You will be a seasoned Information Security professional able to support and maintain governance and leading frameworks such as NIST CSF and the UK Cyber Assessment Framework (CAF) to identify, assess and manage risks across the Group. You will develop risk metrics (KPIs/KRIs), deliver security training and awareness programmes and lead third-party cyber, information and AI security due diligence. This would include ongoing monitoring of risks and incidents. The role also involves supporting audits, driving continuous improvement across policies and controls, and implementing monitoring solutions using Microsoft Purview and DLP. Working closely with the CISO and Cyber Security team, you will contribute to governance, reporting and incident response, while building strong stakeholder relationships across IT, Risk and the wider business.
in a nutshell, responsibilities include:
You are a proactive and detail-oriented Information Security professional with experience working in regulated environments and a passion for improving security maturity.
Together embraces diversity and inclusion, and are proud to be an equal opportunity workplace. Not only do we welcome difference - we celebrate it, support it and really value our colleagues for who they are. We are committed to building a team that represents a variety of backgrounds, perspectives and skills.