The Role
You’ll work closely with security, technology and wider business stakeholders, with responsibilities including:
- Supporting the organisation’s ISO 27001 ISMS, including maintaining policies, controls and supporting evidence
- Working with security frameworks including ISO 27001, NIST CSF and CIS Controls
- Conducting and maintaining information security risk assessments
- Managing security risks, controls, actions and remediation plans
- Supporting internal and external security audits and assessments
- Reviewing existing security controls and identifying areas for improvement
- Maintaining security policies, standards, procedures and governance documentation
- Supporting third-party and supplier security assessments
- Tracking compliance against relevant security frameworks and organisational requirements
- Working with technical teams to ensure security controls are implemented effectively
- Producing security reporting, metrics and governance information for stakeholders
What We’re Looking For: You’ll ideally have:
- Strong commercial experience within GRC, Information Security or Cyber Security
- Good working knowledge of ISO 27001
- Experience working with NIST, ideally NIST CSF
- Practical experience of security risk management and control assessments
- Experience supporting security audits and compliance activity
- Strong understanding of security policies, governance and assurance
- Experience working with technical and non-technical stakeholders
- The ability to take ownership of GRC activity rather than purely providing administrative support
- Experience with Microsoft security tooling would be highly desirable, particularly: Microsoft Purview, Microsoft Defender, Microsoft Sentinel, Microsoft Entra ID, Microsoft 365 and Azure security/compliance controls
- Relevant certifications such as ISO 27001 Lead Implementer/Auditor, CISM, CRISC, CISSP or equivalent would be beneficial but aren't essential.