Information Security Consultant

Reed
Suffolk, UK
5 days ago
Apply on www.careerboard.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
£50,000.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Cyber Security Identity and Access Management Microsoft Security Essentials Information Security Management System

Job description

REED Technology are recruiting for an Information Security & Assurance Officer to join a major UK infrastructure programme. This is a fantastic opportunity for an information security professional who enjoys balancing security governance, compliance and assurance with oversight of operational cyber security activities.

You’ll play a key role in maintaining the organisation’s Information Security Management System (ISMS), ensuring compliance with recognised security frameworks, managing risk and assurance activities, and acting as a trusted adviser to both technical and non-technical stakeholders.

This role would suit someone with experience in Information Security, GRC, Information Assurance or Cyber Security who is looking to develop their career within a highly regulated and complex environment., * Own and maintain the Information Security Management System (ISMS)

  • Ensure compliance with ISO 27001, GDPR and wider security governance requirements
  • Develop and maintain security policies, standards and procedures
  • Conduct security risk assessments and support internal and external audits
  • Manage supplier and third-party security assurance activities
  • Provide oversight of Microsoft 365 security controls, including identity and access management, MFA, endpoint protection and monitoring
  • Work closely with SOC and security service providers to support incident management and response activities
  • Produce security reports, dashboards and assurance documentation for senior stakeholders
  • Deliver security awareness initiatives across the organisation
  • Support continuous improvement of security controls, processes and governance frameworks

About You

We’re interested in speaking with candidates who can demonstrate experience in:

  • Information Security Governance, Risk and Compliance (GRC)
  • Information Security Assurance and risk management
  • ISO 27001 and Information Security Management Systems (ISMS)
  • GDPR and data protection requirements
  • Security audits, compliance reviews and assurance activities
  • Supplier or third-party security assessments
  • Security incident management and response processes
  • Microsoft security technologies such as Defender, Sentinel, Entra ID or similar platforms
  • Building strong relationships with stakeholders at all levels

Requirements

  • NIST Cyber Security Framework
  • Experience within infrastructure, utilities, energy, defence, engineering, financial services or other regulated sectors
  • Professional certifications such as CISSP, CISM, ISO 27001 Lead Auditor/Implementer, Security+ or equivalent

Benefits & conditions

  • 15% project uplift paid monthly
  • Company car or car allowance
  • Annual bonus
  • Private medical insurance
  • Life assurance
  • Enhanced pension contributions
  • 25 days annual leave plus bank holidays
  • Additional holiday purchase scheme
  • Professional memberships paid
  • Ongoing training and development opportunities

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerboard.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:03 min

Microsoft integrating native Unix coreutils into Windows environments

Chris Heilmann +2 · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

1:24 min

Installing premium packages using the Store CLI

Noraa Junker Noraa Junker · Europe 2026 Virtual

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all