Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.
Nuvion Tech is seeking a Cyber Security Lead to drive information security across GRC and technical domains in a hybrid Bedford setup. You will collaborate with Infrastructure, IT Operations and Software Engineering to strengthen security posture, lead audits and enhance ISMS/ISO 27001 compliance.
The role requires 5+ years in cyber/information security with strong GRC, audit and technical credibility, including vulnerability management, incident response, and supplier assurance.
Cyber Security | Information Security | GRC | ISO 27001 | ISMS | Security Audits | Infrastructure Security
Are you an experienced Cyber Security / Information Security professional with a technical background and strong GRC, ISO 27001 and security audit experience?
We're recruiting a Cyber Security Lead / Information Security Lead for a leading international SaaS software house, offering the opportunity to take broader ownership across Information Security, Cyber Security, GRC and security assurance.
The ideal candidate will have 5+ years' Cyber Security / Information Security experience, ideally having started within Infrastructure, Networks or Security Engineering before progressing into broader Information Security responsibilities.
Strong GRC and audit experience is essential. You'll need practical experience across ISO 27001, ISMS, internal/external security audits, risk management, policies, controls and compliance, combined with the technical credibility to work effectively with Infrastructure, IT Operations and Software Engineering teams.
Working closely with the Head of Information Security, you'll help strengthen the security posture of an international SaaS environment across Information Security, Cyber Security, GRC and technical security. You'll support and improve the ISMS and ISO 27001, lead/support security audits, risk and assurance activities, and work with technical teams across vulnerability management, patching, penetration testing, incident response and infrastructure security.
You'll also have involvement across supplier assurance, Cyber Essentials, business continuity, disaster recovery, DPIAs, BIAs, security policies and security awareness.
We're particularly interested in experience across:
The balance is important. We're not looking for a purely technical Security Engineer with limited GRC/audit exposure, or a purely compliance-led GRC candidate with limited technical understanding.
You may currently be working as an Cyber Security Lead, Information Security Lead, Senior Information Security Analyst, Senior Cyber Security Analyst, Information Security Consultant, Cyber Security Consultant, Technical Security Lead, Security Engineer or Infrastructure Security Engineer.
A great opportunity to join a leading international SaaS software business and step into a broader Information Security leadership position, combining your technical security background with greater ownership across GRC, ISO 27001, ISMS, audits and security strategy.
Bedford | Hybrid – 1–2 Days per Week in the Office