Information Security Officer

Company: University College London
Apply for the Information Security Officer
Location: London
Job Description:

Overview

In this role within UCL’s CISO GRC team, you will help deliver governance, risk and compliance services to the university community. You’ll support security governance, risk assessments, policy development and awareness initiatives to meet UCL’s security requirements. You work closely with stakeholders to promote pragmatic, compliant security practices. The role offers impact across the university by shaping risk-informed policies and training. This is a chance to contribute to a large, research-led institution’s security posture and assurance culture.

Pay / Benefits

  • 41 days holiday (27 days annual leave, 8 bank holidays, 6 closure days)
  • CARE pension scheme
  • Cycle to work scheme
  • Relocation scheme for certain posts
  • On-site facilities (nursery, gym)
  • Employee assistance programme

Responsibilities

  • Support security governance, risk assessments and compliance reviews
  • Develop and update security policies and guidance
  • Deliver awareness and training materials for diverse audiences
  • Respond to security-related requests, queries or incidents
  • Promote and ensure compliance with UCL security requirements
  • Contribute to risk management activities and assurance activities

Key requirements

  • Experience supporting structured IT or information security services
  • Understanding of core IT concepts (networks, OS, authentication, cloud)
  • Awareness of information security controls and risk management
  • Experience contributing to policy, governance, assurance, compliance or risk management
  • Experience developing or delivering training/awareness materials
  • Strong written and verbal communication skills with ability to explain technical concepts to non-technical stakeholders
  • Relevant degree, professional qualification or equivalent experience
  • Strong communication skills
  • Ability to explain technical concepts to non-technical stakeholders
  • Training and guidance delivery
  • Networks
  • Operating systems
  • Authentication

Posted: September 16th, 2026