Information Security Officer

Maxwell Bond

Reading

Hybrid

GBP 55,000 - 57,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Maxwell Bond is partnering with a technology distribution business to recruit an Information Security Officer for GRC and compliance. The role focuses on hands-on implementation of ISMS and security controls, working with auditors, suppliers and customers to demonstrate risk managed and controls operating effectively.

The role requires building security assurance across ISO 27001, PCI-DSS, NIST/CIS, with vendor risk management and cloud security in Microsoft 365, Azure, AWS or Google Cloud.

Qualifications

  • 3+ years in information security, GRC, or security consultancy.
  • Hands-on ISMS implementation and ISO 27001 management.
  • Experience with security audits, control testing, risk assessments and remediation.
  • Knowledge of ISO 27001/27002, NIST, CIS Controls, PCI-DSS and Cyber Essentials Plus.
  • Experience in third‑party/vendor risk management and security assurance.
  • Strong stakeholder management skills across technical and business teams.
  • Security qualifications (CISSP, CISM, CISA, CCSP) advantageous.

Responsibilities

  • Maintain and improve the organisation's ISMS, including policies, procedures and controls.
  • Support the implementation and management of ISO 27001, Cyber Essentials Plus, PCI-DSS, NIST/CIS Controls.
  • Conduct security assessments across infrastructure, networks, endpoints, applications and data.
  • Identify, assess and manage information security risks; maintain risk registers.

Skills

Stakeholder management
GRC experience
Security auditing
Risk assessment
ISMS implementation
Policy development

Education

Security qualification (CISSP/CISM/CISA/CCSP)

Tools

Microsoft 365
Azure
AWS
Google Cloud

Job description

Information Security Officer – GRC & Compliance

Location: Reading area – hybrid
Salary: £55,000–£57,000 basic
Contract: Permanent

About the Company

We are working with a large, privately owned technology distribution business operating across the UK and Europe. The organisation partners with some of the world's leading technology brands, supplying hardware, software and technology solutions through a large network of resellers, retailers and business customers.

As the business continues to grow, its Information Security function is expanding and we are looking for an experienced Information Security Officer to join the team.

The Role

Reporting to the Director of Cyber Security, you will work across Information Security, GRC, ISMS, compliance and security consultancy, helping to maintain and improve the organisation's security controls and overall cyber maturity.

The role has a strong focus on hands-on implementation and assurance, rather than purely policy-based or theoretical security work. You will work closely with technical and business teams, customers, suppliers and auditors to demonstrate that security controls are operating effectively and that risks are being identified and managed.

Key Responsibilities
  • Maintain and continually improve the organisation's Information Security Management System (ISMS), including policies, procedures and controls.

  • Support the implementation and ongoing management of ISO 27001, Cyber Essentials Plus, PCI-DSS, NIST/CIS Controls and other relevant security requirements.

  • Conduct security assessments across infrastructure, networks, endpoints, applications and data.

  • Identify, assess and manage information security risks, including maintaining risk registers and tracking remediation.

  • Lead and support internal and external security audits, including evidence gathering, control testing and remediation of findings.

  • Manage technical security risks within Data Protection Impact Assessments and policy exceptions.

  • Support the vendor and third-party risk management programme, including assessment and ongoing monitoring of critical suppliers.

  • Work with technical teams around identity and access management, including SSO and federated services.

  • Provide security assurance for projects, systems and customer requirements.

  • Support security awareness and continuous improvement initiatives.

  • Produce security reporting, dashboards and metrics for senior stakeholders.

  • Work with the wider security team to deliver elements of the organisation's Security Improvement Plan.

  • Support security engagements with customers, suppliers, auditors and other external stakeholders.

What We're Looking For
  • At least 3 years' experience in an Information Security, GRC, compliance or security consultancy role.

  • Practical experience implementing and managing ISO 27001 / ISMS rather than purely theoretical knowledge.

  • Experience with security audits, control testing, risk assessments and remediation.

  • Knowledge of frameworks and standards including ISO 27001/27002, NIST, CIS Controls, PCI-DSS and Cyber Essentials Plus.

  • Experience developing and maintaining security policies and procedures.

  • Experience with third-party/vendor risk management and security assurance.

  • Understanding of cloud security across platforms such as Microsoft 365, Azure, AWS or Google Cloud.

  • Strong stakeholder management skills, with the ability to work with technical, business and external teams.

  • A security qualification such as CISSP, CISM, CISA, CCSP, ISO 27001 Lead Implementer/Auditor or equivalent would be advantageous.

  • A practical, methodical approach to identifying and managing security risks.

Location

The role operates on a hybrid basis, with occasional travel to UK offices and meetings with customers, suppliers and auditors.

Candidates should ideally be based within approximately one hour of the Reading area.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Security Officer
Principal Security Officer

Maxwell Bond • Reading

Hybrid
GBP 42,000 - 70,000
Hybrid work model
Information Security Officer
Information Security Officer

TyneStack Ltd • Newcastle upon Tyne

Hybrid
GBP 45,000 - 70,000
Hybrid working
Exposure to ISO 27001/NIST in cloud
Regulated financial tech environment
IT Information Security Analyst - Compliance
IT Information Security Analyst - Compliance

Adecco • West Midlands

Hybrid
GBP 45,000 - 55,000
IT GRC Senior Analyst
IT GRC Senior Analyst

Nigel Wright Recruitment • Newcastle upon Tyne

Hybrid
GBP 70,000 - 90,000
Hybrid work policy
Information Security Manager
Information Security Manager

Frontpoint Partners Ltd • Greater London

On-site
GBP 85,000 - 110,000
Information Security Manager
Information Security Manager

Nuvion Tech • Bedford

Hybrid
GBP 80,000 - 110,000
GRC Senior Analyst
GRC Senior Analyst

Recruitment • Greater London

On-site
GBP 75,000 - 110,000
Information Security Manager
Information Security Manager

Intec Select • Basingstoke

Hybrid
GBP 51,000 - 85,000
Information Security Manager
Information Security Manager

context recruitment • Greater London

Hybrid
GBP 96,000 - 126,000
Information Security Manager
Information Security Manager

context recruitment • Birmingham

Hybrid
GBP 111,000 - 120,000