أبلاي إيدج ابدأ البحث عن عمل

Information Security Officer

TyneStack Ltd · Newcastle Upon Tyne, England, United Kingdom

قدّم وتابع مع أبلاي إيدج
Information Security Officer (GRC / ISO 27001 / Cyber Security)Location: Newcastle upon Tyne | Hybrid (3 Days Office / 2 Days Home)Type: Full-time, PermanentOverviewA leading financial technology organisation is looking to appoint an Information Security Officer to support the management and continuous improvement of information and cyber security across the business.This is a broad security role covering governance, risk, compliance, third party assurance and security controls across technology platforms, cloud services and business operations. You'll work closely with the Information Security Manager and stakeholders across the organisation to identify risks, strengthen controls and ensure security requirements are considered throughout technology and business change.The position offers exposure to a mature and evolving security environment, including ISO 27001, NIST, cloud security, supplier assurance and emerging technologies such as AI and automation. It would particularly suit someone with a solid grounding in information security who wants broad responsibility rather than specialising solely in one area.Key Responsibilities• Support the development and continual improvement of the Information Security Management System• Identify, assess, treat and report information security, cyber, technology and third party risks• Conduct security risk assessments, control reviews and assurance activities• Support compliance with FCA requirements, UK GDPR and relevant security standards• Implement and monitor controls aligned with ISO 27001, NIST and CIS frameworks• Provide security guidance across technology projects, cloud implementations and business change• Conduct supplier security due diligence and ongoing third party risk assessments• Support internal and external audits, regulatory reviews and certification activities• Develop and maintain security policies, standards and procedures• Support security governance around cloud, AI, automation and other emerging technologiesRequirements• 2+ years of commercial information or cyber security experience• Experience with information security governance, risk and compliance• Strong knowledge of ISO 27001 and recognised security frameworks such as NIST or CIS• Experience conducting security risk assessments and reviewing security controls• Understanding of cloud security and implementing security within cloud environments• Knowledge of security technologies including endpoint, data and mobile security• Understanding of SIEM, SOC, vulnerability management and threat intelligence capabilities• Strong communication skills with the ability to explain security risks to technical and non technical stakeholdersDesirable• CISSP, CISM, ISO 27001 or similar security certification• Experience within Financial Services or another regulated environment• Experience supporting or implementing an ISMS• Third party and supplier security assurance experience• Information Security, Information Systems or related degreeWhat’s on Offer• Competitive salary• Hybrid working with three days per week in Newcastle• Broad exposure across information and cyber security• Opportunity to work with ISO 27001, NIST, cloud security and emerging AI technologies• Exposure to a highly regulated financial technology environment• Opportunity to develop across security governance, risk, compliance and assuranceApplyIf you're an Information Security professional with experience across governance, risk and compliance and want a broad role where you can influence security across technology, cloud and business operations, apply now or get in touch for a confidential discussion.