Principal Information Security Officer

Westcoast Limited

Reading

On-site

GBP 63,000 - 77,000

Full time

27 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Growth opportunities
Generous benefits package
Wellbeing support
Community & connection

Job summary

Westcoast Limited, a Sunday Times Top Track 100 company, invites a security leader to shape risk, architecture and governance across the group. You will drive SDLC security, Identity and Access Management, and compliance with ISO27002, PCI-DSS, Cyber Essentials Plus and other standards.

Regular UK travel, collaboration with stakeholders, and deputizing for the Director of Cyber Security when needed. The role offers growth, a generous benefits package, and the chance to mature security practices

Qualifications

  • Minimum of 5 years' experience in a relevant security position.
  • Security frameworks knowledge: ISO27001, NIST, CIS Controls and PCI-DSS.

Responsibilities

  • Maintaining a security assurance program in support of PMO portfolio.
  • Developing initiatives on inter group Security Improvements.
  • Working with the Technical Design Board on developing security architecture and patterns.
  • Driving improvement in the SDLC processes.
  • Maintaining compliance with external security standards and frameworks required by regulators and customers.

Skills

GRC
Security architecture
Identity management
Consultancy
Security leadership

Education

CISSP/CISM/CCSP/CISA/ISO27001 Lead Implementor/Auditor
NCSC-certified degree

Tools

Firewalls
Web filtering
Anti-virus

Job description

At Westcoast, we take pride in distributing some of the most renowned global IT brands to resellers, retailers, and organizations across the UK and beyond. As an innovative and inclusive company, we thrive on teamwork and the diverse talents of our people. We invite you to turn your passion into a rewarding career with us!

The Job Role

You will report to the Director of Cyber Security and will be working to deliver the Architecture and consultancy, Identity and Access Management and Governance, Risk and Compliance activities within the Westcoast Security Model.

The role will involve working in partnership across the group with both stakeholders, technical teams, development functions and third parties to deliver Secure Development Lifecycle (SDLC) processes and solutions, compliance and consultancy activities. These activities will need to comply with standards such as ISO27002, Cyber Essential Plus, PCI-DSS, DPA:2018. EU Directives and PASF as well as customer specific requirements while also aligning with ISO22301 and resiliency requirements. As an experienced practitioner you will be looking to improve maturity and standards, setting goals and plans with meaningful metrics and KPIs.

As well as working within the PMO on projects you will work the Heads of, through the group compliance board on maintaining external standards, as well as deputizing for the Director of Cyber Security in their absence. As an experienced security lead, you will lead on the security engagements, providing subject matter expertise on requirements, compliance, contracts, controls, resilience, testing and assurance.

Regular travel to UK based offices is required in this role. You must be able to achieve Westcoast security vetting.

Your Day-to-Day Responsibilities Will Include:
  • Maintaining a security assurance program in support of PMO portfolio
  • Developing initiatives on inter group Security Improvements
  • Working with the Technical Design Board on developing security architecture and patterns.
  • Driving improvement in the SDLC processes
  • Maintaining compliance with external security standards and frameworks required by regulators and customers and working in partnership with Compliance, Legal, and Internal Audit functions
  • Security assessment and management of Westcoast hosted and cloud infrastructure, networks, endpoints, and applications and data against threat models. Including developing testing and remediation plans with tracking.
  • Working with system owners to drive the implementation of identity good practice and in particular single sign on and federated services
  • Security Reporting providing management reporting and real time dashboards, to provide the security team business and management assurance of the compliance of projects and IT security controls
  • Work with Security Operations and Engineering teams on control effectiveness
  • Where requested on contracts - Provide end to end assurance of compliance with existing Information Security policies and standards (attend meetings with customers etc.).
Is this the role for you?

We are looking for someone who can shape change and has an experience in GRC, security architecture, consultancy and identity management. Our ideal candidate will have a focus on improvement, a passion security and strong technical skills.

To be successful in this role you will have some of the following skills and experience and the desire to develop in other areas:

  • Minimum of 5 years' experience in a relevant security position
  • A security professional qualification such as CISSP, CISM, CCSP, CISA, ISO27001 Lead Implementor/Auditor, CEH or equivalent
  • Or an equivalent recognized Information Security discipline Degree: NCSC-certified degrees - NCSC.GOV.UK
  • Previous experience and knowledge of security frameworks i.e. ISO27001, NIST, CIS Controls and PCI-DSS compliance
  • An understanding of HMG security standards (e.g. Security Policy Framework, Cyber Essentials Plus, Cloud security principles etc.).
  • Experience of Enterprise Project Management practices as related to information Security
  • Experience of working with enterprise level IT and network teams, systems and processes
  • Experience of working with MSSPs, Pentesters, Redteaming, external SOCs
  • Experience of security products, e.g., firewalls, web filtering, anti-virus etc.
What's in It for You?

This is a fantastic opportunity to immerse yourself in the IT industry, build lasting relationships, and grow with a Sunday Times Top Track 100 company.

  • Growth Opportunities: We offer training and development opportunities to help you reach your full potential. Whether it's funded apprenticeships, work-based studies, or professional qualifications, we've got you covered.
  • Generous Benefits Package: A salary of up to £70,000 depending on experience. Enjoy 25 days of holiday, employee referral bonuses, perks and discounts. (Theale only - New fully equipped gym available 24/7).
  • Wellbeing Support: Access to Westcoast Wellbeing services including mental health counselling, virtual GP services, physiotherapy, life insurance, eye care schemes, and more.
  • Community & Connection: Our teams enjoy social and charitable events throughout the year, fostering a strong sense of belonging.

Please note: Due to the high volume of applications, we may not be able to provide individual feedback for every candidate. If you don't hear from us within 14 working days, kindly note that we have chosen to pursue other candidates for this opportunity. We appreciate your interest and encourage you to explore future opportunities with us.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Information Security & GRC Architect
Senior Information Security & GRC Architect

Westcoast Limited • Reading

On-site
GBP 63,000 - 77,000
Growth opportunities
Generous benefits package
Wellbeing support
+1
Senior Commercial Financial Accountant
Senior Commercial Financial Accountant

Westcoast Limited • Reading

On-site
GBP 65,000 - 90,000
Growth opportunities
25 days holiday
Wellbeing support
+1
Cloud & Software Sales Executive
Cloud & Software Sales Executive

Westcoast Limited • Reading

Hybrid
GBP 35,000 - 52,000
Growth opportunities
25 days holiday
Gym access (Theale)
+2
Operations Coordinator
Operations Coordinator

Westcoast Limited • Theale

On-site
GBP 22,000 - 28,000
25 days holidays
Bonus included in package
Westcoast Wellbeing programme
+1
Microsoft Surestep Manager
Microsoft Surestep Manager

Westcoast Limited • Reading

On-site
GBP 40,000 - 56,000
25 days holiday
Gym access at Theale
Wellbeing services
+2
Operations Coordinator
Operations Coordinator

Westcoast Limited • Reading

On-site
GBP 32,000 - 42,000
Bonus included
25 days holidays
Staff purchase discounts
+1
Team Manager - Microsoft Surestep
Team Manager - Microsoft Surestep

Westcoast Limited • Reading

On-site
GBP 30,000 - 50,000
25 days holiday
Employee referral bonuses
Access to wellbeing support services
+2
Post Despatch Administrator Apprentice
Post Despatch Administrator Apprentice

Westcoast Limited • Reading

On-site
GBP 16,000 - 20,000
Growth opportunities
Generous benefits package
Wellbeing support
+1
Cloud Marketing Executive
Cloud Marketing Executive

Westcoast Limited • Reading

On-site
GBP 24,000 - 32,000
25 days of holiday
Employee referral bonuses
Access to Wellbeing services
+2
Senior Associate – Information Security
Senior Associate – Information Security

Willis Towers Watson • Ipswich

Hybrid
GBP 55,000 - 75,000
25 days annual leave
Private healthcare
Life insurance
+3