Overview
In this role you will support the maturity of Vitality’s cyber security capabilities, protecting member data and strengthening controls. You will work cross-functionally across security operations, governance, and risk to drive the Information Security Strategy. You’ll monitor systems, investigate incidents, and help implement secure software development and third-party due diligence. This hybrid, full-time position offers meaningful impact in a purpose-driven, award-winning environment.
Pay / Benefits
- Bonus schemes
- Pension up to 12% (company matches up to 6%)
- Vitality health insurance
- Life assurance (four times annual salary)
Responsibilities
- Provide security guidance to business units and technology teams
- Develop and maintain the Information Security Management System (ISO27001 compliance)
- Monitor security tools, investigate issues, and escalate incidents
- Detect, manage, and respond to cyber security incidents, including on-call duties
- Enhance technical security controls across the business
- Support penetration testing and remediation of findings
- Embed security risk considerations in the SDLC with project teams
- Conduct security due diligence of third-party partners
- Contribute to security awareness, training, and playbooks
- Produce security metrics and insights for continuous improvement
Key requirements
- Minimum two years’ experience in an Information Security role
- Understanding of information security principles, frameworks and regulatory requirements including ISO27001 and data protection standards
- Experience monitoring security tools and supporting incident management
- Knowledge of vulnerability management, RBAC, PAM, patch management, DLP or antivirus technologies
- Ability to communicate complex concepts to technical and non-technical audiences
- Strong analytical skills to assess risk and propose practical solutions
- Experience identifying and implementing process improvements
- Proactive and collaborative, able to work independently and in teams
- Clear communication
- Analytical thinking
- Proactive collaboration
- Vulnerability management
- RBAC
- PAM
…
