Bedford | Hybrid – 1 / 2 Days Office per week £60,000 – £70,000 + Excellent Benefits | Permanent
GRC | ISO 27001 | ISMS | Security Audits | Risk Management | Cyber Security | Information Security
Are you an experienced Information Security / Cyber Security professional with strong hands-on GRC, ISO 27001 and Security Audit experience, combined with a technical understanding of Cyber Security?
We're recruiting an Information Security Lead / Cyber Security Lead for a leading international SaaS software business, offering the opportunity to take greater ownership across Information Security, GRC, Security Governance, Risk, Compliance and Cyber Security.
Strong GRC and audit experience is essential. We're looking for someone who understands how to operate and improve an ISMS, support ISO 27001, manage security risk and controls, and work confidently across internal audits, external certification audits, customer assurance and supplier security.
Ideally, you'll have developed your career from an IT, Infrastructure, Network or technical Cyber Security background before moving into broader Information Security and GRC.
THE ROLE
You'll work closely with the Head of Information Security, helping maintain and continually improve the organisation's Information Security, GRC and compliance environment.
Your remit will include ISO 27001, ISMS, security audits, risk assessments, policies and controls, customer assurance, supplier security and audit remediation, alongside Cyber Essentials and wider certification activities.
You'll also work closely with technical teams across vulnerability management, patching, penetration testing, incident response, Business Continuity and Disaster Recovery, ensuring security risks and audit findings translate into practical improvements.
SKILLS & EXPERIENCE
We're particularly interested in strong experience across:
• GRC & Security Governance: ISO 27001, ISMS, Risk Management, Security Policies, Controls, Compliance and Information Security Governance.
• Resilience & Compliance: Cyber Essentials, Business Continuity, Disaster Recovery, DPIAs, BIAs and Third-Party Risk.
You'll ideally have 5+ years' experience across Information Security, Cyber Security, GRC, IT Risk, Compliance or Security Assurance.
You don't necessarily need to already be an Information Security Manager. We'd also like to hear from Information Security Leads, GRC Leads, Senior Information Security Analysts, Senior Cyber Security Analysts, Information Security Consultants, IT Risk & Compliance professionals and Security Engineers who have developed substantial GRC and audit experience.
THE BALANCE WE'RE LOOKING FOR
This is not a purely technical Security Engineering position.
The strongest candidates will bring genuine GRC, ISO 27001 and audit experience, but also enough technical understanding to work credibly with Infrastructure, IT Operations and Software Engineering teams.
You'll be equally comfortable discussing audit findings, risk and ISO 27001 controls with senior stakeholders as you are working with technical teams on vulnerabilities, remediation and security improvements.
WHY CONSIDER IT?
A great opportunity to join a leading international SaaS software business and take broader ownership across Information Security, GRC, Audit and Cyber Security.
£60,000 – £70,000 + Excellent Benefits Bedford | Hybrid – 3 Days Office / 2 Days Remote
If you have strong GRC + ISO 27001 + Security Audit + Information Security experience, combined with a good technical security foundation, we'd like to hear from you.
Apply today for a confidential discussion.
KEY SKILLS:
Information Security Lead, Cyber Security Lead, Information Security Manager, GRC, GRC Lead, Information Security, Cyber Security, ISO 27001, ISMS, Information Security Management System, Security Audit, Internal Audit, External Audit, Certification Audit, Security Governance, Risk Management, Compliance, Security Controls, Audit Remediation, Customer Assurance, Supplier Assurance, Third Party Risk, Cyber Essentials, Vulnerability Management, Penetration Testing, Incident Response, Business Continuity, Disaster Recovery, DPIA, BIA, Infrastructure Security, Network Security Only candidates based in UK and eligible to work in UK are allowed
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Others Full-Time Jobs in the UK.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip
GrabJobs is the no1 job portal in the UK, connecting you to thousands of jobs fast!
Find the best jobs in the UK, apply in 1 click and get a job today!