> Markdown version of [/jobs/ext/3296211-information-security-officer](https://www.wearedevelopers.com/jobs/ext/3296211-information-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Officer - **Company:** Buckinghamshire New University - **Location:** High Wycombe, UK - **Salary:** £38,784.0 - £43,482.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cyber Security, Information Systems, Disaster Recovery, Intrusion Detection and Prevention, Microsoft Security Essentials, PCI Data Security Standards, Cloud Services, Information Security Management System, Cybercrime, Vulnerability Analysis - **Published:** September 3, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=a1d4721b63eac913 ## About the Role Professionally qualified with a relevant degree/postgraduate qualification or relevant vocational, strategic management and leadership experience A Relevant information security qualification (or working towards) such as CISSP or CISM, or Security+ A Substantial experience in a security-focused role, with a proven track record of managing security risks and controls A Knowledge & Experience Knowledge of regulatory and statutory compliance requirements e.g. Data Protection Act 2018, UK GDPR, PCI-DSS A/I Experience with security certifications and audits e.g. ISO 27001 and Cyber Essentials or similar information security standards A/I Previous experience in a role that includes an element of detecting and responding to security incidents and the collection and use of threat intelligence ideally within exposure to Higher Education or Public Sector environments A/I Demonstrable knowledge and experience of information risk management and information assurance. A Experience writing formal reports including audit and compliance review findings on data and information systems. A/I Good underlying knowledge of Microsoft security tools and platforms as evidenced by technical or professional qualifications and work experience., Powers of influence and negotiation to secure the prioritisation of resources and workload from other areas of the University I Ability to plan, prioritise and organise own work and resources and leading / guiding others, whilst anticipating problems and planning workable solutions I Communication, persuasion and presentation skills to motivate an organisation to change its culture and to lead people change projects I Ability to explain complex technical information to non-technical audiences and convey complex information in clear ways to a range of audiences, As cyber threats occur at any time, this position requires a willingness to work out of hours/weekend working and emergency incident response., Working collaboratively and across boundaries with others in order to achieve objectives. Recognising and valuing the different contributions people bring to this process. ## Description To maintain a good understanding of cyber security technologies, IT security operations and cyber security controls to improve the University's cyber security posture and drive key information security initiatives. To have a broad understanding of information security and cyber security frameworks, standards and policies to help build and deliver the University's information and cyber security strategies. Undertake a range of audit and assurance activities including technology management; policy development and documentation; testing, monitoring and management of security controls; risk evaluation of threat information; consultative engagements; project-work; and reporting., * Provide governance and assurance to the wider CIO Group and University by supporting the Head of Information Assurance in developing, delivering and auditing against the information governance framework. * Work closely with the Infrastructure and Operations Teams to review the existing global architecture (including infrastructure and cloud services), identify design gaps, and recommend enhancements to cyber security controls and implement any agreed improvements so that the University's data and information systems are secured. * Serve as an internal information and cyber security subject matter expert and lead operational security activities including security monitoring, threat detection, security event management, endpoint security, identity security and oversight of managed security service providers. * Develop, validate, maintain and regularly test all information security, cyber security, disaster recovery and business continuity plans, process and procedures. * In collaboration with the CIO assist with the design and development of the cyber security strategy and recommendations for new cybersecurity systems. * Work with the wider CIO Group to execute regular vulnerability assessments and coordinate external penetration testing to identify data protection, cyber security and other compliance risks and present recommendations for mitigating the risks in the immediate term and provide guidance on plans to manage the risk long term. * Maintain the University's information security risk register, ensuring risks are assessed, tracked, reviewed and reported to appropriate governance forums. Assist departments with risk assessments and developing appropriate management and mitigation strategies to avoid reputational and financial damage to the University. * Lead all investigations related to security incidents, including analysis of impact, resolution, cause, prevention and subsequent remediation as required by the University's Incident Response procedures. This includes ensuring there is adequate out of hours and emergency incident response cover. * Develop and monitor security KPIs to assess the effectiveness of controls and present regular security reporting, risk assessments and assurance updates to leadership, governance committees and external auditors. * Take advice from our third-party security partners and maintain a high level of knowledge about information, cyber security and privacy regulations, new security risks and protocols, and new security technology solutions. * Assist in the development, review, and consultation of information and cyber security policies, standards, and guidelines in line with industry best practices and the University's needs, ensuring that compliance is enforced through the satisfactory completion of regular internal and external audits. * Support the development and maintenance of the University's ISMS, ensuring compliance with legislation e.g. Data Protection Act 2018 and UK GDPR; standards, such as ISO 27001, ISO 22301 and PCI-DSS; and frameworks including Cyber Essentials. * Help create a positive security culture across the University through engagement activities, awareness campaigns, training and leadership engagement by promoting the University's information and cyber security policies and procedures to all staff and serving as the primary point of contact for associated issues across the institution. * Deliver the University's information security awareness programme to promote awareness of the processes, policies and technical solutions in place to protect the confidentiality, integrity and availability of data by maintaining training materials, promoting participation, and monitoring its effectiveness. * Perform line management responsibilities including recruitment and selection, performance management, professional development, motivation, health and safety, and wellbeing. * Comply with relevant legislative and other requirements (e.g., the Data Protection Act 2018 and UK GDPR; Health and Safety; UKVI; and Equality and Diversity) in all working practices * Perform such other duties temporarily or on a continuing basis, as may reasonably be required. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [UK Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/326-uk-business-culture-and-etiquette) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)