Information Security Specialist

clydeco

Glasgow

On-site

GBP 55,000 - 75,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Clyde & Co is seeking an Information Security Specialist in Glasgow to lead the security awareness programme and manage supplier security risk across the firm. You will own training initiatives, liaise with providers and drive behavioural change to strengthen the security culture.

Responsibilities include phishing simulations, CSAM campaigns, stakeholder engagement and producing management reports with security insights.

Qualifications

  • Experience in managing security awareness and training programmes.
  • Knowledge of phishing simulations and user behavioural analytics.
  • Familiarity with third-party risk management and supplier assurance.

Responsibilities

  • Manage phishing simulation campaigns, awareness training initiatives and behavioural change activities to improve security culture and reduce cyber risk.
  • Coordinate annual security campaigns including CSAM, mandatory training activities and targeted awareness initiatives.
  • Monitor threats, industry practices and awareness trends, recommending improvements to strengthen resilience and human-risk management.
  • Maintain and manage initiative plans, milestones, dependencies and reporting for security improvement programmes.
  • Own and maintain productive relationships with external vendors to ensure quality, effectiveness and continuous improvement of awareness and training services.
  • Monitor vendor performance against service levels, metrics and contractual commitments, driving improvements where needed.
  • Produce tailored management reports, dashboards and presentations for senior leaders with insights into programme performance and risk.
  • Partner with senior stakeholders to boost engagement, improve completion rates and promote a strong security culture.
  • Present findings and updates to management in a clear, business-focused manner.
  • Maintain, execute and enhance third-party and supply chain security risk management processes including tiering by risk and TPISA assessments.
  • Design and operate supplier security assessment mechanisms and review processes.
  • Manage information security within the supplier lifecycle and address risks and remediation actions.
  • Collaborate with Information Security, IT, Procurement and Risk/Legal to integrate security requirements into operations.
  • Monitor, analyse and assess emerging supply chain threats and incidents impacting the firm.
  • Develop understanding of the supplier estate and identify concentration and critical supplier exposures.
  • Improve third-party risk management processes and assurance activities to match the risk landscape.
  • Establish assurance activities over key suppliers via audits, certifications and attestations.

Job description

Department: Information Security

Location: Glasgow

Contract Type: Permanent

Role: Information Security Specialist

Key Responsibilities
Training, Awareness & Human Risk

The chosen candidate will be accountable for the successful delivery and continuous improvement of Clyde & Co's security awareness programme, owning the relationship with training providers, developing engaging content and partnering with stakeholders across the firm to drive behavioural change and strengthen the firm's security culture.

  • Manage enterprise phishing simulation campaigns, awareness training initiatives and behavioural change activities to improve security culture and reduce cyber risk.
  • Coordinate the delivery of annual security campaigns including Cyber Security Awareness Month (CSAM), mandatory training activities and targeted awareness initiatives.
  • Monitor emerging threats, industry practices and security awareness trends, recommending improvements to strengthen organisational resilience and human-risk management capabilities.
  • Maintain and manage initiative plans, milestones, dependencies and reporting for assigned security improvement programmes.
  • Own and maintain strong a productive relationship with external vendors to ensure the quality, effectiveness and continuous improvement of awareness and training services.
  • Monitor vendor performance against agreed service levels, success metrics, and contractual commitments, driving improvements where required.
  • Produce tailored management reports, dashboards and presentations for senior leaders, providing meaningful insights into programme performance, compliance levels, user behaviour and areas of risk.
  • Partner with senior stakeholders to increase engagement, improve training completion rates and promote a strong security culture throughout the firm.
  • Present findings, recommendations, and programme updates to management in a clear, concise and business-focused manner.
Supply Chain Risk and Supplier Assurance

The chosen candidate will be responsible for maintaining effective oversight of Clyde & Co's third-party security risk exposure, providing proactive insight into emerging supply chain threats and vulnerabilities and ensuring the firm's supplier assurance processes remain current, risk-based and aligned to the firm's IT&O Risk Management Framework.

  • Maintain, execute and enhance third-party and supply chain security risk management processes including tiering of suppliers by risk, periodic and ad hoc third-party information security assessments (TPISA) and ongoing assurance activities.
  • Design and operate supplier security assessment mechanisms, including contractual security schedules, supplier risk questionnaires, attestations and contract review processes.
  • Manage information security within the supplier relationship throughout the lifecycle, ensuring that supply chain risks, control deficiencies and remediation actions are identified, tracked and addressed in a timely manner.
  • Collaborate with Information Security, IT, Procurement, Risk Management, Legal and business stakeholders to ensure security requirements are integrated into operational processes and supplier engagements.
  • Monitor, analyse, and assess emerging supply chain security threats, industry trends, regulatory developments, geopolitical risks, and third-party security incidents to identify risks that may impact Clyde & Co's supply chain.
  • Develop and maintain a comprehensive understanding of Clyde & Co's supplier estate, identifying areas of concentration risk, systemic risk, fourth-party dependencies, and critical supplier exposures.
  • Continuously evaluate and improve third-party risk management processes, methodologies, assessment frameworks, and assurance activities to ensure they remain effective, proportionate, and aligned to the firm's risk appetite and evolving threat landscape.
  • Establish and maintain meaningful assurance activities over key(critical) suppliers through the review of independent audits, certifications, penetration test summaries, security attestations, performance metrics, and other relevant evidence.
Email DLP and Information Protection

To continuously enhance Clyde & Co's Email DLP and Information Protection capabilities, ensuring the firm's confidential, sensitive, and client information is protected through effective preventative, detective, and responsive controls while enabling secure business operations and collaboration.

  • In conjunction with the Risk department, continue the development and enhancement of
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Specialist
Information Security Specialist

Whereby • Glasgow

On-site
GBP 55,000 - 85,000
Information Security & Risk Awareness Lead
Information Security & Risk Awareness Lead

Whereby • Glasgow

On-site
GBP 55,000 - 85,000
Information Security Specialist
Information Security Specialist

Clyde & Co Global Services Limited • Glasgow

On-site
GBP 60,000 - 90,000
Information Security Specialist - Awareness & Risk
Information Security Specialist - Awareness & Risk

clydeco • Glasgow

On-site
GBP 55,000 - 75,000
Security Awareness & Third-Party Risk Lead
Security Awareness & Third-Party Risk Lead

Clyde & Co Global Services Limited • Glasgow

On-site
GBP 60,000 - 90,000
Cyber Solutions Lead
Cyber Solutions Lead

clydeco • Glasgow

On-site
GBP 80,000 - 110,000
Cyber Solutions Lead
Cyber Solutions Lead

Clyde & Co Global Services Limited • Glasgow

On-site
GBP 90,000 - 130,000
Information Security Analyst
Information Security Analyst

Herbert Smith Freehills Kramer • City Of London

On-site
GBP 60,000 - 80,000
Information Security Analyst
Information Security Analyst

Herbert Smith Freehills Kramer • City Of London

On-site
GBP 40,000 - 60,000
Due Diligence Analyst
Due Diligence Analyst

Clyde & Co Global Services Limited • Glasgow

Hybrid
GBP 30,000 - 45,000
Life assurance from day one
Season ticket loans
Lifestyle discounts
+2