Overview
In this role you lead the firm’s information security assurance activities and maintain ISO 27001:2022 across the organisation. You coordinate audits, manage policy lifecycles, and drive continual improvement of security governance to meet regulatory and client obligations. You will work with enterprise risk to ensure controls remain effective and aligned with business objectives. You help translate complex governance topics into practical outcomes and support client requests related to security assurance.
Responsibilities
- Own and maintain the ISO 27001:2022 ISMS
- Coordinate internal and external certification audits
- Manage the lifecycle of policies, standards and supporting documentation
- Facilitate management reviews and support continual improvement activities
- Ensure security governance processes align to business objectives and evolving risk
- Design and operate a programme of security control testing and assurance activities
- Assess the effectiveness of administrative, technical and operational controls
- Produce assurance reports and communicate outcomes to stakeholders
- Monitor remediation activities and support closure of identified weaknesses
- Develop assurance dashboards, metrics and management reporting
- Support ongoing maturity of the security governance framework
- Review the impact of regulatory, industry and client requirements on the control environment
- Contribute to internal security awareness and governance initiatives
- Support external client requests relating to security assurance and certification activities
- Facilitate identification, assessment and evaluation of security risks
- Provide analysis and recommendations to support risk-based decisions
- Monitor risk treatment activities and provide challenge where appropriate
- Support risk acceptance and exception management processes
Key requirements
- Experience operating or supporting an ISO 27001 ISMS
- Knowledge of information security control frameworks and assurance methodologies
- Knowledge of Cyber Essentials Plus
- Ability to assess the effectiveness of security controls and identify improvement opportunities
- Experience coordinating audit, certification or assurance activities
- Ability to translate technical and governance topics into practical business outcomes
- Experience presenting security findings, recommendations and risk information to stakeholders
- Experience identifying, assessing and managing information security risks
- Understanding of information security threats, vulnerabilities and control environments
- Experience applying risk management principles, frameworks and methodologies
- Ability to evaluate the potential business impact of security risks and control gaps
- strong communication to stakeholders
- problem solving
- risk-focused mindset
- ISO 27001 Information Security Management System
- security control frameworks (e.g., NIST CSF, CIS Controls, SOC 2)
- assurance methodologies
…
