Information Security Specialist

Company: deciphex
Apply for the Information Security Specialist
Location: Kidlington
Job Description:

Location:

  • Living & working full time in either Ireland or UK only
  • Willingness & flexibility to travel to UK locations, when required to support InfoSec work. (Kidlington & Exeter) – circa varies 1-3 days per quarter
  • Very Occasional travel to Dublin HQ (Glasnevin) as needed to support audit work

Right to Work

  • We are unable to offer UK or Irish visa sponsorship for this role.

Reporting & work team

  • You’ll report to and work closely with the Information Security Lead, as well as Cybersecurity Engineering, DevOps, IT, Data Governance, and AI Governance to embed secure-by-design practices across the organisation.

About this Role

  • Information security underpins all of our business activities, including AI development
  • and compliance with Medical Device regulations
  • This role is ideal for a hands-on security specialist who supports the ISMS, validates controls for themselves, and drives continuous improvement with energy and pragmatism.
  • This role moves away from traditional GRC and leans into modernising it – moving teams towards always-on compliance and consistently demonstrating business value in the activities we run.
  • You’ll work across the business as someone who meets challenges head-on, brings people with them, and makes security work in practice, not just on paper.

More specifically;

  • This role involves protecting systems and data that directly support cancer diagnostics and drug development, security work with real-world consequence.
  • This is a hands-on, delivery-focused role suited to someone who thrives in a very fast-moving environment.
  • Success requires a pragmatic approach, strong judgement, and the ability to navigate challenges, remove obstacles, and drive progress at pace.

ISMS & Certifications

  • We hold ISO 27001 certification across our core business units and are expanding coverage as we grow.
  • Support the day-to-day running of the ISO 27001 ISMS across our Deciphex business units (Deciphex, Diagnexia & Patholytix)
  • Prepare for internal and external audits so that teams are ready, controls are functioning, and evidence is complete. Audit readiness as a steady state.
  • Contribute to continuous improvement initiatives. Iidentify what needs to change, make the case, and see it through.
  • Proactively identify and close gaps in the control framework, driving corrective actions (CAPAs) to closure
  • Build and maintain a reliable evidence pipeline with clear ownership and high completeness.
  • Assess which ISMS activities deliver measurable business value – and be willing to challenge or retire processes that aren’t.

Security Governance & Risk

  • Maintain a live, decision-oriented risk register with owners and mitigation plans.
  • Champion a risk-aware culture where decisions are informed by risk, not paralysed by it.
  • Develop and maintain policies and procedures that reflect how the business actually operates (not a unworkable bottleneck)
  • Support vendor and customer security due diligence in support of commercial and product needs.
  • Contribute to tabletop exercises (e.g. incident response, business continuity)
  • Maintain awareness of applicable regulatory requirements (EU AI Act, GDPR, HIPAA, MDR/IVD) and ensure the ISMS remains aligned with our other Certifications and Standards

Technical Oversight

  • Define evidence expectations for technical controls (SIEM, EDR, MFA, RBAC, vulnerability management).
  • Go and check: verify controls independently rather than relying on assertions; if something looks wrong, investigate and resolve it.
  • Support site reliability and resilience initiatives

Awareness & Security Culture

  • Build engaging security awareness training that changes behaviour, not just completion rates.
  • Act as a visible, approachable point of contact for information security questions to enable change across the business
  • Translate security requirements into plain language for non-technical audiences without losing accuracy or impact.

What This Is Not

  • Not a paper-only ISMS role or tick-box compliance exercise. The clear expectation here is you take hands-on ownership of effective controls, not just documentation.
  • Not a technical incident response role. Security operations is handled separately.
  • Not a bureaucratic or gatekeeping function. Our priority goal is to enable the business, not slow it down.
  • Not a role for someone who prefers to escal… as a first port of call. We value/reward people who find the answer and move things forward.
  • Not a ‘policing’ role. We focus on shared responsibility and enabling teams to move fast safely.

Skills and Experience

Required

  • 5+ years in Information Security / ISMS operations.
  • Ideally in med tech/ clinical or lifesciences
  • Hands-on ISO 27001 exposur e — internal audit and management review experience.
  • Experience with external audit from both certified bodies and clients
  • Strong documentation and stakeholder-management discipline.
  • Ability to translate technical controls into practical action.
  • Familiarity with cloud security fundamentals

Preferred

  • Hands-on experience with

#J-18808-Ljbffr…

Posted: September 21st, 2026