Information Security Officer

NSG Environmental
Buckshaw Village, UK
13 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
£30,000.0 - £35,000.0
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Databases Data Sharing Disaster Recovery Microsoft Office Vulnerability Analysis

Job description

The Information Security Officer supports the Information Security Manager in implementing, operating, maintaining and continually improving the company’s information security, cyber security, data protection and protective security arrangements., * Support the Information Security Manager in creating, reviewing, implementing and maintaining information security policies, standards, procedures and guidance.

  • Maintain controlled security records, registers, evidence and action logs, ensuring information is accurate, current and appropriately protected.
  • Support the maintenance of information risk registers by recording risks, controls, owners, actions, review dates and status updates.
  • Assist with information asset identification, classification, ownership and handling requirements, working with Information Asset Owners where required.
  • Monitor assigned actions arising from audits, assessments, incidents and management reviews, and escalate overdue or unresolved matters.

Security Assurance and Compliance

  • Coordinate and support internal security assurance activities, audits, control checks, vulnerability assessments and supplier or client information requests.
  • Collect, organise and retain objective evidence demonstrating compliance with company policies and applicable legal, regulatory and contractual requirements.
  • Support tender, pre-qualification and supplier-assurance submissions relating to information security, cyber security and data protection.
  • Identify potential non-conformities, control weaknesses and emerging risks, and report them promptly to the Information Security Manager.
  • Support business continuity, disaster recovery and security exercise planning, testing, record keeping and follow-up actions.

Incident Management

  • Receive, record, triage and promptly escalate suspected or actual information security, cyber security and data protection incidents in accordance with company procedures.
  • Assist investigations by preserving records and evidence, documenting timelines, coordinating actions and maintaining incident logs.
  • Support root cause analysis, corrective and preventive actions, lessons learned and verification that agreed remediation has been completed.
  • Maintain confidentiality and evidence integrity throughout incident handling.

Security Awareness and Support

  • Coordinate security and privacy awareness activities, induction content, refresher training, communications and completion records.
  • Provide first-line guidance to colleagues on approved security procedures and refer complex, high-risk or exceptional matters to the Information Security Manager.
  • Promote secure working practices and a positive security culture across the company.
  • Liaise professionally with internal teams, clients, suppliers and other stakeholders within the authority delegated to the role.

Data Protection Support

  • Support the Data Protection Lead and Information Security Manager with the company’s data protection framework and associated records.
  • Maintain the Record of Processing Activities, data protection action logs, privacy documentation and retention records as directed.
  • Coordinate administrative and evidence-gathering activities for Data Protection Impact Assessments, data subject rights requests, personal data breaches, data-sharing arrangements and international transfer assessments.
  • Escalate data protection queries, potential breaches and matters requiring legal, regulatory or risk acceptance decisions to the Data Protection Lead and Information Security Manager.
  • Support privacy awareness and training activities.

General

  • Comply with NSG company procedures and policies and maintain the confidentiality, integrity and availability of information handled in the role.
  • Prepare accurate reports, metrics and briefing material for review by the Information Security Manager.
  • Maintain professional competence through relevant learning and continuing professional development.
  • Display a professional attitude and image in all work undertaken on behalf of NSG Environmental Ltd.

Requirements

  • Degree desirable, A Level qualifications or equivalent in an IT related subject - Essential
  • IOSH Managing Safely or Level 2 Health & Safety in the Workplace or equivalent - Relevant training will be provided if required, * Well organised with the ability to manage multiple tasks, work to deadlines and demonstrate a high level of attention to detail - Essential
  • Experience of maintaining accurate records, registers and documentation within a controlled environment - Essential
  • Experience handling confidential and sensitive information with discretion and integrity - Essential
  • Experience of routine recording, reporting and analysis of information, including both written, verbal and numerical data - Essential
  • Knowledge of UK GDPR, Data Protection Act 2018, Information Security principles or related compliance frameworks - Essential
  • Familiar with integrated management system operating procedures and requirements etc. - Desirable
  • Understanding of government security classifications and the handling of classified information - Desirable, * Competent user of MS Office - Essential
  • Able to organise and prioritise own work - Essential
  • Maintenance of database and physical records and files - Desirable
  • Ability to communicate with a wide range of colleagues at all levels and with external stakeholders and contractors - Desirable, * Do you have a Degree, A Level qualifications or equivalent in an IT related subject?

About the company

NSG Environmental Ltd has been delivering work programmes in the nuclear industry for over 40 years. Traditionally in the areas of decommissioning and waste management, NSG now has a broad customer base and provides a wide spectrum of services across the nuclear project lifecycle, ranging from expert consultancy support, R&D and engineering design to rekit and refurbishment, site installation services and high-hazard physical decommissioning works, amongst others. This work is delivered at NSG’s own offices and purpose-built facilities and nuclear sites across the UK. The delivery and management of these projects and programmes of work is carried out by a skilled workforce composed of both white-collar and blue-collar personnel in technical, administrative, and physical roles.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

4:01 min

Managing application isolation via pluggable database models

Wei Hu Wei Hu · World Congress 2022

3:18 min

Utilizing AI and public data sharing for urban planning

Christian Wiegand +3 · World Congress 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

Videos

See all

Related articles

See all