assurance up to 4 x annual salary
- Green travel schemes
We are a hybrid working organisation, and we offer a range of flexible working options from day one. We expect most hybrid-working colleagues to spend 40-60% of their time at their dedicated office or location. We will also consider other work arrangements if you wish to work more flexibly or require adjustments due to a disability.
Ready to pursue your potential? Apply now.
We reviewapplications on an ongoing basis, with a closing date for all applications being 27th July although we may close it earlier if suitable candidates areidentified. Interviews are scheduled to take place shortly after it closes.
Please note that successful applicants will be subject to satisfactory background checks including DBS due to working in a regulated industry.
University Press & Assessment is an approved UK employer for the sponsorship of eligible roles and applicants under the Skilled Worker visa route. Please refer to thegovwebsite for guidance to understand your own eligibility based on the role you are applying for.
Head of Security Governance, Risk & Compliance
Head of Security Governance, Risk & Compliance (5880) - Cambridge
Posted 1 day ago
Job Viewed
Job Description
Job Title: Head of Security Governance, Risk & Compliance
Salary: £70,400 - £94,100
Location: Cambridge/Hybrid Minimum 2 days a week in the office
Contract: Permanent
The Head of Security GRC is a senior leadership role within the Security SMT, tasked with driving the organisation's security governance, risk, and compliance strategy. This position engages across all levels of the business, ensuring regulatory compliance, effective risk management, and robust assurance processes to support decision-making by the Senior Leadership Team.
You will deliver a robust Security Assurance Framework, oversee supplier assurance activities, and maintain relevant ISO and Cyber Essentials certifications. Additionally, you'll drive the implementation of security standards, policies, governance reporting, and audit programmes to ensure robust controls are in place. You'll play a.
Information Security Manager
Posted 11 days ago
Job Viewed
Job Description
Information Security Manager
Location: Central Bristol
Job Type: Full-time, Hybrid (2 days per week in-office)
Salary: 60,000 - 70,000 + Benefits
We are recruiting an Information Security Manager to lead the operational and strategic security programme for a respected organisation headquartered in central Bristol. This hybrid role offers the opportunity to shape the company's approach to information risk and resilience, while managing a skilled internal team and driving alignment with industry standards and best practice.
Reporting to the Head of Security & Governance , the successful candidate will play a central role in delivering risk reduction across the business. You'll be responsible for maintaining ISO27001 compliance, overseeing risk assessment and mitigation, and supporting incident management across multi-entity operations.
Key Accountabilities:
- Lead and manage a team of three security professionals , supporting their development and day-to-day delivery.
- Ensure ongoing ISO27001 accreditation and alignment with broader assurance frameworks (e.g. NIST CSF, Cyber Essentials).
- Shape and implement the company's information security strategy , including policy, tooling, and training.
- Conduct risk assessments, oversee remediation plans, and guide secure-by-design approaches across projects.
- Provide technical leadership in areas including threat intelligence, compliance reporting, and incident response .
- Support regulatory and internal audits, contributing clear documentation and continuous improvement.
- Collaborate with internal teams and external partners, including service providers and the organisation's parent company.
Required Skills & Qualifications:
- Demonstrable experience in information security leadership , including line management or team leadership .
- In-depth knowledge of ISO27001, GDPR, FCA SYSC, PCI DSS and other regulatory/compliance frameworks.
- Hands-on experience with security technologies: SIEM, IAM, vulnerability assessment, endpoint protection, cloud services (AWS, SaaS, IaaS) .
- Strong communication skills and stakeholder management abilities.
- Experience in incident response and enterprise risk reporting.
- Professional certifications such as CISSP or ISO27001 Lead Implementer/Auditor (desirable).
Benefits:
- Hybrid working (2 days per week in-office)
- Generous annual leave & pension contributions
- Life assurance and private health options
- Training budget and career development support
- Collaborative, supportive team culture
If you're ready to lead a team, shape an enterprise-wide security programme, and work at the heart of a well-established organisation, we'd love to hear from you.
Apply today - successful applicants will be contacted within 24-48 working hours.
Information Security Manager
Posted 1 day ago
Job Viewed
Job Description
Information Security Manager
Location: Central Bristol
Job Type: Full-time, Hybrid (2 days per week in-office)
Salary: 60,000 - 70,000 + Benefits
We are recruiting an Information Security Manager to lead the operational and strategic security programme for a respected organisation headquartered in central Bristol. This hybrid role offers the opportunity to shape the company's approach to information risk and resilience, while managing a skilled internal team and driving alignment with industry standards and best practice.
Reporting to the Head of Security & Governance , the successful candidate will play a central role in delivering risk reduction across the business. You'll be responsible for maintaining ISO27001 compliance, overseeing risk assessment and mitigation, and supporting incident management across multi-entity operations.
Key Accountabilities:
- Lead and manage a team of three security professionals , supporting their development and day-to-day delivery.
- Ensure ongoing ISO27001 accreditation and alignment with broader assurance frameworks (e.g. NIST CSF, Cyber Essentials).
- Shape and implement the company's information security strategy , including policy, tooling, and training.
- Conduct risk assessments, oversee remediation plans, and guide secure-by-design approaches across projects.
- Provide technical leadership in areas including threat intelligence, compliance reporting, and incident response .
- Support regulatory and internal audits, contributing clear documentation and continuous improvement.
- Collaborate with internal teams and external partners, including service providers and the organisation's parent company.
Required Skills & Qualifications:
- Demonstrable experience in information security leadership , including line management or team leadership .
- In-depth knowledge of ISO27001, GDPR, FCA SYSC, PCI DSS and other regulatory/compliance frameworks.
- Hands-on experience with security technologies: SIEM, IAM, vulnerability assessment, endpoint protection, cloud services (AWS, SaaS, IaaS) .
- Strong communication skills and stakeholder management abilities.
- Experience in incident response and enterprise risk reporting.
- Professional certifications such as CISSP or ISO27001 Lead Implementer/Auditor (desirable).
Benefits:
- Hybrid working (2 days per week in-office)
- Generous annual leave & pension contributions
- Life assurance and private health options
- Training budget and career development support
- Collaborative, supportive team culture
If you're ready to lead a team, shape an enterprise-wide security programme, and work at the heart of a well-established organisation, we'd love to hear from you.
Apply today - successful applicants will be contacted within 24-48 working hours.
Be The First To Know
About the latest Security policy development Jobs in United Kingdom !
Information Security Manager

Posted 1 day ago
Job Viewed
Job Description
**Job Title:** Information Security Manager
**Location:** London, UK or Birmingham hybrid Variable
**Department:** Information Security
**About Us:**
NTT Data is a leading Managed Service Provider (MSP) with a global reach empowering local team, undertaking hugely exciting work and is genuinely changing the world.
We specialise in delivering cutting-edge IT and cybersecurity solutions to our diverse client base. We provide expert-managed services to help clients protect their data, comply with regulations, and manage evolving cyber threats. We are looking for a skilled Information Security Manager to join our team and be billed out to a key client to enhance their information security posture.
**What you'll be doing:**
**What you will be doing;**
We are seeking an experienced Information Security Manager to play a critical role in ensuring the security and resilience of our client's IT systems and data. As a client-facing professional, you will act as the pivotal point of contact for all matters relating to information and cybersecurity. You will collaborate closely with multiple teams to develop, implement, and manage robust information security frameworks, policies, and protocols.
This role combines both strategic leadership and technical expertise, enabling you to influence decision-making, advise on best practices, and ensure continuous improvement in the security posture. You will lead efforts in risk management, regulatory compliance, incident response, and security awareness training, while ensuring the client remains aligned with industry standards and legal requirements (e.g., ISO 27001, GDPR, Cyber Essentials). Your expertise will help mitigate risks, defend against cyber threats, and maintain the highest level of security across the client's infrastructure, all while maintaining a clear focus on delivering outstanding service and value.
Key to your success will be your ability to manage complex security challenges, foster strong relationships with teams, and drive a proactive security culture within their organisation.
**Core responsibilities;**
+ Act as the primary information security point of contact for relevant teams, developing a trusted relationship and advising on all aspects of cybersecurity.
+ Develop, implement, and maintain information security policies, procedures, and frameworks, ensuring alignment with industry standards (e.g., ISO 27001, NIST) and legal requirements (e.g., GDPR, Cyber Essentials).
+ Conduct security risk assessments and vulnerability management for the client, providing actionable recommendations to mitigate risks.
+ Lead incident detection, investigation, and response efforts, ensuring minimal impact to the client's business operations.
+ Collaborate with the client's IT and business teams to integrate security solutions and processes that align with their goals.
+ Deliver regular reporting to the client on security status, incidents, risks, and compliance with agreed SLAs and KPIs.
+ Provide guidance and support for the client in meeting their regulatory obligations (e.g., GDPR compliance, data protection).
+ Oversee and lead security audits, penetration testing, and vulnerability assessments for the client.
+ Manage security awareness training programs for the client's staff, fostering a culture of cybersecurity awareness.
+ Provide ongoing advice on emerging threats, vulnerabilities, and security best practices, helping the client stay ahead of the curve.
+ Ensure that the client's information security posture is continuously improved through proactive security measures, monitoring, and reporting.
**What experience you'll bring:**
**What you will bring;**
Proven experience (typically 5+ years) in information security management or a related role, preferably within an MSP or client-facing environment.
+ Strong understanding of UK and international cybersecurity regulations, including GDPR, Cyber Essentials, and ISO 27001.
+ Experience managing and leading security operations, incident response, and risk assessments.
+ Understanding and knowledge of security technologies (SIEM, firewalls, endpoint protection, encryption, etc.) and practices (vulnerability management, penetration testing).
+ Experience working in a service delivery or consultancy capacity with external clients.
+ Excellent communication skills, able to convey technical security information to non-technical stakeholders at all levels.
+ Relevant certifications such as CISSP, CISM, CISA, or equivalent are highly desirable.
**Desirable Attributes:**
+ Strong stakeholder engagement experiences.
+ Ability to work independently, take initiative, and work in a dynamic environment.
+ Proactive approach to identifying and solving problems before they escalate.
+ Strong leadership and mentoring skills to support junior staff and teams.
+ Ability to translate business needs into security solutions.
**Who we are:**
We're a business with a global reach that empowers local teams, and we undertake hugely exciting work that is genuinely changing the world. Our advanced portfolio of consulting, applications, business process, cloud, and infrastructure services will allow you to achieve great things by working with brilliant colleagues, and clients, on exciting projects.
Our inclusive work environment prioritises mutual respect, accountability, and continuous learning for all our people. This approach fosters collaboration, well-being, growth, and agility, leading to a more diverse, innovative, and competitive organisation. We are also proud to share that we have a range of Inclusion Networks such as: the Women's Business Network, Cultural and Ethnicity Network, LGBTQ+ & Allies Network, Neurodiversity Network and the Parent Network.
For more information on Diversity, Equity and Inclusion please click here: Creating Inclusion Together at NTT DATA UK | NTT DATA ( we'll offer you:**
We offer a range of tailored benefits that support your physical, emotional, and financial wellbeing. Our Learning and Development team ensure that there are continuous growth and development opportunities for our people. We also offer the opportunity to have flexible work options.
You can find more information about NTT DATA UK & Ireland here: are an equal opportunities employer. We believe in the fair treatment of all our employees and commit to promoting equity and diversity in our employment practices. We are also a proud Disability Confident Committed Employer - we are committed to creating a diverse and inclusive workforce. We actively collaborate with individuals who have disabilities and long-term health conditions which have an effect on their ability to do normal daily activities, ensuring that barriers are eliminated when it comes to employment opportunities. In line with our commitment, we guarantee an interview to applicants who declare to us, during the application process, that they have a disability and meet the minimum requirements for the role. If you require any reasonable adjustments during the recruitment process, please let us know. Join us in building a truly diverse and empowered team.
Back to search Email to a friend Apply now
Information Security Engineer
Posted today
Job Viewed
Job Description
Title: Infomation Security Engineer
Contract: 8 month (Initially)
Rate: Up to £625 Per Day (Inside IR35)
Location: Remote!
Are you passionate about embedding security into the heart of technology change?
if so.
Our client is looking for an experienced Secure by Design Specialist to support their high-profile organisation in strengthening their security posture across major transformation initiative.
WHJS1_UKTJ
Information Security Architect
Posted 1 day ago
Job Viewed
Job Description
To support the Chief Information Security Officer in managing and reporting the Information Security Risks faced by Technology Services (TS) in delivering AJ Bells systems and services. This role is responsible for facilitating the secure delivery of AJ Bells technology and business change. The Information Security Architect will play a lead role in designing and implementing security controls and.
WHJS1_UKTJ