Information Security Officer
hace 7 días
Harrow
Information Security Officer\n\nLocation: Harrow, London\n Salary: Up to £40,000 per annum\n Job Type: Full-time\n Working Pattern: Office-based\n\nAbout the Role\n\nWe are seeking a proactive and detail-oriented Information Security Officer to join our team in Harrow. This is an excellent opportunity for someone with experience in information security, cyber risk, and compliance who is looking to play a key role in strengthening and maintaining a secure technology environment.\n\nReporting to senior leadership, the successful candidate will support the delivery of information security and cyber security initiatives across the organisation, including risk assessments, policy maintenance, security monitoring, audit support, incident management, and third-party risk reviews.\n\nKey Responsibilities\n\nSupport the delivery, documentation, and monitoring of information security and cyber security risk assessments for new and existing systems, technologies, and third-party vendors.\nMaintain risk registers, monitor identified vulnerabilities and threats, and track remediation and mitigation actions.\nReview and maintain information security and cyber security policies, procedures, and related documentation, ensuring timely updates and compliance.\nCoordinate and support security assessments such as vulnerability assessments, penetration testing, and related cyber security reviews.\nWork with internal IT/infrastructure teams to support implementation of security controls and secure configuration standards.\nLiaise with offshore teams and third-party providers on security, access, and risk-related matters where required.\nAssist with internal audits, external audits, and security assessments, helping to ensure compliance with regulatory and industry standards.\nPrepare risk assessment reports, management information, and key risk indicator dashboards.\nSupport the management and resolution of information security incidents, ensuring timely escalation and closure.\nContribute to improving the organisation's cyber security and information security maturity.\nSupport governance activities, committee reporting, and security-related documentation.\nAssist in the development and delivery of security awareness and staff training initiatives.\nReview supplier and vendor security questionnaires and assess third-party security risks.\nEvaluate the effectiveness of internal security controls and recommend improvements where necessary.\nUndertake additional tasks and project work related to systems, security, and operational risk as required.Skills and Experience Required\n\nPrevious experience in information security, cyber security, or technology risk management.\nGood understanding of cyber security risk, security controls, and information security governance.\nFamiliarity with risk management frameworks and security best practice.\nWorking knowledge of networking concepts, operating systems, and cloud platforms.\nExperience supporting audits, risk reviews, or compliance activities.\nStrong Microsoft Office skills, particularly Excel for analysis and reporting.\nAbility to produce clear reports, dashboards, and security documentation.\nExperience of working with internal stakeholders, offshore teams, and third-party suppliers would be advantageous.Qualifications\n\nCISSA qualification required\nCISM qualification requiredPersonal Attributes\n\nStrong analytical and problem-solving skills with excellent attention to detail.\nConfident communicator with the ability to explain technical risks to non-technical stakeholders.\nOrganised and able to manage multiple tasks effectively under pressure.\nSelf-motivated, adaptable, and willing to learn new systems, processes, and technologies.\nAble to work both independently and collaboratively as part of a wider team.\nFlexible approach to work, including occasional out-of-hours support where business needs require it.What We Offer\n\nSalary of up to £40,000\nOpportunity to work in a growing and security-focused environment\nExposure to a broad range of information security, cyber risk, and governance activities\nSupportive team environment with opportunities for professional developmentIf you have the relevant information security experience and qualifications and are looking for your next challenge in a hands-on security role, we would love to hear from you