Job Search and Career Advice Platform

Enable job alerts via email!

Information Security and Compliance Lead

HCRG Care Group

Birmingham

On-site

GBP 50,000 - 55,000

Full time

Today
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading health and care services provider in the United Kingdom is looking for an Information Security & Compliance Lead to enhance their governance over digital environments. This role involves ensuring compliance with various standards, collaborating across departments, and maintaining an effective Information Security Management System. The ideal candidate will have a strong background in information security principles, compliance frameworks, and risk management. Competitive salary range of £50,000 to £55,000, along with several benefits including private medical insurance.

Benefits

Competitive salary
Private medical insurance
Access to wages as you earn
Online wellbeing support
Wellbeing support for mental and physical health
Learning and professional development opportunities
Innovative work culture

Qualifications

  • Strong understanding of information security principles, applicable in compliance contexts.
  • Hands-on experience with frameworks like DSPT and Cyber Essentials Plus.
  • Proficient in reviewing controls and producing mitigation plans.
  • Strong documentation skills for policies and procedures.

Responsibilities

  • Support the delivery of secure infrastructure services.
  • Contribute to the maintenance of the ISMS.
  • Monitor compliance with security frameworks.
  • Support internal and external audits and assurance reviews.

Skills

Information security principles
Compliance with DSPT
Risk assessment
Documentation skills
Cloud environment compliance

Education

Relevant professional certifications

Tools

EDR
SIEM
Job description

We're looking for a motivated and detail-driven Information Security & Compliance Lead to help us strengthen the way we govern, protect and assure our digital environment. You'll play a key role in ensuring our systems, services and processes meet the national standards and regulatory expectations we work to, including DSPT, Cyber Essentials Plus and the Cyber Assessment Framework. Working closely with our Head of Information Security & Enterprise Architecture, you'll provide senior support across policy development, assurance activity, supplier governance and risk management. You'll help us maintain a robust and well‑evidenced Information Security Management System (ISMS), ensuring our approach to compliance is consistent, well‑structured and embedded across the organisation.

Responsibilities
  • Support the delivery and monitoring of secure infrastructure services across cloud, on‑premises and hybrid environments
  • Ensure security and compliance controls are applied consistently across networks, servers, endpoints and backup environments
  • Contribute to the maintenance of the Information Security Management System (ISMS), including policies, procedures and risk registers
  • Support internal and external audit activity, evidence gathering and assurance reviews
  • Monitor compliance with frameworks such as DSPT, Cyber Essentials Plus (CE+) and the Cyber Assessment Framework (CAF)
  • Provide clear, practical security and compliance input for supplier reviews, contract renewals and new technology onboarding
  • Support incident management processes, including root cause analysis and follow‑up improvements
  • Contribute to business continuity and disaster recovery planning with relevant technical teams
  • Collaborate closely with Infrastructure, Service Operations, Business Systems and Transformation teams to embed secure‑by‑design principles across services and projects
  • Share guidance, raise awareness and promote good security and compliance practices across the organisation
Benefits
  • £50,000 – £55,000 with group pension
  • Private medical insurance with fast access to specialist support, including musculoskeletal and mental health services, available at locations across the UK
  • Membership of My Reward Hub, giving you discounts on everyday purchases such as groceries, plus cashback and voucher offers for you and your loved ones
  • Access to your wages as you earn them, helping you manage unexpected expenses without high interest or overdraft fees
  • Online and face‑to‑face wellbeing support for both mental and physical health, from healthy recipes and activity challenges to counselling, trauma support, career coaching and more
  • Access to eLearning, bespoke career pathways and professional development through our Outstanding Learning Enterprise team
  • An open, supportive culture where your ideas and contributions can shape how we deliver our purpose: changing lives through transforming health and care, supported by at least £100,000 of ringfenced innovation funding each year
  • The pride of working for an organisation committed to the highest clinical and quality standards, with the majority of our services rated "Good" or "Outstanding" by the Care Quality Commission
Qualifications
  • Strong understanding of information security principles, with the ability to apply them in a compliance and governance context
  • Hands‑on experience supporting compliance with frameworks such as Data Security and Protection Toolkit (DSPT), Cyber Essentials Plus (CE+) and Cyber Assessment Framework (CAF) or ISO 27001
  • Confident reviewing controls, assessing risks, and producing clear, well‑evidenced mitigation plans
  • Familiarity with public sector or NHS data protection responsibilities, including GDPR and NHS Data Security Standards
  • Experience contributing to incident response and ensuring that lessons learned are properly documented and embedded
  • Strong documentation skills – able to produce accurate policies, procedures, risk records and audit evidence
  • Comfortable working with Infrastructure, Service Operations and Transformation teams to ensure security and compliance requirements are understood and built in from the start
  • Able to work effectively with auditors, suppliers and governance groups, presenting information clearly and professionally
  • Experience working within private cloud or hybrid environments, particularly where compliance requirements vary across services
  • Familiarity with toolsets such as EDR, vulnerability scanning, SIEM or MDM, particularly in relation to evidence gathering and assurance reporting
  • Relevant professional certifications (e.g., Security+, SSCP, ISO 27001, CISMP, CISSP Associate)
  • Understanding of backup and disaster recovery security principles, including compliance considerations
We change lives by transforming health and care.

Established in 2006 we are one of the UK's leading independent providers of community health and care services, working with health and care commissioners and communities to transform services with a focus on experience, efficiency and improved outcomes. We deliver and transform adult and children community health services, primary care services including urgent care, sexual health, dermatology and MSK services as well as adult social care and wellbeing services. Across England, we support communities of many millions and directly help more than half a million people each year – guided by our simple values: we care, we think, we do.

We are committed to equal opportunities and welcome applications from a broad, diverse range of people who want to join our team. We are a Disability Confident Committed company, so we work to provide facilities, work environment adjustments and technical solutions to be as inclusive of everyone.

While it doesn't happen often, sometimes a role is very popular, and we'll need to close it earlier than the date we've shown here. If you're keen to join our team, we'd love to hear from you, so please apply as soon as you can. As you'd expect, safeguarding and protecting the children, young people and vulnerable adults that we work with is of the utmost importance; therefore we have policies and procedures in place to promote safeguarding and safer working practices and everyone who joins the team is subject to a safer recruitment process, including the disclosure of criminal records and vetting checks.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.