> Markdown version of [/jobs/ext/2820499-information-security-specialist](https://www.wearedevelopers.com/jobs/ext/2820499-information-security-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Specialist - **Company:** deciphex - **Location:** Kidlington, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cloud Computing Security, Cyber Security, Data Governance, DevOps, Multi-Factor Authentication, Role-Based Access Control, Reliability Engineering, Security Information and Event Management, Software Vulnerability Management, Information Security Management System - **Published:** September 10, 2026 - **Apply:** https://www.collegerecruiter.com/job/2833343141-information-security-specialist ## About the Role * 5+ years in Information Security / ISMS operations. * Ideally in med tech/ clinical or lifesciences * Hands-on ISO 27001 exposur e - internal audit and management review experience. * Experience with external audit from both certified bodies and clients * Strong documentation and stakeholder-management discipline. * Ability to translate technical controls into practical action. * Familiarity with cloud security fundamentals ## Description * You'll report to and work closely with the Information Security Lead, as well as Cybersecurity Engineering, DevOps, IT, Data Governance, and AI Governance to embed secure-by-design practices across the organisation., * Information security underpins all of our business activities, including AI development * and compliance with Medical Device regulations * This role is ideal for a hands-on security specialist who supports the ISMS, validates controls for themselves, and drives continuous improvement with energy and pragmatism. * This role moves away from traditional GRC and leans into modernising it - moving teams towards always-on compliance and consistently demonstrating business value in the activities we run. * You'll work across the business as someone who meets challenges head-on, brings people with them, and makes security work in practice, not just on paper., * This role involves protecting systems and data that directly support cancer diagnostics and drug development, security work with real-world consequence. * This is a hands-on, delivery-focused role suited to someone who thrives in a very fast-moving environment. * Success requires a pragmatic approach, strong judgement, and the ability to navigate challenges, remove obstacles, and drive progress at pace. ISMS & Certifications * We hold ISO 27001 certification across our core business units and are expanding coverage as we grow. * Support the day-to-day running of the ISO 27001 ISMS across our Deciphex business units (Deciphex, Diagnexia & Patholytix) * Prepare for internal and external audits so that teams are ready, controls are functioning, and evidence is complete. Audit readiness as a steady state. * Contribute to continuous improvement initiatives. Iidentify what needs to change, make the case, and see it through. * Proactively identify and close gaps in the control framework, driving corrective actions (CAPAs) to closure * Build and maintain a reliable evidence pipeline with clear ownership and high completeness. * Assess which ISMS activities deliver measurable business value - and be willing to challenge or retire processes that aren't. Security Governance & Risk * Maintain a live, decision-oriented risk register with owners and mitigation plans. * Champion a risk-aware culture where decisions are informed by risk, not paralysed by it. * Develop and maintain policies and procedures that reflect how the business actually operates (not a unworkable bottleneck) * Support vendor and customer security due diligence in support of commercial and product needs. * Contribute to tabletop exercises (e.g. incident response, business continuity) * Maintain awareness of applicable regulatory requirements (EU AI Act, GDPR, HIPAA, MDR/IVD) and ensure the ISMS remains aligned with our other Certifications and Standards Technical Oversight * Define evidence expectations for technical controls (SIEM, EDR, MFA, RBAC, vulnerability management). * Go and check: verify controls independently rather than relying on assertions; if something looks wrong, investigate and resolve it. * Support site reliability and resilience initiatives Awareness & Security Culture * Build engaging security awareness training that changes behaviour, not just completion rates. * Act as a visible, approachable point of contact for information security questions to enable change across the business * Translate security requirements into plain language for non-technical audiences without losing accuracy or impact., * Not a paper-only ISMS role or tick-box compliance exercise. The clear expectation here is you take hands-on ownership of effective controls, not just documentation. * Not a technical incident response role. Security operations is handled separately. * Not a bureaucratic or gatekeeping function. Our priority goal is to enable the business, not slow it down. * Not a role for someone who prefers to escal... as a first port of call. We value/reward people who find the answer and move things forward. * Not a 'policing' role. We focus on shared responsibility and enabling teams to move fast safely. ## Related Videos - [Data Governance in the Era of AI](https://www.wearedevelopers.com/videos/1622-data-governance-in-the-era-of-ai) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)