Information Security & Assurance Officer Salary: up to 50,000 + 15% Project Uplift + Company Car/Car Allowance Location: Suffolk (onsite) REED Technology are recruiting for an Information Security & Assurance Officer to join a major UK infrastructure programme. This is a fantastic opportunity for an information security professional who enjoys balancing security governance, compliance and assurance with oversight of operational cyber security activities. You'll play a key role in maintaining the organisation's Information Security Management System (ISMS), ensuring compliance with recognised security frameworks, managing risk and assurance activities, and acting as a trusted adviser to both technical and non-technical stakeholders. This role would suit someone with experience in Information Security, GRC, Information Assurance or Cyber Security who is looking to develop their career within a highly regulated and complex environment. Key Responsibilities Own and maintain the Information Security Management System (ISMS) Ensure compliance with ISO 27001, GDPR and wider security governance requirements Develop and maintain security policies, standards and procedures Conduct security risk assessments and support internal and external audits Manage supplier and third-party security assurance activities Provide oversight of Microsoft 365 security controls, including identity and access management, MFA, endpoint protection and monitoring Work closely with SOC and security service providers to support incident management and response activities Produce security reports, dashboards and assurance documentation for senior stakeholders Deliver security awareness initiatives across the organisation Support continuous improvement of security controls, processes and governance frameworks About You We're interested in speaking with candidates who can demonstrate experience in: Information Security Governance, Risk and Compliance (GRC) Information Security Assurance and risk management ISO 27001 and Information Security Management Systems (ISMS) GDPR and data protection requirements Security audits, compliance reviews and assurance activities Supplier or third-party security assessments Security incident management and response processes Microsoft security technologies such as Defender, Sentinel, Entra ID or similar platforms Building strong relationships with stakeholders at all levels Desirable Experience Cyber Essentials or Cyber Essentials Plus NIST Cyber Security Framework Experience within infrastructure, utilities, energy, defence, engineering, financial services or other regulated sectors Professional certifications such as CISSP, CISM, ISO 27001 Lead Auditor/Implementer, Security+ or equivalent What's on Offer? 15% project uplift paid monthly Company car or car allowance Annual bonus Private medical insurance Life assurance Enhanced pension contributions 25 days annual leave plus bank holidays Additional holiday purchase scheme Professional memberships paid Ongoing training and development opportunities This is an excellent opportunity to join a high-profile programme where you'll have real ownership of information security governance and assurance, while contributing to the success of a nationally significant project. If you are interested, apply using the link provided.
Aug 21, 2026
Full time
Information Security & Assurance Officer Salary: up to 50,000 + 15% Project Uplift + Company Car/Car Allowance Location: Suffolk (onsite) REED Technology are recruiting for an Information Security & Assurance Officer to join a major UK infrastructure programme. This is a fantastic opportunity for an information security professional who enjoys balancing security governance, compliance and assurance with oversight of operational cyber security activities. You'll play a key role in maintaining the organisation's Information Security Management System (ISMS), ensuring compliance with recognised security frameworks, managing risk and assurance activities, and acting as a trusted adviser to both technical and non-technical stakeholders. This role would suit someone with experience in Information Security, GRC, Information Assurance or Cyber Security who is looking to develop their career within a highly regulated and complex environment. Key Responsibilities Own and maintain the Information Security Management System (ISMS) Ensure compliance with ISO 27001, GDPR and wider security governance requirements Develop and maintain security policies, standards and procedures Conduct security risk assessments and support internal and external audits Manage supplier and third-party security assurance activities Provide oversight of Microsoft 365 security controls, including identity and access management, MFA, endpoint protection and monitoring Work closely with SOC and security service providers to support incident management and response activities Produce security reports, dashboards and assurance documentation for senior stakeholders Deliver security awareness initiatives across the organisation Support continuous improvement of security controls, processes and governance frameworks About You We're interested in speaking with candidates who can demonstrate experience in: Information Security Governance, Risk and Compliance (GRC) Information Security Assurance and risk management ISO 27001 and Information Security Management Systems (ISMS) GDPR and data protection requirements Security audits, compliance reviews and assurance activities Supplier or third-party security assessments Security incident management and response processes Microsoft security technologies such as Defender, Sentinel, Entra ID or similar platforms Building strong relationships with stakeholders at all levels Desirable Experience Cyber Essentials or Cyber Essentials Plus NIST Cyber Security Framework Experience within infrastructure, utilities, energy, defence, engineering, financial services or other regulated sectors Professional certifications such as CISSP, CISM, ISO 27001 Lead Auditor/Implementer, Security+ or equivalent What's on Offer? 15% project uplift paid monthly Company car or car allowance Annual bonus Private medical insurance Life assurance Enhanced pension contributions 25 days annual leave plus bank holidays Additional holiday purchase scheme Professional memberships paid Ongoing training and development opportunities This is an excellent opportunity to join a high-profile programme where you'll have real ownership of information security governance and assurance, while contributing to the success of a nationally significant project. If you are interested, apply using the link provided.
Chief Information Security Officer (CISO) Location: Hybrid Permanent ClearCourse is seeking an experienced Chief Information Security Officer (CISO) to lead and evolve our group wide security strategy across a diverse portfolio of 40+ software and payments businesses. Reporting to the Chief Technology & Transformation Officer, with a dotted line to the Board and Audit Committee, this is a pivotal executive leadership role responsible for security governance, operations, compliance, and risk management across a complex technology estate spanning payments, healthcare, and B2B SaaS. With ongoing M&A activity, active PCI-DSS obligations, and a rapidly evolving platform landscape, you'll play a critical role in protecting our customers, supporting business growth, and embedding security across the organisation. What you'll do Define and lead the Group's security strategy, policies, and governance framework Provide Board-level reporting on security posture, risks, and compliance activities Oversee security operations, including threat detection, incident response, and remediation Act as the executive lead during security incidents and manage external stakeholder communications Own PCI-DSS compliance across ClearAccept and ClearDebit payment platforms Lead the Group's Governance, Risk and Compliance (GRC) function, including ISO 27001, Cyber Essentials, PCI-DSS, and data protection obligations Manage relationships with auditors, regulators, cyber insurers, and certification bodies Lead security assessments and integration activities for acquisitions, driving alignment to Group standards Partner with Platform Engineering teams to embed security practices into development lifecycles without impacting delivery velocity Lead and develop the GRC function to support a proactive and risk aware security culture Previous experience operating at CISO level within a multi-product or multi-entity organisation Hands on experience leading PCI DSS compliance programmes and QSA assessments Proven expertise building and managing enterprise wide GRC frameworks and risk registers Experience assessing and integrating security functions following M&A activity Strong understanding of DevSecOps principles and embedding security into engineering practices Experience leading major security incidents, including external communications and stakeholder management Ability to influence at Board and executive leadership level Strong leadership skills with experience building and developing high performing security teams Competitive salary + benefits 25 days holiday + your birthday off Private medical insurance (Bupa) & health cash plan Life assurance & income protection Enhanced parental leave & family wellbeing support Perkbox discounts & perks Generous pension contributions Hybrid working model This is a rare opportunity to shape and lead the security strategy of a fast growing international software and payments group. You'll work at executive level, influence critical business decisions, and play a key role in safeguarding the future growth of the organisation. If you're passionate about security leadership and thrive in complex, evolving environments, we'd love to hear from you.
Aug 07, 2026
Full time
Chief Information Security Officer (CISO) Location: Hybrid Permanent ClearCourse is seeking an experienced Chief Information Security Officer (CISO) to lead and evolve our group wide security strategy across a diverse portfolio of 40+ software and payments businesses. Reporting to the Chief Technology & Transformation Officer, with a dotted line to the Board and Audit Committee, this is a pivotal executive leadership role responsible for security governance, operations, compliance, and risk management across a complex technology estate spanning payments, healthcare, and B2B SaaS. With ongoing M&A activity, active PCI-DSS obligations, and a rapidly evolving platform landscape, you'll play a critical role in protecting our customers, supporting business growth, and embedding security across the organisation. What you'll do Define and lead the Group's security strategy, policies, and governance framework Provide Board-level reporting on security posture, risks, and compliance activities Oversee security operations, including threat detection, incident response, and remediation Act as the executive lead during security incidents and manage external stakeholder communications Own PCI-DSS compliance across ClearAccept and ClearDebit payment platforms Lead the Group's Governance, Risk and Compliance (GRC) function, including ISO 27001, Cyber Essentials, PCI-DSS, and data protection obligations Manage relationships with auditors, regulators, cyber insurers, and certification bodies Lead security assessments and integration activities for acquisitions, driving alignment to Group standards Partner with Platform Engineering teams to embed security practices into development lifecycles without impacting delivery velocity Lead and develop the GRC function to support a proactive and risk aware security culture Previous experience operating at CISO level within a multi-product or multi-entity organisation Hands on experience leading PCI DSS compliance programmes and QSA assessments Proven expertise building and managing enterprise wide GRC frameworks and risk registers Experience assessing and integrating security functions following M&A activity Strong understanding of DevSecOps principles and embedding security into engineering practices Experience leading major security incidents, including external communications and stakeholder management Ability to influence at Board and executive leadership level Strong leadership skills with experience building and developing high performing security teams Competitive salary + benefits 25 days holiday + your birthday off Private medical insurance (Bupa) & health cash plan Life assurance & income protection Enhanced parental leave & family wellbeing support Perkbox discounts & perks Generous pension contributions Hybrid working model This is a rare opportunity to shape and lead the security strategy of a fast growing international software and payments group. You'll work at executive level, influence critical business decisions, and play a key role in safeguarding the future growth of the organisation. If you're passionate about security leadership and thrive in complex, evolving environments, we'd love to hear from you.
Security Compliance Officer Location: Colchester - Essex - must be commutable Sector: Software & IT Services NO VISA SPONSORSHIP - MUST HAVE VALID RIGHT TO WORK A leading software and IT services company is seeking a Security Compliance Officer with experience in Cyber Essentials and/or Cyber Essentials Plus to take ownership of security compliance and certification activities across both internal systems and client environments. This is a key hire within a growing technical organisation where cybersecurity assurance, governance, and compliance are increasingly central to customer delivery and commercial growth. Key Responsibilities Lead and manage Cyber Essentials and Cyber Essentials Plus (CE+) assessments and certification activities Maintain and improve compliance with key frameworks including ISO 27001, GDPR, and internal security policies Conduct internal security audits, control reviews, and risk assessments Support evidence collection and audit readiness across technical teams Work closely with IT support, DevOps, and engineering teams to ensure security controls are implemented and maintained Handle client-facing security questionnaires and compliance requirements Assist in improving the organisation's overall security posture and governance framework Required Experience Experience working with Cyber Essentials and/or Cyber Essentials Plus frameworks and assessments Strong understanding of Cyber Essentials / Cyber Essentials Plus requirements Experience in information security, compliance, GRC, or IT security roles Familiarity with ISO 27001 or similar security frameworks Experience working with technical teams (MSP, software, or IT environments preferred) Desirable IASME Cyber Essentials Assessor/Auditor qualification ISO 27001 Lead Auditor or Implementation experience CISSP, CISM, CISA, or equivalent certifications Experience within MSP, SaaS, or software delivery environments Exposure to client-facing compliance or consultancy work What's on Offer Hybrid working (Essex-based office with flexibility) Opportunity to own and shape security compliance in a growing technical business Exposure to both internal security operations and external client compliance requirements Strong career progression into GRC, Security Manager, or Head of Compliance roles
May 20, 2026
Full time
Security Compliance Officer Location: Colchester - Essex - must be commutable Sector: Software & IT Services NO VISA SPONSORSHIP - MUST HAVE VALID RIGHT TO WORK A leading software and IT services company is seeking a Security Compliance Officer with experience in Cyber Essentials and/or Cyber Essentials Plus to take ownership of security compliance and certification activities across both internal systems and client environments. This is a key hire within a growing technical organisation where cybersecurity assurance, governance, and compliance are increasingly central to customer delivery and commercial growth. Key Responsibilities Lead and manage Cyber Essentials and Cyber Essentials Plus (CE+) assessments and certification activities Maintain and improve compliance with key frameworks including ISO 27001, GDPR, and internal security policies Conduct internal security audits, control reviews, and risk assessments Support evidence collection and audit readiness across technical teams Work closely with IT support, DevOps, and engineering teams to ensure security controls are implemented and maintained Handle client-facing security questionnaires and compliance requirements Assist in improving the organisation's overall security posture and governance framework Required Experience Experience working with Cyber Essentials and/or Cyber Essentials Plus frameworks and assessments Strong understanding of Cyber Essentials / Cyber Essentials Plus requirements Experience in information security, compliance, GRC, or IT security roles Familiarity with ISO 27001 or similar security frameworks Experience working with technical teams (MSP, software, or IT environments preferred) Desirable IASME Cyber Essentials Assessor/Auditor qualification ISO 27001 Lead Auditor or Implementation experience CISSP, CISM, CISA, or equivalent certifications Experience within MSP, SaaS, or software delivery environments Exposure to client-facing compliance or consultancy work What's on Offer Hybrid working (Essex-based office with flexibility) Opportunity to own and shape security compliance in a growing technical business Exposure to both internal security operations and external client compliance requirements Strong career progression into GRC, Security Manager, or Head of Compliance roles