Maxwell Bond

Information Security Officer

Maxwell Bond

Reading, England, United Kingdom (Hybrid) · Full Time

Be the first to apply

Experience
3+ yrs
Salary
GBP 55,000 – GBP 57,000 / year
Openings
1
Posted
5 days ago
Work mode
Hybrid
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About the Company

This opportunity is with a substantial, privately held technology distribution company operating throughout the UK and Europe. The organisation collaborates with leading global technology brands to provide hardware, software, and technology solutions via an extensive network of resellers, retailers, and commercial clients. Due to its expanding operations, the Information Security division is growing, creating an opening for a skilled Information Security Officer.

Role Overview

Reporting directly to the Director of Cyber Security, the successful candidate will engage with areas such as Information Security, Governance, Risk Management, and Compliance (GRC), Information Security Management System (ISMS), and security consultancy. The focus will be on practical application and assurance to raise the company's cyber security maturity, working closely with cross-functional technical and business teams, customers, suppliers, and external auditors to validate security controls and manage risks effectively.

Key Duties

  • Maintain and enhance the company's ISMS, including developing and updating security policies, procedures, and controls.
  • Assist in the deployment and management of compliance frameworks such as ISO 27001, Cyber Essentials Plus, PCI-DSS, and NIST/CIS Controls.
  • Carry out comprehensive security evaluations encompassing infrastructure, networks, endpoints, applications, and data.
  • Identify, evaluate, and handle information security risks; keep risk registers updated and monitor remediation efforts.
  • Lead and facilitate internal and external security audits by gathering evidence, testing controls, and addressing any identified gaps.
  • Oversee technical security risks within Data Protection Impact Assessments and exceptions to security policies.
  • Contribute to the vendor and third-party risk management program including assessing and monitoring critical suppliers continuously.
  • Collaborate with technical teams concerning identity and access management solutions, including Single Sign-On (SSO) and federated services.
  • Provide security validation and assurance for projects, systems, and client requirements.
  • Promote security awareness and support ongoing process improvements.
  • Prepare security metrics, reports, and dashboards for senior management review.
  • Participate in delivering aspects of the overall Security Improvement Plan together with the security team.
  • Engage with customers, suppliers, auditors, and other external parties on security matters.

Candidate Requirements

  • Minimum of three years' hands-on experience in information security, GRC, compliance, or security consultancy roles.
  • Proven practical experience implementing and managing ISO 27001 / ISMS, beyond theoretical understanding.
  • Experience conducting security audits, control assessments, risk evaluations, and follow-up remediation.
  • Familiarity with security frameworks and standards such as ISO 27001/27002, NIST, CIS Controls, PCI-DSS, and Cyber Essentials Plus.
  • Competence in creating and maintaining security policies and procedures.
  • Experience in managing third-party/vendor risk and delivering security assurance.
  • Understanding of cloud security concepts across platforms like Microsoft 365, Azure, AWS, or Google Cloud.
  • Strong interpersonal skills to collaborate effectively with technical teams, business units, and external stakeholders.
  • Qualifications in security such as CISSP, CISM, CISA, CCSP, ISO 27001 Lead Implementer/Auditor, or equivalent are beneficial.
  • A systematic and pragmatic approach to identifying and mitigating security risks.

Additional Information

This role is based on a hybrid working arrangement, requiring occasional visits to UK offices and meetings with customers, suppliers, and auditors. Applicants should ideally reside within roughly one hour's travel from Reading, England.

Location

Reading area, England, United Kingdom

Employment Type

Permanent full-time, onsite/hybrid work environment.

Salary

£55,000 to £57,000 annual basic salary.

How they work

Teamwork & Collaboration Attention to Detail Organisation Relationship Building

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer