Enable job alerts via email!

Information Security and Assurance Advisor

Concept Information Technology

England

On-site

GBP 40,000 - 70,000

Full time

Yesterday
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking an Information Security and Assurance Advisor to provide expert guidance on information assurance, security, and risk management. This permanent role involves developing policies for compliance with national standards and conducting audits to ensure security across the organization. The successful candidate will work collaboratively with internal and external stakeholders, providing professional advice and support on data protection and security-related matters. If you are passionate about information security and eager to make a significant impact, this opportunity is perfect for you.

Qualifications

  • Expertise in information assurance and risk management.
  • Recognized qualifications in information security or data protection.
  • In-depth understanding of security frameworks like ISO 27001.

Responsibilities

  • Provide guidance on information assurance and security.
  • Conduct audits and compliance checks for security standards.
  • Coordinate investigations into security incidents and recommend actions.

Skills

Information Security
Risk Management
Data Protection
Compliance Audits
Stakeholder Engagement
Communication Skills

Education

A Levels or equivalent
CISM, CISSP, CRISC, BCS DPO

Tools

ISO 27001
NIST

Job description

Social network you want to login/join with:

Information Security and Assurance Advisor, Warwickshire

col-narrow-left

Location:

Warwickshire, United Kingdom

Job Category:

Information Technology

EU work permit required:

Yes

col-narrow-right

Job Reference:

BBBH75954_1745571910

Job Views:

6

Posted:

25.04.2025

Expiry Date:

09.06.2025

col-wide

Job Description:

Information Security and Assurance Advisor
Leek Wootton

Permanent opportunity

JOB PURPOSE:

To provide expert guidance and specialist advice on all aspects of information assurance, security, and risk management. The role ensures the development and implementation of relevant policies, procedures, and processes necessary for compliance with national standards and codes of connection for information systems.

This role includes maintaining the Information Security Incident Register, coordinating investigations into reported incidents, and recommending corrective measures to prevent recurrence.

The postholder will also undertake onsite audits of facilities and assessments of third-party suppliers to ensure compliance with expected security and assurance standards.

Additionally, the role supports departments with completing Data Protection Impact Assessments and offers professional advice on information assurance and security-related matters.



MAIN RESPONSIBILITIES:

1 Support the Information Security and Assurance programme to ensure assurance and compliance processes meet national standards and reporting requirements (e.g. SyAP).
2 Develop, review, and implement policies and best practices for managing information and cyber security, in alignment with organisational needs.
3 Establish and apply techniques to regularly assess compliance of information assets with legal, regulatory, and best practice requirements.
4 Serve as a point of contact for queries on information security and assurance.
5 Plan and conduct information security audits and compliance checks, ensuring the security of systems, data, and physical assets across the organisation and third-party entities.
6 Identify and assess security requirements, producing Risk Assessment Reports and reviewing related documentation for new or evolving systems, assets, and processes.
7 Coordinate the investigation and reporting of information security incidents, ensuring appropriate remedial action is taken and trends are monitored.
8 Prepare and deliver training, education, and awareness sessions related to information security, assurance, and risk management.
9 Work collaboratively with key internal and external stakeholders—including third-party suppliers—ensuring best practices and compliance with relevant legislation and standards.
10 Stay informed on developments in legislation, practices, and tools related to information security and data protection, fostering continuous improvement and innovation.
11 Represent the organisation in internal and external meetings, promoting information security standards and contributing to relevant partnerships and working groups.
12 Perform other duties as appropriate to the nature and level of the role.



Regular travel across operational areas may be required.


PERSON SPECIFICATION

Knowledge:

* A Levels or equivalent.
* Recognised qualification in information security, data protection, or risk (e.g. CISM, CISSP, CRISC, BCS DPO, etc.).
* In-depth understanding of ISO 27001, NIST, or other relevant security frameworks.
* Up-to-date knowledge of data protection legislation and associated best practices.
* Understanding of cross-functional areas affecting security (e.g. HR, procurement, tech infrastructure).
* Familiarity with principles of information confidentiality, integrity, and availability.

Experience:

* Operational delivery of security assurance in a multi-site environment.
* Managing compliance with standards like PSN or SyAP.
* Developing and enforcing information security and assurance policies.
* Performing internal audits and managing accreditation processes.
* Facilitating high-level stakeholder engagement.
* Collaborating with external agencies and partners on security issues.

Key Skills:

* Ability to manage workloads, meet deadlines, and adapt to changing priorities.
* Strong communication and interpersonal skills for influencing and explaining complex topics.
* Discretion and professionalism when handling sensitive information.
* Capability to work independently on complex investigations.

Job Requirements:

Knowledge:* A Levels or equivalent.* Recognised qualification in information security, data protection, or risk (e.g. CISM, CISSP, CRISC, BCS DPO, etc.).* In-depth understanding of ISO 27001, NIST, or other relevant security frameworks.* Up-to-date knowledge of data protection legislation and associated best practices.* Understanding of cross-functional areas affecting security (e.g. HR, procurement, tech infrastructure).* Familiarity with principles of information confidentiality, integrity, and availability.Experience:* Operational delivery of security assurance in a multi-site environment.* Managing compliance with standards like PSN or SyAP.* Developing and enforcing information security and assurance policies.* Performing internal audits and managing accreditation processes.* Facilitating high-level stakeholder engagement.* Collaborating with external agencies and partners on security issues.Key Skills:* Ability to manage workloads, meet deadlines, and adapt to changing priorities.* Strong communication and interpersonal skills for influencing and explaining complex topics.* Discretion and professionalism when handling sensitive information.* Capability to work independently on complex investigations.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.