Information Security Officer

Buckinghamshire New University

High Wycombe

On-site

GBP 39,000 - 43,000

Full time

8 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Hybrid working
Training & development support
Contributory pension scheme
Free gym membership
Staff discounts

Job summary

Buckinghamshire New University is hiring an Information Security Officer to strengthen our information security and compliance programme. You will lead ISMS improvements, manage security incidents, and shape information security policies and controls.

The role offers hybrid working and is based at High Wycombe Campus with flexi-hours. You will drive risk management, collaborate with IT operations, and provide expert guidance to embed security into decision-making and service delivery across the

Qualifications

  • Professionally qualified with a relevant degree or equivalent leadership experience.
  • Security qualifications such as CISSP, CISM or Security+ (working towards acceptable).
  • Substantial experience in a security-focused role with risk controls and audits.

Responsibilities

  • Develop, validate and maintain information security policies, standards, and controls.
  • Lead vulnerability assessments and coordinate external penetration testing.
  • Maintain ISMS and ensure compliance with Data Protection Act 2018 and UK GDPR; ISO 27001 & Cyber Essentials.
  • Lead investigations into security incidents and oversee incident response.
  • Promote security awareness and develop training to embed a positive security culture.

Skills

Influence & negotiations
Planning & prioritisation
Communication & presentation
Explain complex tech to non-technical
Willingness for rota/off-hours

Education

Relevant degree or equivalent leadership experience
Security qualifications (CISSP/CISM/Security+)

Tools

Microsoft security tools

Job description

Full Time (37 hours per week) - Permanent - High Wycombe Campus / Hybrid working
Salary - £38,784 - £43,482

We're not trying to fit in with the higher education status quo. We're challenging it. We're doing things differently - because our students, our staff, and our world need us to.

So this is an exciting moment to join us. We're boldly reimagining what a university can be: a place rooted in social mobility, a community where difference is celebrated, and an institution that empowers people to become more than they thought possible.

Buckinghamshire New University is seeking a proactive and ambitious Information Security Officer to help shape and strengthen our information security and compliance programme. Working within the Information Assurance team, you will play a key role in protecting the University's information assets, managing security risks, and embedding a strong security culture across the organisation.

You will lead the continual improvement of our Information Security Management System (ISMS), support the management of security incidents, drive compliance activities, and develop information security policies, standards and controls. You will also contribute to strategic projects, maintain oversight of information security risks and assets, and provide expert advice to colleagues to ensure security is embedded in decision-making and service delivery.

This is an opportunity to make a meaningful impact in a university committed to transforming lives through education. We welcome applications from all backgrounds and are committed to an inclusive and supportive workplace.

What we offer:
  • a generous holiday entitlement (35/30 days per annum, plus bank holidays & closure days)
  • Hybrid working (dependent on business needs)
  • training & development support opportunities
  • contributory pension scheme
  • free gym membership for our on-site gym
  • a range of staff discounts with major retailers.

If you have the qualities and attributes representative of the University's values and ambition, we would be delighted to hear from you.

For further information about this role please contact jenny.horwood@bnu.ac.uk

We are committed to promoting an inclusive and diverse workplace and aim to continue building an environment where everyone thrives and can be themselves.

Please let us know if you require any adjustments or support during the recruitment process. We are happy to discuss any reasonable adjustments that would enable you to perform to the best of your abilities in your role. Please reach out to people@bnu.ac.uk if you have any specific needs or if you would like more information on how we can support you

We ensure that our interview/shortlisting Chairs complete the relevant e-learning and/or inclusive recruitment training.

If you're considering using AI to support your application, we encourage you to question the value it adds. The use of AI tools sometimes erodes authenticity and prevents us from being able to assess the real you. We strongly recommend you prepare your application using your own skills and knowledge and that AI is only used for the purpose of review.

Closing Date: Friday 02 October 2026
Interview Date: Monday 12 October 2026

If you are invited to interview for this role, you will need to provide evidence of your eligibility to work in the UK and if on a visa, current visa and status. Sponsorship is dependent on the salary level of the position.

BNU is a Disability Confident employer and as such you will be given the opportunity to declare a disability as part of the application process.

Job Title: Information Security Officer

Faculty/Directorate: CIO Group

Grade: G

Location: High Wycombe

Hours: 37

Responsible to: Head of Information Assurance

Responsible for: Information Assurance and Security Analyst

Job Purpose:

To maintain a good understanding of cyber security technologies, IT security operations and cyber security controls to improve the University's cyber security posture and drive key information security initiatives.

To have a broad understanding of information security and cyber security frameworks, standards and policies to help build and deliver the University's information and cyber security strategies.

Undertake a range of audit and assurance activities including technology management; policy development and documentation; testing, monitoring and management of security controls; risk evaluation of threat information; consultative engagements; project-work; and reporting.

Main Duties & Responsibilities of the role:
  • Provide governance and assurance to the wider CIO Group and University by supporting the Head of Information Assurance in developing, delivering and auditing against the information governance framework.
  • Work closely with the Infrastructure and Operations Teams to review the existing global architecture (including infrastructure and cloud services), identify design gaps, and recommend enhancements to cyber security controls and implement any agreed improvements so that the University's data and information systems are secured.
  • Serve as an internal information and cyber security subject matter expert and lead operational security activities including security monitoring, threat detection, security event management, endpoint security, identity security and oversight of managed security service providers.
  • Develop, validate, maintain and regularly test all information security, cyber security, disaster recovery and business continuity plans, process and procedures.
  • In collaboration with the CIO assist with the design and development of the cyber security strategy and recommendations for new cybersecurity systems.
  • Work with the wider CIO Group to execute regular vulnerability assessments and coordinate external penetration testing to identify data protection, cyber security and other compliance risks and present recommendations for mitigating the risks in the immediate term and provide guidance on plans to manage the risk long term.
  • Maintain the University's information security risk register, ensuring risks are assessed, tracked, reviewed and reported to appropriate governance forums. Assist departments with risk assessments and developing appropriate management and mitigation strategies to avoid reputational and financial damage to the University.
  • Lead all investigations related to security incidents, including analysis of impact, resolution, cause, prevention and subsequent remediation as required by the University's Incident Response procedures. This includes ensuring there is adequate out of hours and emergency incident response cover.
  • Develop and monitor security KPIs to assess the effectiveness of controls and present regular security reporting, risk assessments and assurance updates to leadership, governance committees and external auditors.
  • Take advice from our third-party security partners and maintain a high level of knowledge about information, cyber security and privacy regulations, new security risks and protocols, and new security technology solutions.
  • Assist in the development, review, and consultation of information and cyber security policies, standards, and guidelines in line with industry best practices and the University's needs, ensuring that compliance is enforced through the satisfactory completion of regular internal and external audits.
  • Support the development and maintenance of the University's ISMS, ensuring compliance with legislation e.g. Data Protection Act 2018 and UK GDPR; standards, such as ISO 27001, ISO 22301 and PCI-DSS; and frameworks including Cyber Essentials.
  • Help create a positive security culture across the University through engagement activities, awareness campaigns, training and leadership engagement by promoting the University's information and cyber security policies and procedures to all staff and serving as the primary point of contact for associated issues across the institution.
  • Deliver the University's information security awareness programme to promote awareness of the processes, policies and technical solutions in place to protect confidentiality, integrity and availability of data by maintaining training materials, promoting participation, and monitoring its effectiveness.
  • Perform line management responsibilities including recruitment and selection, performance management, professional development, motivation, health and safety, and wellbeing.
  • Comply with relevant legislative and other requirements (e.g., the Data Protection Act 2018 and UK GDPR; Health and Safety; UKVI; and Equality and Diversity) in all working practices
  • Perform such other duties temporarily or on a continuing basis, as may reasonably be required.
PERSON SPECIFICATION
A = Application T = Test I = Interview
Education, Qualifications & Training
Means of Testing

Professionally qualified with a relevant degree/postgraduate qualification or relevant vocational, strategic management and leadership experience

A

Relevant information security qualification (or working towards) such as CISSP or CISM, or Security+

A

Substantial experience in a security-focused role, with a proven track record of managing security risks and controls

A

Knowledge & Experience

Knowledge of regulatory and statutory compliance requirements e.g. Data Protection Act 2018, UK GDPR, PCI-DSS

A/I

Experience with security certifications and audits e.g. ISO 27001 and Cyber Essentials or similar information security standards

A/I

Previous experience in a role that includes an element of detecting and responding to security incidents and the collection and use of threat intelligence ideally within exposure to Higher Education or Public Sector environments

A/I

Demonstrable knowledge and experience of information risk management and information assurance.

A

Experience writing formal reports including audit and compliance review findings on data and information systems.

A/I

Good underlying knowledge of Microsoft security tools and platforms as evidenced by technical or professional qualifications and work experience.

A/I

Skills

Powers of influence and negotiation to secure the prioritisation of resources and workload from other areas of the University

I

Ability to plan, prioritise and organise own work and resources and leading / guiding others, whilst anticipating problems and planning workable solutions

I

Communication, persuasion and presentation skills to motivate an organisation to change its culture and to lead people change projects

I

Ability to explain complex technical information to non-technical audiences and convey complex information in clear ways to a range of audiences

I

Special Requirements

As cyber threats occur at any time, this position requires a willingness to work out of hours/weekend working and emergency incident response.

A/I

Willingness to work a rota-based shift pattern and undertake on-call duties when required.

A/I

Behavioural INDICATORS

The BNU Behaviours Framework (BBF) is a framework for all University staff that sets out the key behaviours that exemplify the values and ethos of the University. .

Finding solutions

Taking a holistic view and working enthusiastically to analyse problems and to develop workable solutions. Identifying opportunities for innovation.

Using resources effectively

Identifying and making the most productive use of resources including people, time, information, networks and budgets.

Working together

Working collaboratively and across boundaries with others in order to achieve objectives. Recognising and valuing the different contributions people bring to this process.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Due Diligence Advisor
Senior Due Diligence Advisor

Buckinghamshire New University • High Wycombe

On-site
GBP 34,000 - 38,000
Holiday entitlement
Hybrid working
Training & development support
+3
Technical Support Manager
Technical Support Manager

Buckinghamshire New University • Bridge

Hybrid
GBP 39,000 - 43,000
Generous holiday entitlement
Hybrid working
Training & development
+3
Senior Study Skills Advisor
Senior Study Skills Advisor

Buckinghamshire New University • High Wycombe

Hybrid
GBP 34,000 - 38,000
Holiday entitlement
Hybrid work
Training opportunities
+3
Learning Designer
Learning Designer

Buckinghamshire New University • High Wycombe

Hybrid
GBP 39,000 - 43,000
Hybrid working
Generous holiday entitlement
Training & development support
+2
Data Analyst FTC 23 months
Data Analyst FTC 23 months

Buckinghamshire New University • High Wycombe

Hybrid
GBP 39,000 - 43,000
Generous holiday entitlement
Hybrid working
Training & development support
+3
Senior Information Security Officer
Senior Information Security Officer

UCL • City Of London

On-site
GBP 65,000 - 85,000
Security Administrator
Security Administrator

School of Computer Science and Engineering, Bangor University • Bangor

On-site
GBP 27,000 - 30,000
Head of IT
Head of IT

UK Management College • Manchester

On-site
GBP 90,000 - 130,000
Assistant Security Controller
Assistant Security Controller

Diversity Dashboard • Rotherham

Hybrid
GBP 32,000 - 37,000
38 days annual leave (incl bank)
Flexible working
Generous pension scheme
+4
Lead Information Security Officer
Lead Information Security Officer

UCL • City Of London

On-site
GBP 90,000 - 125,000
41 Days holiday
Cycle to work
On-site nursery
+4