Information Security & Assurance OfficerSalary: up to £50,000 + 15% Project Uplift + Company Car/Car AllowanceLocation: Suffolk (onsite)REED Technology are recruiting for an Information Security & Assurance Officer to join a major UK infrastructure programme. This is a fantastic opportunity for an information security professional who enjoys balancing security governance, compliance and assurance with oversight of operational cyber security activities.You'll play a key role in maintaining the organisation's Information Security Management System (ISMS), ensuring compliance with recognised security frameworks, managing risk and assurance activities, and acting as a trusted adviser to both technical and non-technical stakeholders.This role would suit someone with experience in Information Security, GRC, Information Assurance or Cyber Security who is looking to develop their career within a highly regulated and complex environment.Key ResponsibilitiesOwn and maintain the Information Security Management System (ISMS)Ensure compliance with ISO 27001, GDPR and wider security governance requirementsDevelop and maintain security policies, standards and proceduresConduct security risk assessments and support internal and external auditsManage supplier and third-party security assurance activitiesProvide oversight of Microsoft 365 security controls, including identity and access management, MFA, endpoint protection and monitoringWork closely with SOC and security service providers to support incident management and response activitiesProduce security reports, dashboards and assurance documentation for senior stakeholdersDeliver security awareness initiatives across the organisationSupport continuous improvement of security controls, processes and governance frameworksAbout YouWe're interested in speaking with candidates who can demonstrate experience in:Information Security Governance, Risk and Compliance (GRC)Information Security Assurance and risk managementISO 27001 and Information Security Management Systems (ISMS)GDPR and data protection requirementsSecurity audits, compliance reviews and assurance activitiesSupplier or third-party security assessmentsSecurity incident management and response processesMicrosoft security technologies such as Defender, Sentinel, Entra ID or similar platformsBuilding strong relationships with stakeholders at all levelsDesirable ExperienceCyber Essentials or Cyber Essentials PlusNIST Cyber Security FrameworkExperience within infrastructure, utilities, energy, defence, engineering, financial services or other regulated sectorsProfessional certifications such as CISSP, CISM, ISO 27001 Lead Auditor/Implementer, Security+ or equivalentWhat's on Offer?15% project uplift paid monthlyCompany car or car allowanceAnnual bonusPrivate medical insuranceLife assuranceEnhanced pension contributions25 days annual leave plus bank holidaysAdditional holiday purchase schemeProfessional memberships paidOngoing training and development opportunitiesThis is an excellent opportunity to join a high-profile programme where you'll have real ownership of information security governance and assurance, while contributing to the success of a nationally significant project. If you are interested, apply using the link provided.
read more