Information Security Officer

Ergo UK Specialty Limited
London, UK
about 2 months ago
Apply on uk.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Phishing

Job description

We are looking for an Information Security Officer to support the ongoing development, implementation and maintenance of our information security strategy, policies, controls and risk management processes. The successful candidate will play a central role in protecting information assets, embedding security best practice and supporting compliance with regulatory, Group and business requirements.

Responsibility:

  • Developing and maintaining information security policies, procedures, frameworks and controls.

  • Conducting information security risk assessments, identifying vulnerabilities and supporting proportionate mitigation plans.
  • Supporting incident response, investigation, reporting and follow-up activity for security incidents and breaches.
  • Working with IT, Legal, Compliance, Group and senior stakeholders to strengthen security governance and regulatory alignment.
  • Preparing clear reports, dashboards and updates for governance forums, senior management and executive stakeholders.
  • Delivering security awareness, training and incident response exercises to promote a strong security culture.
  • Supporting audits, third-party reviews and remediation activity linked to information security and IT risk.

What you will bring:

  • You will bring strong knowledge of information security, cyber risk, governance, compliance and incident management.
  • You will be comfortable working across teams, translating technical risks into clear business recommendations, and supporting a regulated environment where integrity, diligence, customer outcomes and effective risk management are essential., * Cyber security risk assessment, vulnerability review and risk mitigation planning.
  • Development and maintenance of security policies, standards, procedures and controls.
  • Incident response coordination, investigation, reporting and lessons-learned activity.
  • Knowledge of regulatory requirements and security frameworks relevant to financial services or insurance.
  • Audit support, control monitoring, remediation tracking and management reporting.
  • Security awareness training, phishing simulation reporting and incident response exercises.
  • Stakeholder management, including engagement with IT, Legal, Compliance, Group teams and senior leadership.
  • Clear written and verbal communication, with the ability to translate technical risks into practical business recommendations.
  • Strong analytical thinking, attention to detail, prioritization and continuous improvement mindset.

Why ERGO?

ERGO UK Specialty is a well-established specialist insurer with a strong market reputation. We are focused on profitable, sustainable growth, operational excellence and delivering consistent value to clients and partners.

Requirements

  • Experience in information security, cyber security, IT risk or governance, risk and compliance.

  • Knowledge of security frameworks, policies, standards and regulatory expectations relevant to a regulated financial services or insurance environment.
  • Experience supporting risk assessments, incident response, audit activity and security reporting.
  • Strong stakeholder management, communication and advisory skills.
  • A proactive, analytical and collaborative approach, with strong attention to detail and a commitment to continuous improvement.

Key skills:

  • Information security governance, risk and compliance management.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on uk.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · World Congress 2026 Europe

Videos

See all

Related articles

See all