Information Security Officer

The Information Security Officer is responsible for supporting the effective management of information and cyber security across the business.

The role provides oversight, assurance and guidance relating to information assets, technology platforms, cloud services, third-party providers and business processes to preserve the confidentiality, integrity, availability and resilience of corporate and client information in line with legal, regulatory and business requirements.


Core Responsibilities



  • Support the Information Security Manager and business stakeholders to understand security objectives, regulatory requirements and information security risks, providing appropriate security advice, guidance and solutions that align with business needs.

  • Assist in the development, implementation and continual improvement of the Information Security Management System, ensuring alignment with corporate objectives, industry standards and regulatory requirements.

  • Support the identification, assessment, treatment and reporting of information security, cyber security, technology and third-party risks within the corporate risk management framework.

  • Assist in maintaining compliance with applicable regulatory, legal and contractual requirements, including FCA requirements, UK GDPR, Data Protection legislation and relevant security standards.

  • Conduct and support information security risk assessments, control reviews and assurance activities across business functions, technology platforms, cloud services and third-party suppliers.

  • Support the implementation and monitoring of security controls aligned to recognised frameworks including ISO 27001, NIST Cybersecurity Framework, CIS Controls and other applicable industry standards.

  • Provide security guidance and consultancy to projects, technology initiatives, cloud implementations and business change programmes to ensure security requirements are considered by design.

  • Assist in overseeing third-party and supplier security assurance activities, including due diligence assessments, security reviews and ongoing monitoring of supplier risk.

  • Support internal and external audits, regulatory reviews and certification activities, ensuring audit findings, recommendations and remedial actions are effectively managed and tracked to completion.

  • Assist in the development, implementation and review of information security policies, standards, procedures and supporting documentation to ensure they remain current, effective and aligned with organisational requirements.

  • Support security awareness, education and training programmes to promote a positive security culture and ensure colleagues understand their information security responsibilities.

  • Assist in the monitoring and reporting of security metrics, key risk indicators, control effectiveness and compliance activities, providing management with meaningful security and risk information.


Skills/Experience



  • Track record of two years or more implementing information security practices within an organisation.

  • Good background in information management, with clear understanding of the challenges of information and IT security.

  • An excellent knowledge of relevant information security standards and practices.

  • Solid technical knowledge and experience of security technologies (e.g.

    endpoint protection, mobile security, data protection, cloud security) and cyber security capabilities (SIEM, SOC, CERT, vulnerability management, threat intelligence).

  • Strong knowledge of the main information security standards and frameworks (in particular ISO 27001, Cyber Essentials Plus).

  • A good understanding of, and experience in, implementing information security within cloud-based environments.

  • Experience and skills in the project management of corporate information security projects.

  • Demonstrated leadership abilities that energise multi-discipline work teams to respond to business needs.

  • Excellent oral and written communication skills, with the ability to present and explain information security in a way that establishes rapport, persuades others and gains understanding across the organisation.


Qualifications



  • Industry certifications in information security.

  • Degree in Information Systems, information security or a closely related subject.

  • Certifications in information security (e.g.

    CISSP, CISM, ISO 27001, ISO 22301) would be a plus.



Core-Asset Consulting is an equal opportunities recruiter and we welcome applications from everyone irrespective of age, disability, gender, gender identity or expression, race, colour, ethnic or national origin, sexual orientation, religion or belief, marital/civil partner status or pregnancy.



To apply for this vacancy applicants must be eligible to work in the UK in accordance with the Immigration, Asylum and Nationality Act 2006.



At Core-Asset, we're committed to protecting and respecting your privacy.

Our privacy statement explains when and why we collect personal information about people who engage with our services, how we use it, the conditions under which we may disclose it to others, and how we keep it secure.

We may change this policy from time to time, so please check this policy occasionally to ensure that you're happy with any changes.



By engaging with us (either by applying for a job we're advertising, registering through our website, or getting in touch with our business) you're agreeing to be bound by this policy.



Core-Asset Consulting is committed to protecting the privacy of our candidates, clients and website users.

For further information, please refer to our full Privacy Statement available on our website http://www.core-asset.co.uk/about-core-asset/privacy-statement



Core-Asset Consulting offers specialist recruitment services to asset management, accounting & finance, asset servicing, legal and the wider financial services sector in Scotland.




Share Job