Information Security Officer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
We are looking for an Information Security Officer to support the ongoing development, implementation and maintenance of our information security strategy, policies, controls and risk management processes. The successful candidate will play a central role in protecting information assets, embedding security best practice and supporting compliance with regulatory, Group and business requirements.
Responsibility:
-
Developing and maintaining information security policies, procedures, frameworks and controls.
- Conducting information security risk assessments, identifying vulnerabilities and supporting proportionate mitigation plans.
- Supporting incident response, investigation, reporting and follow-up activity for security incidents and breaches.
- Working with IT, Legal, Compliance, Group and senior stakeholders to strengthen security governance and regulatory alignment.
- Preparing clear reports, dashboards and updates for governance forums, senior management and executive stakeholders.
- Delivering security awareness, training and incident response exercises to promote a strong security culture.
- Supporting audits, third-party reviews and remediation activity linked to information security and IT risk.
What you will bring:
- You will bring strong knowledge of information security, cyber risk, governance, compliance and incident management.
- You will be comfortable working across teams, translating technical risks into clear business recommendations, and supporting a regulated environment where integrity, diligence, customer outcomes and effective risk management are essential., * Cyber security risk assessment, vulnerability review and risk mitigation planning.
- Development and maintenance of security policies, standards, procedures and controls.
- Incident response coordination, investigation, reporting and lessons-learned activity.
- Knowledge of regulatory requirements and security frameworks relevant to financial services or insurance.
- Audit support, control monitoring, remediation tracking and management reporting.
- Security awareness training, phishing simulation reporting and incident response exercises.
- Stakeholder management, including engagement with IT, Legal, Compliance, Group teams and senior leadership.
- Clear written and verbal communication, with the ability to translate technical risks into practical business recommendations.
- Strong analytical thinking, attention to detail, prioritization and continuous improvement mindset.
Why ERGO?
ERGO UK Specialty is a well-established specialist insurer with a strong market reputation. We are focused on profitable, sustainable growth, operational excellence and delivering consistent value to clients and partners.
Requirements
-
Experience in information security, cyber security, IT risk or governance, risk and compliance.
- Knowledge of security frameworks, policies, standards and regulatory expectations relevant to a regulated financial services or insurance environment.
- Experience supporting risk assessments, incident response, audit activity and security reporting.
- Strong stakeholder management, communication and advisory skills.
- A proactive, analytical and collaborative approach, with strong attention to detail and a commitment to continuous improvement.
Key skills:
- Information security governance, risk and compliance management.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
IT Salaries in UK
Data Analyst Salary in the UK
Guide for Expats Living in the UK
Best Companies to work for in London: Top 25 Companies in 2023