Information Security Specialist

deciphex

Kidlington, Exeter

On-site

GBP 70,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Deciphex is seeking an experienced information security professional to own the ISMS, drive continuous improvement, and ensure ISO 27001 alignment across Deciphex, Diagnexia and Patholytix.

You will partner with Cybersecurity Engineering, DevOps, IT and Governance to embed secure-by-design practices, manage risk, and support internal and external audits, vendor due diligence and regulatory requirements in a fast-paced life sciences environment.

Qualifications

  • 5+ years in Information Security / ISMS operations.
  • Ideally in med tech/ clinical or lifesciences.
  • Hands-on ISO 27001 exposure — internal audit and management review experience.
  • Experience with external audit from both certified bodies and clients.
  • Strong documentation and stakeholder-management discipline.
  • Ability to translate technical controls into practical action.
  • Familiarity with cloud security fundamentals.

Responsibilities

  • Maintain a live, decision-oriented risk register with owners and mitigation plans.
  • Champion a risk-aware culture where decisions are informed by risk, not paralysed by it.
  • Develop and maintain policies and procedures that reflect how the business actually operates (not a unworkable bottleneck)
  • Support vendor and customer security due diligence in support of commercial and product needs.
  • Contribute to tabletop exercises (e.g. incident response, business continuity)
  • Maintain awareness of applicable regulatory requirements (EU AI Act, GDPR, HIPAA, MDR/IVD) and ensure the ISMS remains aligned with our other Certifications and Standards
  • Define evidence expectations for technical controls (SIEM, EDR, MFA, RBAC, vulnerability management).
  • Go and check: verify controls independently rather than relying on assertions; if something looks wrong, investigate and resolve it.
  • Support site reliability and resilience initiatives
  • Build engaging security awareness training that changes behaviour, not just completion rates.
  • Act as a visible, approachable point of contact for information security questions to enable change across the business
  • Translate security requirements into plain language for non-technical audiences without losing accuracy or impact.

Skills

ISMS operations
Documentation
Stakeholder management
Cloud security
Risk management

Tools

ISO 27001

Job description

Location:
  • Living & working full time in either Ireland or UK only
  • Willingness & flexibility to travel to UK locations, when required to support InfoSec work. (Kidlington & Exeter) - circa varies 1-3 days per quarter
  • Very Occasional travel to Dublin HQ (Glasnevin) as needed to support audit work
Right to Work
  • We are unable to offer UK or Irish visa sponsorship for this role.
Reporting & work team
  • You’ll report to and work closely with the Information Security Lead, as well as Cybersecurity Engineering, DevOps, IT, Data Governance, and AI Governance to embed secure-by-design practices across the organisation.
About this Role
  • Information security underpins all of our business activities, including AI development
  • and compliance with Medical Device regulations
  • This role is ideal for a hands-on security specialist who supports the ISMS, validates controls for themselves, and drives continuous improvement with energy and pragmatism.
  • This role moves away from traditional GRC and leans into modernising it - moving teams towards always-on compliance and consistently demonstrating business value in the activities we run.
  • You’ll work across the business as someone who meets challenges head-on, brings people with them, and makes security work in practice, not just on paper.
More specifically;
  • This role involves protecting systems and data that directly support cancer diagnostics and drug development, security work with real-world consequence.
  • This is a hands-on, delivery-focused role suited to someone who thrives in a very fast-moving environment.
  • Success requires a pragmatic approach, strong judgement, and the ability to navigate challenges, remove obstacles, and drive progress at pace.
ISMS & Certifications
  • We hold ISO 27001 certification across our core business units and are expanding coverage as we grow.
  • Support the day-to-day running of the ISO 27001 ISMS across our Deciphex business units (Deciphex, Diagnexia & Patholytix)
  • Prepare for internal and external audits so that teams are ready, controls are functioning, and evidence is complete. Audit readiness as a steady state.
  • Contribute to continuous improvement initiatives. Iidentify what needs to change, make the case, and see it through.
  • Proactively identify and close gaps in the control framework, driving corrective actions (CAPAs) to closure
  • Build and maintain a reliable evidence pipeline with clear ownership and high completeness.
  • Assess which ISMS activities deliver measurable business value - and be willing to challenge or retire processes that aren't.
Security Governance & Risk
  • Maintain a live, decision-oriented risk register with owners and mitigation plans.
  • Champion a risk-aware culture where decisions are informed by risk, not paralysed by it.
  • Develop and maintain policies and procedures that reflect how the business actually operates (not a unworkable bottleneck)
  • Support vendor and customer security due diligence in support of commercial and product needs.
  • Contribute to tabletop exercises (e.g. incident response, business continuity)
  • Maintain awareness of applicable regulatory requirements (EU AI Act, GDPR, HIPAA, MDR/IVD) and ensure the ISMS remains aligned with our other Certifications and Standards
Technical Oversight
  • Define evidence expectations for technical controls (SIEM, EDR, MFA, RBAC, vulnerability management).
  • Go and check: verify controls independently rather than relying on assertions; if something looks wrong, investigate and resolve it.
  • Support site reliability and resilience initiatives
Awareness & Security Culture
  • Build engaging security awareness training that changes behaviour, not just completion rates.
  • Act as a visible, approachable point of contact for information security questions to enable change across the business
  • Translate security requirements into plain language for non-technical audiences without losing accuracy or impact.
What This Is Not
  • Not a paper-only ISMS role or tick-box compliance exercise. The clear expectation here is you take hands-on ownership of effective controls, not just documentation.
  • Not a technical incident response role. Security operations is handled separately.
  • Not a bureaucratic or gatekeeping function. Our priority goal is to enable the business, not slow it down.
  • Not a role for someone who prefers to escal... as a first port of call. We value/reward people who find the answer and move things forward.
  • Not a 'policing' role. We focus on shared responsibility and enabling teams to move fast safely.
Skills and Experience
Required
  • 5+ years in Information Security / ISMS operations.
  • Ideally in med tech/ clinical or lifesciences
  • Hands-on ISO 27001 exposur e — internal audit and management review experience.
  • Experience with external audit from both certified bodies and clients
  • Strong documentation and stakeholder-management discipline.
  • Ability to translate technical controls into practical action.
  • Familiarity with cloud security fundamentals
Preferred
  • Hands-on experience with
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Manager
Information Security Manager

British Land • Greater London

Hybrid
GBP 90,000 - 130,000
Security Lead
Security Lead

Jobtailor • Greater London

On-site
GBP 60,000 - 90,000
Information Security Analyst
Information Security Analyst

REX Cyber Security • Bristol

Hybrid
GBP 50,000 - 70,000
Information Security Analyst
Information Security Analyst

Herbert Smith Freehills Kramer • City Of London

On-site
GBP 60,000 - 80,000
Information Security Analyst
Information Security Analyst

Herbert Smith Freehills Kramer • City Of London

On-site
GBP 40,000 - 60,000
Information Security and Data Protection Analyst
Information Security and Data Protection Analyst

Interact Software • Manchester

On-site
GBP 45,000 - 65,000
Security Analyst
Security Analyst

Peaple Talent • West of England

Hybrid
GBP 45,000 - 50,000
25 days annual leave
Pension scheme: 5% employee + 4% employer
Investment in certifications
Cyber Security Analyst
Cyber Security Analyst

SmartestEnergy • Ipswich

On-site
GBP 50,000 - 75,000
Flexible Working
Diversity and Inclusion Commitment
Cyber Security Lead
Cyber Security Lead

Chambers & Partners • Greater London

Hybrid
GBP 90,000 - 130,000
Information Security Manager
Information Security Manager

United States Digital Space LLC • Greater London

Hybrid
GBP 80,000 - 110,000
Unlimited Annual Leave Policy
Private healthcare and dental
Enhanced parental leave
+3