Overview
As Senior Information Security Officer, you will drive Vitality’s security agenda across the business, translating strategy into actionable security programs. You’ll lead the Security Governance team, elevate ISO27001/ISMS, and align risk management with the Enterprise Risk Framework. You will partner with the CISO to embed security across projects, ensuring protection while enabling growth. This role offers a collaborative, impact-driven environment with a strong emphasis on culture and regulatory compliance.
Pay / Benefits
- Bonus schemes
- Pension matching up to 6% (up to 12% total)
- Health insurance with Vitality rewards
- Life assurance (four times salary)
Responsibilities
- Lead continuous improvement of ISO27001 framework and ISMS and ensure ongoing compliance
- Drive security initiatives to translate strategy into measurable impact
- Own and mature Information Risk management within the Enterprise Risk Framework
- Advise on regulatory requirements and best practices (ISO27001, GDPR, NIST, ITIL)
- Lead security governance forums and manage Information Security Governance team including Information Risk
- Embed security across projects and development lifecycles (SDLC, Agile) and identify/mitigate risks (including DPIAs)
- Oversee supplier and third-party security risk with Cyber Security Operations
- Develop and roll out policies, compliance reviews and security awareness/training programs
Key requirements
- 5+ years in Information Security
- Experience assessing and managing supplier/third-party risk
- Strong communication to translate technical concepts for business audiences
- Experience across SDLC and Agile environments
- Hands-on ISO27001 and broader governance frameworks (ISO27001/2, NIST, PCI DSS)
- Knowledge of data protection and regulatory requirements (FCA, ICO, PRA, GDPR)
- Ability to balance risk, compliance and business objectives in a fast-paced environment
- Strong communication
- Stakeholder management
- Security culture advocacy
- ISO27001/2
- NIST
- GDPR
…
