Information Security Lead

SSA Digital Recruitment
Northampton, UK
3 days ago
Apply on www.adzuna.co.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
£65,000.0 - £70,000.0
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Cyber Security Disaster Recovery Information Technology Operations Software Engineering Software Vulnerability Management Information Security Management System Patch Management

Job description

  • Youll work closely with our Head of Information Security to maintain and continually improve our Information Security, GRC, and compliance environment.
  • Youll take ownership across ISO 27001, our ISMS, security audits, risk assessments, policies and controls, customer assurance, supplier security, audit remediation, Cyber Essentials, and wider certification activities.
  • Youll collaborate with technical teams on vulnerability management, patching, penetration testing, incident response, Business Continuity, and Disaster Recovery.
  • Youll help ensure security risks and audit findings lead to practical improvements.

Technologies:

  • Network
  • Security
  • Support

Requirements

  • Were looking for strong hands-on experience in GRC, ISO 27001, security audits, and Information Security, alongside a technical understanding of Cyber Security.
  • We expect experience operating and improving an ISMS, supporting ISO 27001, managing security risks and controls, and working with internal audits, external certification audits, customer assurance, and supplier security.
  • Were particularly interested in experience with security governance, risk management, policies, compliance, audit evidence and remediation, vulnerability management, penetration testing, patch management, incident response, Cyber Essentials, business continuity, disaster recovery, DPIAs, BIAs, and third-party risk.
  • Ideally, youll have developed your career from an IT, infrastructure, network, or technical Cyber Security background before moving into broader Information Security and GRC.
  • Wed ideally like you to have 5+ years experience across Information Security, Cyber Security, GRC, IT Risk, Compliance, or Security Assurance.
  • Were open to Information Security Leads, GRC Leads, Senior Information Security Analysts, Senior Cyber Security Analysts, Information Security Consultants, IT Risk and Compliance professionals, and Security Engineers with substantial GRC and audit experience.
  • Were looking for someone with enough technical understanding to work credibly with Infrastructure, IT Operations, and Software Engineering teams, as well as communicate about audit findings, risk, and ISO 27001 controls with senior stakeholders.

Benefits & conditions

Were a leading international SaaS software business offering the opportunity to take broader ownership across Information Security, GRC, audit, and Cyber Security. This is a permanent Information Security Lead / Cyber Security Lead role based in Bedford, with a salary of £60,000-£70,000 plus excellent benefits. The posting describes the hybrid arrangement as 1-2 office days per week in one section and 3 office days with 2 remote days in another.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.co.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:14 min

Crafting an effective disaster recovery and communication plan

Mihaela-Roxana Ghidersa · LIVE

2:25 min

Automating builds and getting involved with z/OS Open Tools

Igor Todorovski · World Congress 2023

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

4:40 min

Defining software resilience and layers of system architecture

Sander ten Brinke Sander ten Brinke · World Congress 2025

Videos

See all

Related articles

See all