Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
Buckinghamshire New University is hiring an Information Security Officer to strengthen our information security and compliance programme. You will lead ISMS improvements, manage security incidents, and shape information security policies and controls.
The role offers hybrid working and is based at High Wycombe Campus with flexi-hours. You will drive risk management, collaborate with IT operations, and provide expert guidance to embed security into decision-making and service delivery across the
We're not trying to fit in with the higher education status quo. We're challenging it. We're doing things differently - because our students, our staff, and our world need us to.
So this is an exciting moment to join us. We're boldly reimagining what a university can be: a place rooted in social mobility, a community where difference is celebrated, and an institution that empowers people to become more than they thought possible.
Buckinghamshire New University is seeking a proactive and ambitious Information Security Officer to help shape and strengthen our information security and compliance programme. Working within the Information Assurance team, you will play a key role in protecting the University's information assets, managing security risks, and embedding a strong security culture across the organisation.
You will lead the continual improvement of our Information Security Management System (ISMS), support the management of security incidents, drive compliance activities, and develop information security policies, standards and controls. You will also contribute to strategic projects, maintain oversight of information security risks and assets, and provide expert advice to colleagues to ensure security is embedded in decision-making and service delivery.
This is an opportunity to make a meaningful impact in a university committed to transforming lives through education. We welcome applications from all backgrounds and are committed to an inclusive and supportive workplace.
If you have the qualities and attributes representative of the University's values and ambition, we would be delighted to hear from you.
For further information about this role please contact jenny.horwood@bnu.ac.uk
We are committed to promoting an inclusive and diverse workplace and aim to continue building an environment where everyone thrives and can be themselves.
Please let us know if you require any adjustments or support during the recruitment process. We are happy to discuss any reasonable adjustments that would enable you to perform to the best of your abilities in your role. Please reach out to people@bnu.ac.uk if you have any specific needs or if you would like more information on how we can support you
We ensure that our interview/shortlisting Chairs complete the relevant e-learning and/or inclusive recruitment training.
If you're considering using AI to support your application, we encourage you to question the value it adds. The use of AI tools sometimes erodes authenticity and prevents us from being able to assess the real you. We strongly recommend you prepare your application using your own skills and knowledge and that AI is only used for the purpose of review.
If you are invited to interview for this role, you will need to provide evidence of your eligibility to work in the UK and if on a visa, current visa and status. Sponsorship is dependent on the salary level of the position.
BNU is a Disability Confident employer and as such you will be given the opportunity to declare a disability as part of the application process.
Job Title: Information Security Officer
Faculty/Directorate: CIO Group
Grade: G
Location: High Wycombe
Hours: 37
Responsible to: Head of Information Assurance
Responsible for: Information Assurance and Security Analyst
To maintain a good understanding of cyber security technologies, IT security operations and cyber security controls to improve the University's cyber security posture and drive key information security initiatives.
To have a broad understanding of information security and cyber security frameworks, standards and policies to help build and deliver the University's information and cyber security strategies.
Undertake a range of audit and assurance activities including technology management; policy development and documentation; testing, monitoring and management of security controls; risk evaluation of threat information; consultative engagements; project-work; and reporting.
Professionally qualified with a relevant degree/postgraduate qualification or relevant vocational, strategic management and leadership experience
A
Relevant information security qualification (or working towards) such as CISSP or CISM, or Security+
A
Substantial experience in a security-focused role, with a proven track record of managing security risks and controls
A
Knowledge of regulatory and statutory compliance requirements e.g. Data Protection Act 2018, UK GDPR, PCI-DSS
A/I
Experience with security certifications and audits e.g. ISO 27001 and Cyber Essentials or similar information security standards
A/I
Previous experience in a role that includes an element of detecting and responding to security incidents and the collection and use of threat intelligence ideally within exposure to Higher Education or Public Sector environments
A/I
Demonstrable knowledge and experience of information risk management and information assurance.
A
Experience writing formal reports including audit and compliance review findings on data and information systems.
A/I
Good underlying knowledge of Microsoft security tools and platforms as evidenced by technical or professional qualifications and work experience.
A/I
Powers of influence and negotiation to secure the prioritisation of resources and workload from other areas of the University
I
Ability to plan, prioritise and organise own work and resources and leading / guiding others, whilst anticipating problems and planning workable solutions
I
Communication, persuasion and presentation skills to motivate an organisation to change its culture and to lead people change projects
I
Ability to explain complex technical information to non-technical audiences and convey complex information in clear ways to a range of audiences
I
As cyber threats occur at any time, this position requires a willingness to work out of hours/weekend working and emergency incident response.
A/I
Willingness to work a rota-based shift pattern and undertake on-call duties when required.
A/I
The BNU Behaviours Framework (BBF) is a framework for all University staff that sets out the key behaviours that exemplify the values and ethos of the University. .
Taking a holistic view and working enthusiastically to analyse problems and to develop workable solutions. Identifying opportunities for innovation.
Identifying and making the most productive use of resources including people, time, information, networks and budgets.
Working collaboratively and across boundaries with others in order to achieve objectives. Recognising and valuing the different contributions people bring to this process.