Job Search and Career Advice Platform

Enable job alerts via email!

Information Security Officer

Form3

Greater London

Hybrid

GBP 70,000 - 90,000

Full time

Yesterday
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A technology firm in Greater London is seeking an experienced Information Security Officer to enhance its security governance, risk, and compliance practices. The role involves applying extensive security framework knowledge, conducting audits, and fostering a strong security culture. Candidates should have at least 5 years in Information Security and relevant certifications. The position requires a collaborative mindset with excellent communication skills, allowing for impactful engagement across teams. This is primarily an on-site role with some remote flexibility.

Benefits

Flexible working arrangements
Commuting support
Professional development opportunities

Qualifications

  • Proven experience developing, implementing, and improving information security policies.
  • Hands-on experience with audits and risk assessments.
  • Strong working knowledge of ISO and NIST frameworks.

Responsibilities

  • Apply expert knowledge of security frameworks to support governance.
  • Support ISMS and BCMS development.
  • Monitor adherence to security controls via risk assessments.

Skills

Analytical mindset
Strong communication skills
Stakeholder engagement
Hands-on experience in audits
Experience with vulnerability management

Education

5 years in Information Security
Security certifications (CISSP, CISM, CISA)

Tools

GRC tooling
ISO27001 framework
NIST framework
Job description
THE ROLE

AsanInformation Security Officer at Form3youllplay a pivotal role in strengthening and evolving our information security governance risk and compliance practices. Working within the Information Security teamyoullhelp ensure that Form3 continues tooperatesecurely andmaintainthe trust of our customers and partners.

Youllwork closely with teams across the organisationfrom Engineeringand Product toLegaland Riskteamsto embed security into business and technology decisions. This is a hands-on role that combines strategic oversight with practical execution ensuring our controls frameworks and awareness initiativesremainindustry leadingas we scale globally.

Whatyoulldo
  • Apply expert knowledge of security frameworks and controls such as NIST ISO22301 ISO27001 ISO27017 / 18 ISAE3000 / SOC2 and GDPR to support security governance.
  • Support the development maintenance and continual improvement of the ISMS and BCMS.
  • Assist in drafting and maintaining Information Security Policies and ensure alignment with business and customer requirements.
  • Contribute to the planning and execution of external audits engaging directly with auditors and customers.
  • Monitor and report on adherence to security controls across all areas of the business via risk assessments and internal audits.
  • Assess and support the remediation of information security risks non-conformities and issues across systems and services.
  • Support vulnerability management processes from triage and tracking to remediation reporting in partnership with Offensive Security and Engineering teams.
  • Conduct vendor and third-party security assessments ensuring suppliers meet Form3's security and compliance requirements.
  • Partner with the Defensive Engineering team to ensure security requirements are built into product developments.
  • Deliver and enhance security awareness and training initiatives to promote a strong security culture across Form3.
  • Collaborate with the Security Operations team to maintain situational awareness of emerging threats and vulnerabilities ensuring timely escalation and risk-based response.
WERE LOOKING FOR

Form3s Information Security Governance Risk and Compliance (GRC) team plays a critical role in protecting the organisation sower looking for someone who is analytical collaborative and passionate about driving security on solving complex problems balancingdeeptechnicalknowledgewith strong governance principles and finding ways to make security scalable across a fast-moving cloud-native business.

Essential
  • 5 years experience in Information Security ideally within a fast-paced technology or financial services industry.
  • Strong working knowledge of frameworks such as ISO27001 ISO22301 SOC1 SOC2 NIST and GDPR.
  • Proven experience developing implementing and improving information security policies standards and controls aligned to recognised frameworks.
  • Hands‑on experience conducting audits risk assessments and business impact analyses.
  • Hands‑on experience with vulnerability management within a complex and dynamic cloud environment.
  • Broad understanding of cloud security.
  • Excellent communication and stakeholder engagement skills with the confidence to influence at all levels of the organisation.
  • Analytical mindset with a focus on continual improvement and measurable outcomes.
Desirable
  • Security-related qualifications such as CISSP CISM CISA or ISO27001 Lead Implementer / Auditor.
  • Experience leading certification and attestation programmes such as ISO27001 ISO22301 or SOC 2.
  • Experience operating in regulated or high‑availability environments such as financial services payments or critical infrastructure.
  • Familiarity with GRC tooling and automation to streamline compliance risk and control management activities.
THE TEAM

This role sits within Form3's Information Security Governance Risk and Compliance (GRC) team and reports directly to the Head of GRC. As part of a highly collaborative security function youll play a key role in shaping how Form3 manages information security risk compliance and assurance across all areas of the business.

The GRC team underpins Form3's security standards designing and maintaining the frameworks policies and controls that keep our people systems and customers safe. Joining at this stage offers the opportunity to make a significant impact strengthening governance and compliance across a cloud-native environment while helping define how security scales with the business.

Note :

This role requires attendance at our London office 12 days per month and therefore must be within a commutable distance to Londo n.

INTERVIEW PROCESS

Stage 1: Screening Call with Talent Team

Stage 2: Interview with Principal Security Officer

Stage 3: Interview with Head of GRC

We always aim to stick to the above process however there may be occasions when anadditionalinterview stage is needed for us to be surewerehiring the right person!

HIRING LOCATIONS

Weare able toaccept applications from theUKonly.

All new joiners start their first day in our office to collect the equipment needed to work remotely. Well also arrange for some of your team to come in to say hi ensuring youre supported and have a positive first few days with Form3!

ABOUT FORM3

Revolutionising the world of payments with ourcutting-edgetechnology and innovative solutions. For more information aboutlife atForm3 check out the following pages : What we do Life at Form3 Benefits Podcasts

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.