Principal Information Security Officer

Location: Reading area – hybrid
Salary: Up to £70,000 basic
Contract: Permanent

About the Company

We are working with a large, privately owned technology distribution business operating across the UK and Europe. The organisation partners with some of the world's leading technology brands, supplying hardware, software and technology solutions through a large network of resellers, retailers and business customers.

Due to continued growth within the Information Security function, we are looking for a Principal Information Security Officer to provide senior security leadership and act as the key deputy to the Director of Cyber Security.

The Role

This is a senior position combining Information Security leadership, GRC, security architecture, compliance and hands-on security delivery.

You will take ownership of significant security initiatives and projects, provide guidance across the wider business and act as the senior point of escalation for the Information Security Officer.

The role requires someone who can move comfortably between strategic security requirements and practical implementation, working with technical teams to make sure security controls are properly designed, implemented and maintained.

Key Responsibilities

  • Act as the senior Information Security SME across GRC, ISMS, security architecture and compliance.

  • Support the Director of Cyber Security with the delivery of the wider security strategy and improvement plan.

  • Provide leadership, guidance and technical oversight to Information Security Officers within the team.

  • Lead significant security projects and initiatives from assessment and design through to implementation.

  • Own and drive improvements to the organisation's ISMS, security controls and overall cyber maturity.

  • Lead security assessments across infrastructure, networks, endpoints, applications, cloud environments and data.

  • Provide security input into technical architecture and design decisions.

  • Work with technical teams to implement appropriate security controls around identity, access management, SSO and federated services.

  • Oversee information security risk management, including risk registers, policy exceptions and remediation plans.

  • Lead and support ISO 27001, Cyber Essentials Plus, PCI-DSS, NIST/CIS Controls and customer compliance requirements.

  • Manage and provide assurance around internal and external audits, including remediation of findings.

  • Provide senior oversight of third-party/vendor security risk and critical supplier assurance.

  • Support security assurance for customer contracts and external stakeholder requirements.

  • Develop security reporting, KPIs and dashboards for senior management.

  • Work with security operations and engineering teams to identify vulnerabilities, manage remediation and improve security controls.

  • Provide security input into Data Protection Impact Assessments and wider business risk activity.

  • Act as a senior security representative when working with customers, suppliers, auditors and external technical stakeholders.

What We're Looking For

  • Strong experience in an Information Security, security consultancy, GRC or security architecture environment.

  • Proven hands-on experience implementing and improving ISO 27001 / ISMS and security controls.

  • Strong understanding of security frameworks including ISO 27001/27002, NIST, CIS Controls, PCI-DSS and Cyber Essentials Plus.

  • Experience leading security projects, audits, assessments and remediation programmes.

  • Strong understanding of information security risk and the ability to translate technical risks into practical remediation plans.

  • Experience working with enterprise IT, infrastructure, cloud and network teams.

  • Experience across cloud environments such as Microsoft 365, Azure, AWS or Google Cloud.

  • Understanding of security technologies and controls such as firewalls, endpoint security, vulnerability management, SIEM and identity security.

  • Strong stakeholder management skills, including experience dealing with senior business stakeholders, customers, suppliers and auditors.

  • A recognised security qualification such as CISSP, CISM, CISA, CCSP, ISO 27001 Lead Implementer/Auditor or equivalent.

  • Previous leadership, mentoring or technical oversight experience would be advantageous.

  • A practical approach to security, with the ability to take ownership of initiatives and see them through to delivery.

Location

The role operates on a hybrid basis, with occasional travel to UK offices and meetings with customers, suppliers and auditors.

Candidates should ideally be based within approximately one hour of the Reading area.