Information Security Officer – GRC & Compliance

Location: Reading area – hybrid
Salary: £55,000–£57,000 basic
Contract: Permanent

About the Company

We are working with a large, privately owned technology distribution business operating across the UK and Europe. The organisation partners with some of the world's leading technology brands, supplying hardware, software and technology solutions through a large network of resellers, retailers and business customers.

As the business continues to grow, its Information Security function is expanding and we are looking for an experienced Information Security Officer to join the team.

The Role

Reporting to the Director of Cyber Security, you will work across Information Security, GRC, ISMS, compliance and security consultancy, helping to maintain and improve the organisation's security controls and overall cyber maturity.

The role has a strong focus on hands-on implementation and assurance, rather than purely policy-based or theoretical security work. You will work closely with technical and business teams, customers, suppliers and auditors to demonstrate that security controls are operating effectively and that risks are being identified and managed.

Key Responsibilities

  • Maintain and continually improve the organisation's Information Security Management System (ISMS), including policies, procedures and controls.

  • Support the implementation and ongoing management of ISO 27001, Cyber Essentials Plus, PCI-DSS, NIST/CIS Controls and other relevant security requirements.

  • Conduct security assessments across infrastructure, networks, endpoints, applications and data.

  • Identify, assess and manage information security risks, including maintaining risk registers and tracking remediation.

  • Lead and support internal and external security audits, including evidence gathering, control testing and remediation of findings.

  • Manage technical security risks within Data Protection Impact Assessments and policy exceptions.

  • Support the vendor and third-party risk management programme, including assessment and ongoing monitoring of critical suppliers.

  • Work with technical teams around identity and access management, including SSO and federated services.

  • Provide security assurance for projects, systems and customer requirements.

  • Support security awareness and continuous improvement initiatives.

  • Produce security reporting, dashboards and metrics for senior stakeholders.

  • Work with the wider security team to deliver elements of the organisation's Security Improvement Plan.

  • Support security engagements with customers, suppliers, auditors and other external stakeholders.

What We're Looking For

  • At least 3 years' experience in an Information Security, GRC, compliance or security consultancy role.

  • Practical experience implementing and managing ISO 27001 / ISMS rather than purely theoretical knowledge.

  • Experience with security audits, control testing, risk assessments and remediation.

  • Knowledge of frameworks and standards including ISO 27001/27002, NIST, CIS Controls, PCI-DSS and Cyber Essentials Plus.

  • Experience developing and maintaining security policies and procedures.

  • Experience with third-party/vendor risk management and security assurance.

  • Understanding of cloud security across platforms such as Microsoft 365, Azure, AWS or Google Cloud.

  • Strong stakeholder management skills, with the ability to work with technical, business and external teams.

  • A security qualification such as CISSP, CISM, CISA, CCSP, ISO 27001 Lead Implementer/Auditor or equivalent would be advantageous.

  • A practical, methodical approach to identifying and managing security risks.

Location

The role operates on a hybrid basis, with occasional travel to UK offices and meetings with customers, suppliers and auditors.

Candidates should ideally be based within approximately one hour of the Reading area.