Senior Information Security (GRC) Specialist

BMS Group

Greater London

Hybrid

GBP 90,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

comprehensive private medical cover
annual health checks
virtual 24hr GP
gym subsidy
equity opportunity
birthday leave

Job summary

BMS Group is seeking a Senior Information Security Specialist to design, implement, and apply information security systems, policies, and procedures. You will work with IT and business units to protect data and ensure risk is managed effectively.

Responsibilities include governance, risk management, and compliance, with a focus on incident response, training, and ongoing information security improvements. The role reports to the Head of Security GRC & Deputy CISO and offers a permanent, hybrid

Qualifications

  • Proven experience in Information Security GRC functions (10+ years) with senior roles.
  • Cyber risk expert with experience across multiple frameworks and standards.
  • Ability to work with technical and business colleagues to drive risk-aware outcomes.
  • Excellent writing and communication skills.
  • Experience developing and maintaining written security controls, compliance monitoring and defining treatment strategies.

Responsibilities

  • Support development and implementation of Information Security Strategy and policies.
  • Manage Information Security Risk Register and risk assessments.
  • Track compliance with relevant legislation, regulations and standards (e.g., GDPR, NIST, etc.).
  • Consolidate audit actions and drive remediation and closure; produce risk dashboards.
  • Support incident response and continuous improvement of information security services.

Skills

GRC expertise
Cyber risk
Stakeholder communication
Policy development
Regulatory knowledge
Written communication

Job description

Summary of Position

This position will report to the Head of Security GRC & Deputy CISO as a senior member of the team. The role is expected to support day-to-day activities alongside other Security Specialists in the team whilst being able to step up and cover leadership responsibilities as and when required.

As a Senior Information Security Specialist, you will be providing expert subject matter expertise in the design, implementation, and application of BMS information security systems, policies, and procedures. You will work closely with other IT professionals and specialist business units to ensure that the company's data is protected from Information Security threats.

Key Responsibilities & Accountabilities
Governance
  • Support the Head of Security GRC & Deputy CISO with the development, alignment and implementation of an Information Security Strategy
  • Development, review and alignment of Information Security Policy
  • Support the development and delivery of an ongoing information security awareness programme
  • Ensure InfoSec policies, procedures and standards are accessible, communicated and understood by staff, contractors and vendors. Where required this will include delivering training
  • Attendance of relevant governance groups within BMS to ensure complete, transparent and effective risk management is delivered
  • Consolidating information security audit actions and driving remediation and closure
  • Producing management information (Dashboard) that clearly reflects BMS’s information security risk profile
  • Act as an Information Security subject matter specialist to the business
  • Establish mechanisms, behaviours and culture to encourage the protection of BMS information and information systems
Risk
  • Management and maintenance of the Information Security Risk Register, ensuring risks are actively managed or exemptions are managed and recorded.
  • Completion of InfoSec risk assessments and workshops.
  • Ensuring that InfoSec risk governance and control frameworks are maintained and that risks/issues are reported and escalated appropriately.
  • Review, challenge and track the implementation and effectiveness of controls and risk mitigation treatment plans as a result of a risk assessment
  • Ensure appropriate management focus for any vulnerability that could damage the confidentiality, integrity or availability of BMS information or information systems.
  • Track and record information security incidents and to ensure risk mitigation controls are appropriate and proportionate and that exposure is minimized.
  • Support the Information Security Incident response process as required
  • Facilitate a process of continuous improvement in the delivery of information security services to BMS
Compliance
  • To track requirements and compliance with relevant legislation, regulations, standards and frameworks as they pertain to Information Security
  • Measure the performance and compliance of key BMS controls which include (but are not limited to):
  • Management and maintenance of a rolling 12-month compliance schedule
What we’re looking for
  • Proven experience in Information Security GRC functions (10+ year) with senior roles held
  • Cyber Risk expert (experience of multiple frameworks and standards)
  • Able to work with technical and wider business colleagues in driving good business outcomes that align with business risk appetite
  • Excellent writing and communication skills
  • Significant experience and success in managing multiple issues, problems and work streams with a clear ability to prioritise
  • Excellent understanding of general information security concepts and principals
  • Exposure to cyber incident management frameworks and recovery concepts.
  • Experience developing and maintaining written security controls, compliance monitoring, and defining treatment strategies.
  • Expert knowledge of regulations and industry standards as applicable to the insurance sector (e.g. NIST Cybersecurity Framework, GDPR, DORA, SWIFT etc)
  • Personally demonstrate the five BMS values and ensure that team members are aligned with these:

We put clients first

We work as one

We find a way

We sweat the details

We take ownership

What’s in it for me?

This is a permanent role, offering a competitive salary and bonus, 27 days holiday, plus access to our personalised benefits platform, Your Rewards, including:

  • comprehensive private medical cover for you and your dependents
  • complimentary annual health checks
  • access to a virtual 24hr GP
  • gym subsidy & dedicated wellbeing support
  • opportunity to purchase equity
  • extra day’s leave to celebrate your birthday

Through our Diversity, Equality and Inclusion (DEI) vision, we are committed to ‘building a culture of belonging for all, valuing diverse perspectives and embracing authenticity.’ As such, we have created our ‘BMS Together’ programme, with dedicated training, collaborative committees and intentional partnerships. In support of our ESG vision, we offer two additional paid days each year to take part in charitable work.

BMS offers flexible and hybrid working policies and we’re happy to discuss options with you upon application. Please let our team know if you require any adjustments to support you through the application process.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security GRC Specialist
Information Security GRC Specialist

Motor Insurers' Bureau (MIB) • Milton Keynes

Hybrid
GBP 55,000 - 70,000
Contributory Group Pension scheme
Life Assurance
Employee Incentive Scheme
+5
Information Security GRC Manager
Information Security GRC Manager

AJ Bell • Manchester

Hybrid
GBP 65,000 - 85,000
27 days’ holiday
Pension with matched contributions up to 8%
Discretionary bonus and share awards
+3
Information Security Officer
Information Security Officer

SBS • Bristol

Hybrid
GBP 55,000 - 60,000
Private Medical Insurance
Health Cash Plan
Dental Insurance
+6
Security Consultant
Security Consultant

M&G • City of Edinburgh

Hybrid
GBP 80,000 - 110,000
Pension up to 18%
Share Save plan
38 days annual leave
+2
Security Consultant
Security Consultant

M&G • Stirling

Hybrid
GBP 70,000 - 100,000
Pension up to 18%
Share Save Plan
38 days annual leave
+1
Security Assurance & Advisory Principal
Security Assurance & Advisory Principal

Marks and Spencer • Greater London

Hybrid
GBP 90,000 - 130,000
Colleague discount 20%
Holiday allowance
Discretionary bonus schemes
+3
Information Security Governance, Risk and Compliance Specialist
Information Security Governance, Risk and Compliance Specialist

GWI • Greater London

Hybrid
GBP 70,000 - 100,000
25 days annual leave
Health cash plan
4% pension matching
+6
Development Executive - Employee Benefits
Development Executive - Employee Benefits

DR&P Group • Stockport

On-site
GBP 35,000 - 55,000
25 days holiday
Company Pension Scheme
Discretionary annual bonus
+4
Principal Information Security Engineer
Principal Information Security Engineer

Manchester Digital • Manchester

On-site
GBP 70,000 - 95,000
26 days holiday
Pension 7% matched
Discretionary bonus
+6
Security Consultant
Security Consultant

M&G plc • City of Edinburgh

Hybrid
GBP 70,000 - 110,000
Pension scheme 18%
Share Save
Share Incentive Plan
+1