Principal Cyber Officer

Maxwell Bond

Reading

Hybrid

GBP 63,000 - 77,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Maxwell Bond is assisting a large UK tech group in Reading with a Principal Information Security Officer role. You will own security across the project portfolio and provide senior leadership on risk, architecture and assurance.

Reporting to the Director of Cyber Security, you will collaborate with SecOps, GRC and engineering teams, mentor junior staff and drive security-by-design across multiple programmes within a hybrid working environment.

Qualifications

  • Strong experience across Information Security, Cyber Security, GRC, security assurance or security consultancy.
  • Experience owning and delivering security projects within an enterprise environment.
  • Strong knowledge of ISO 27001 / ISMS with practical experience implementing controls.
  • Good understanding of security architecture and security-by-design principles.
  • Experience with infrastructure, cloud, networks, engineering or SecOps teams.
  • Familiarity with security testing, vulnerability management and tooling.
  • Experience with ISO 27001/27002, NIST CSF or CIS Controls.
  • Exposure to Cyber Essentials Plus or PCI-DSS.

Responsibilities

  • Own the security element of the wider project portfolio and ensure security requirements are built into delivery.
  • Lead security projects from requirements and risk assessment through to implementation and assurance.
  • Collaborate with infrastructure, cloud, engineering, SecOps and GRC teams to design and implement controls.
  • Provide security architecture input and security-by-design guidance.
  • Review security information, controls and data to support decision-making and remediation.
  • Coordinate with penetration testing, vulnerability assessment and security testing teams.
  • Support ISMS development and continual improvement of security controls.
  • Translate risks into business requirements and practical remediation plans.
  • Provide guidance across customers, suppliers and external auditors; mentor Information Security Officers.

Skills

Information Security
GRC
Security Architecture
ISMS
ISO 27001
PCI-DSS
Stakeholder Mgmt
Mentoring

Job description

Location: Hybrid, ideally within commuting distance of Reading

Salary: Up to £69,999 basic

Type: Permanent

We’re working with a large, privately owned UK and European technology business as they continue to expand their Information Security function.

They’re looking for a Principal Information Security Officer to work closely with the Director of Cyber Security and take ownership of the security side of the organisation’s project portfolio.

This is a senior individual contributor / manager-level position for someone who can operate across security projects, GRC, architecture, assurance and technical teams, with the ability to step in and provide senior cover when required.

The Role

You’ll work closely with the newly appointed Portfolio Programme Manager, taking ownership of the security requirements across business and technology projects.

The role will involve:
  • Owning and managing the security element of the wider project portfolio, ensuring security requirements are considered throughout project delivery.
  • Leading security projects and initiatives from requirements and risk assessment through to implementation and assurance.
  • Working closely with infrastructure, cloud, engineering, SecOps and GRC teams to ensure security controls are appropriately designed and implemented.
  • Providing security architecture and security-by-design input where required.
  • Reviewing technical security information, controls and security data to challenge assumptions and support informed decision-making.
  • Working with penetration testing, vulnerability assessment and security testing teams to understand findings and drive remediation.
  • Supporting the development and continual improvement of the organisation's ISMS and security control framework.
  • Providing guidance around ISO 27001, NIST, CIS Controls, Cyber Essentials Plus and other relevant security frameworks.
  • Translating technical and information security risks into clear business requirements and practical remediation plans.
  • Supporting security assurance activity across customers, suppliers and external auditors.
  • Acting as a senior point of escalation within the Information Security function and providing cover for the Director of Cyber Security when required.
  • Supporting and mentoring Information Security Officers and working collaboratively across the wider security team.
What We're Looking For

We're looking for someone who has developed into a Manager / Senior Manager-level security professional and is ready to take broader ownership rather than someone already operating at CISO or Director level.

You’ll ideally have:
  • Strong experience across Information Security, Cyber Security, GRC, security assurance or security consultancy.
  • Experience owning and delivering security projects within an enterprise environment.
  • Strong knowledge of ISO 27001 / ISMS, with practical experience improving or implementing security controls.
  • Good understanding of security architecture and security-by-design principles.
  • Experience working with technical teams across infrastructure, cloud, networks, engineering or SecOps.
  • Good understanding of security testing, vulnerability management and security tooling.
  • Experience with frameworks such as ISO 27001/27002, NIST CSF and CIS Controls.
  • Exposure to Cyber Essentials Plus, PCI-DSS or similar regulatory/security standards.
  • Experience working with senior stakeholders and translating technical risks into practical business decisions.
  • The confidence to get hands-on with security tools and data when required, even where dedicated SecOps and engineering specialists are available.
  • Strong communication, stakeholder management and project ownership skills.
Technical Environment
Experience across some of the following would be beneficial:
  • Security architecture and secure-by-design
  • SIEM / security monitoring
  • Vulnerability management and security testing
  • Endpoint security / Microsoft Defender
  • Firewalls and network security
  • Identity, access management and SSO
  • Penetration testing / security assessment
  • GRC / ISMS platforms
Qualifications
Relevant certifications would be beneficial, including:
  • CISSP
  • CISM
  • CISA
  • CCSP
  • Other relevant security qualifications

The role is hybrid, with flexibility around home working. The preference is for someone within reasonable commuting distance of the Reading, particularly for occasional office attendance, project meetings and external audit activity.

This is a role for someone who wants genuine ownership of security projects and the opportunity to work across both the strategic and practical sides of Information Security.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal Security Officer
Principal Security Officer

Maxwell Bond • Reading

Hybrid
GBP 42,000 - 70,000
Hybrid work model
Information Security Officer
Information Security Officer

Maxwell Bond • Reading

On-site
GBP 55,000 - 57,000
Cyber Security Manager
Cyber Security Manager

Amtis - Digital, Technology, Transformation • Birmingham

Hybrid
GBP 77,000 - 94,000
Hybrid working
Private healthcare
Dental plan
+5
Cyber Security Manager
Cyber Security Manager

Amtis Professional Ltd • Birmingham

On-site
GBP 51,000 - 85,000
Hybrid work model
Annual bonus 30%
Pension contributions 1.5x
+7
Head of Information Security
Head of Information Security

Oakley Recruitment Ltd • Birmingham

On-site
GBP 110,000 - 160,000
Additional benefits package
Birmingham based
Travel as required
+4
Information Security Manager
Information Security Manager

context recruitment • Birmingham

On-site
GBP 111,000 - 120,000
Information Security Manager
Information Security Manager

context recruitment • Greater London

On-site
GBP 96,000 - 126,000
Information Security Consultant
Information Security Consultant

Bestman Solutions • Southampton

Hybrid
GBP 60,000 - 90,000
Hybrid working environment
Professional development
Career progression opportunities
Information Security Consultant
Information Security Consultant

InfraView Ltd • Greater London

On-site
GBP 70,000 - 85,000
Information Security Manager
Information Security Manager

Intec Select • Basingstoke

On-site
GBP 76,500 - 93,500