Information Security Specialist
deciphex
Kidlington, UK
16 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.collegerecruiter.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source
Tech stack
Artificial Intelligence
Cloud Computing Security
Cyber Security
Data Governance
DevOps
Multi-Factor Authentication
Role-Based Access Control
Reliability Engineering
Security Information and Event Management
Software Vulnerability Management
Information Security Management System
Job description
- You’ll report to and work closely with the Information Security Lead, as well as Cybersecurity Engineering, DevOps, IT, Data Governance, and AI Governance to embed secure-by-design practices across the organisation., * Information security underpins all of our business activities, including AI development
- and compliance with Medical Device regulations
- This role is ideal for a hands-on security specialist who supports the ISMS, validates controls for themselves, and drives continuous improvement with energy and pragmatism.
- This role moves away from traditional GRC and leans into modernising it - moving teams towards always-on compliance and consistently demonstrating business value in the activities we run.
- You’ll work across the business as someone who meets challenges head-on, brings people with them, and makes security work in practice, not just on paper., * This role involves protecting systems and data that directly support cancer diagnostics and drug development, security work with real-world consequence.
- This is a hands-on, delivery-focused role suited to someone who thrives in a very fast-moving environment.
- Success requires a pragmatic approach, strong judgement, and the ability to navigate challenges, remove obstacles, and drive progress at pace.
ISMS & Certifications
- We hold ISO 27001 certification across our core business units and are expanding coverage as we grow.
- Support the day-to-day running of the ISO 27001 ISMS across our Deciphex business units (Deciphex, Diagnexia & Patholytix)
- Prepare for internal and external audits so that teams are ready, controls are functioning, and evidence is complete. Audit readiness as a steady state.
- Contribute to continuous improvement initiatives. Iidentify what needs to change, make the case, and see it through.
- Proactively identify and close gaps in the control framework, driving corrective actions (CAPAs) to closure
- Build and maintain a reliable evidence pipeline with clear ownership and high completeness.
- Assess which ISMS activities deliver measurable business value - and be willing to challenge or retire processes that aren’t.
Security Governance & Risk
- Maintain a live, decision-oriented risk register with owners and mitigation plans.
- Champion a risk-aware culture where decisions are informed by risk, not paralysed by it.
- Develop and maintain policies and procedures that reflect how the business actually operates (not a unworkable bottleneck)
- Support vendor and customer security due diligence in support of commercial and product needs.
- Contribute to tabletop exercises (e.g. incident response, business continuity)
- Maintain awareness of applicable regulatory requirements (EU AI Act, GDPR, HIPAA, MDR/IVD) and ensure the ISMS remains aligned with our other Certifications and Standards
Technical Oversight
- Define evidence expectations for technical controls (SIEM, EDR, MFA, RBAC, vulnerability management).
- Go and check: verify controls independently rather than relying on assertions; if something looks wrong, investigate and resolve it.
- Support site reliability and resilience initiatives
Awareness & Security Culture
- Build engaging security awareness training that changes behaviour, not just completion rates.
- Act as a visible, approachable point of contact for information security questions to enable change across the business
- Translate security requirements into plain language for non-technical audiences without losing accuracy or impact., * Not a paper-only ISMS role or tick-box compliance exercise. The clear expectation here is you take hands-on ownership of effective controls, not just documentation.
- Not a technical incident response role. Security operations is handled separately.
- Not a bureaucratic or gatekeeping function. Our priority goal is to enable the business, not slow it down.
- Not a role for someone who prefers to escal… as a first port of call. We value/reward people who find the answer and move things forward.
- Not a ‘policing’ role. We focus on shared responsibility and enabling teams to move fast safely.
Requirements
- 5+ years in Information Security / ISMS operations.
- Ideally in med tech/ clinical or lifesciences
- Hands-on ISO 27001 exposur e - internal audit and management review experience.
- Experience with external audit from both certified bodies and clients
- Strong documentation and stakeholder-management discipline.
- Ability to translate technical controls into practical action.
- Familiarity with cloud security fundamentals
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.collegerecruiter.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
DC
Daniel Cranney
7 months ago
EM
Eli McGarvie
IT Salaries in UK
about 3 years ago
IK
Igor Khokhriakov
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
about 1 month ago
DC
Daniel Cranney
The Overflow: Security and Privacy
7 months ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
over 2 years ago
LM
Luis Minvielle
The Most Popular IT Jobs on the Market
over 2 years ago