Senior Information Security Officer

Company: Vitality
Apply for the Senior Information Security Officer
Location: Bournemouth
Job Description:

Overview

As Senior Information Security Officer, you will drive Vitality’s security agenda across the business, translating strategy into actionable security programs. You’ll lead the Security Governance team, elevate ISO27001/ISMS, and align risk management with the Enterprise Risk Framework. You will partner with the CISO to embed security across projects, ensuring protection while enabling growth. This role offers a collaborative, impact-driven environment with a strong emphasis on culture and regulatory compliance.

Pay / Benefits

  • Bonus schemes
  • Pension matching up to 6% (up to 12% total)
  • Health insurance with Vitality rewards
  • Life assurance (four times salary)

Responsibilities

  • Lead continuous improvement of ISO27001 framework and ISMS and ensure ongoing compliance
  • Drive security initiatives to translate strategy into measurable impact
  • Own and mature Information Risk management within the Enterprise Risk Framework
  • Advise on regulatory requirements and best practices (ISO27001, GDPR, NIST, ITIL)
  • Lead security governance forums and manage Information Security Governance team including Information Risk
  • Embed security across projects and development lifecycles (SDLC, Agile) and identify/mitigate risks (including DPIAs)
  • Oversee supplier and third-party security risk with Cyber Security Operations
  • Develop and roll out policies, compliance reviews and security awareness/training programs

Key requirements

  • 5+ years in Information Security
  • Experience assessing and managing supplier/third-party risk
  • Strong communication to translate technical concepts for business audiences
  • Experience across SDLC and Agile environments
  • Hands-on ISO27001 and broader governance frameworks (ISO27001/2, NIST, PCI DSS)
  • Knowledge of data protection and regulatory requirements (FCA, ICO, PRA, GDPR)
  • Ability to balance risk, compliance and business objectives in a fast-paced environment
  • Strong communication
  • Stakeholder management
  • Security culture advocacy
  • ISO27001/2
  • NIST
  • GDPR

…

Posted: September 14th, 2026