Information Security Consultant
Information Security & Assurance Officer
Salary: up to £50,000 + 15% Project Uplift + Company Car/Car Allowance
Location: Suffolk (onsite)
REED Technology are recruiting for an Information Security & Assurance Officer to join a major UK infrastructure programme. This is a fantastic opportunity for an information security professional who enjoys balancing security governance, compliance and assurance with oversight of operational cyber security activities.
You'll play a key role in maintaining the organisation's Information Security Management System (ISMS), ensuring compliance with recognised security frameworks, managing risk and assurance activities, and acting as a trusted adviser to both technical and non-technical stakeholders.
This role would suit someone with experience in Information Security, GRC, Information Assurance or Cyber Security who is looking to develop their career within a highly regulated and complex environment.
Key Responsibilities
- Own and maintain the Information Security Management System (ISMS)
- Ensure compliance with ISO 27001, GDPR and wider security governance requirements
- Develop and maintain security policies, standards and procedures
- Conduct security risk assessments and support internal and external audits
- Manage supplier and third-party security assurance activities
- Provide oversight of Microsoft 365 security controls, including identity and access management, MFA, endpoint protection and monitoring
- Work closely with SOC and security service providers to support incident management and response activities
- Produce security reports, dashboards and assurance documentation for senior stakeholders
- Deliver security awareness initiatives across the organisation
- Support continuous improvement of security controls, processes and governance frameworks
About You
We're interested in speaking with candidates who can demonstrate experience in:
- Information Security Governance, Risk and Compliance (GRC)
- Information Security Assurance and risk management
- ISO 27001 and Information Security Management Systems (ISMS)
- GDPR and data protection requirements
- Security audits, compliance reviews and assurance activities
- Supplier or third-party security assessments
- Security incident management and response processes
- Microsoft security technologies such as Defender, Sentinel, Entra ID or similar platforms
- Building strong relationships with stakeholders at all levels
Desirable Experience
- Cyber Essentials or Cyber Essentials Plus
- NIST Cyber Security Framework
- Experience within infrastructure, utilities, energy, defence, engineering, financial services or other regulated sectors
- Professional certifications such as CISSP, CISM, ISO 27001 Lead Auditor/Implementer, Security+ or equivalent
What's on Offer?
- 15% project uplift paid monthly
- Company car or car allowance
- Annual bonus
- Private medical insurance
- Life assurance
- Enhanced pension contributions
- 25 days annual leave plus bank holidays
- Additional holiday purchase scheme
- Professional memberships paid
- Ongoing training and development opportunities
This is an excellent opportunity to join a high-profile programme where you'll have real ownership of information security governance and assurance, while contributing to the success of a nationally significant project. If you are interested, apply using the link provided.