Salary: up to £50,000 + 15% Project Uplift + Company Car/Car Allowance Location: Suffolk (onsite)
REED Technology are recruiting for an Information Security & Assurance Officer to join a major UK infrastructure programme. This is a fantastic opportunity for an information security professional who enjoys balancing security governance, compliance and assurance with oversight of operational cyber security activities.
You'll play a key role in maintaining the organisation's Information Security Management System (ISMS), ensuring compliance with recognised security frameworks, managing risk and assurance activities, and acting as a trusted adviser to both technical and non-technical stakeholders.
This role would suit someone with experience in Information Security, GRC, Information Assurance or Cyber Security who is looking to develop their career within a highly regulated and complex environment.
Key Responsibilities
Own and maintain the Information Security Management System (ISMS) Ensure compliance with ISO 27001, GDPR and wider security governance requirements Develop and maintain security policies, standards and procedures Conduct security risk assessments and support internal and external audits Manage supplier and third-party security assurance activities Provide oversight of Microsoft 365 security controls, including identity and access management, MFA, endpoint protection and monitoring Work closely with SOC and security service providers to support incident management and response activities Produce security reports, dashboards and assurance documentation for senior stakeholders Deliver security awareness initiatives across the organisation Support continuous improvement of security controls, processes and governance frameworksAbout You
We're interested in speaking with candidates who can demonstrate experience in:
Information Security Governance, Risk and Compliance (GRC) Information Security Assurance and risk management ISO 27001 and Information Security Management Systems (ISMS) GDPR and data protection requirements Security audits, compliance reviews and assurance activities Supplier or third-party security assessments Security incident management and response processes Microsoft security technologies such as Defender, Sentinel, Entra ID or similar platforms Building strong relationships with stakeholders at all levelsDesirable Experience
Cyber Essentials or Cyber Essentials Plus NIST Cyber Security Framework Experience within infrastructure, utilities, energy, defence, engineering, financial services or other regulated sectors Professional certifications such as CISSP, CISM, ISO 27001 Lead Auditor/Implementer, Security+ or equivalentWhat's on Offer?
15% project uplift paid monthly Company car or car allowance Annual bonus Private medical insurance Life assurance Enhanced pension contributions 25 days annual leave plus bank holidays Additional holiday purchase scheme Professional memberships paid Ongoing training and development opportunitiesThis is an excellent opportunity to join a high-profile programme where you'll have real ownership of information security governance and assurance, while contributing to the success of a nationally significant project. If you are interested, apply using the link provided Only candidates based in UK and eligible to work in UK are allowed
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Others Full-Time Jobs in the UK.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip
GrabJobs is the no1 job portal in the UK, connecting you to thousands of jobs fast!
Find the best jobs in the UK, apply in 1 click and get a job today!