At a Glance
- Tasks: Lead efforts to protect sensitive information and build a strong cybersecurity culture.
- Company: Join a fast-growing company focused on cybersecurity and compliance.
- Benefits: Enjoy flexible work arrangements and professional development opportunities.
- Why this job: Make a meaningful impact while working in a dynamic and supportive environment.
- Qualifications: Bachelor's degree in Computer Science or related field; 5+ years in information security required.
- Other info: Ideal for those passionate about cybersecurity and eager to grow their skills.
Job Title: Information Security Officer
Location: London – Hybrid (Monthly)
We are seeking a proactive and experienced Information Security Officer (ISO) to lead our efforts in protecting sensitive information, ensuring compliance, and building a robust cybersecurity culture.
Key Responsibilities
-
Strategy & Governance:
- Develop and maintain the company's information security policies, standards, and guidelines.
- Create and implement a comprehensive cybersecurity strategy aligned with business goals.
- Act as the primary advisor to senior leadership on cybersecurity risks and mitigation strategies.
-
Risk Management:
- Identify, assess, and mitigate security risks across the organization.
- Conduct regular risk assessments and vulnerability testing.
- Ensure compliance with regulatory requirements (e.g., GDPR, PCI DSS, SOC 2, ISO 27001).
-
Incident Response:
- Lead efforts to respond to security breaches and incidents, minimizing impact and ensuring a swift recovery.
- Establish and manage an incident response plan, including regular tabletop exercises.
-
Technology & Operations:
- Oversee security operations, including firewalls, intrusion detection systems, endpoint security, and SIEM tools.
- Partner with IT to implement secure architecture and configurations.
- Ensure data encryption and secure storage of sensitive customer information.
-
Training & Awareness:
- Develop and deliver security awareness training for employees to foster a security-conscious culture.
- Communicate complex security concepts to non-technical audiences effectively.
-
Vendor Management:
- Assess and manage the security posture of third-party vendors and partners.
- Conduct due diligence on vendors and ensure adherence to contractual security requirements.
Qualifications
Required:
- Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent experience).
- 5+ years of experience in information security, including leadership roles.
- Strong understanding of cybersecurity frameworks (e.g., NIST, ISO 27001).
- Experience with regulatory compliance and industry standards (e.g., GDPR, PCI DSS).
- Hands-on experience with security tools such as firewalls, IDS/IPS, and endpoint protection.
- Strong analytical and problem-solving skills.
Preferred:
- Relevant certifications such as CISSP, CISM, CEH, or CISA.
- Experience in the fintech or financial services industry.
- Knowledge of secure software development practices and DevSecOps principles.
What We Offer:
- Competitive salary and benefits package.
- Flexible work arrangements (in-office, remote, or hybrid).
- Professional development opportunities, including certifications and training.
- A chance to make a meaningful impact in a fast-growing company
InfoSec Officer employer: Harnham
Contact Detail:
Harnham Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land InfoSec Officer
✨Tip Number 1
Familiarize yourself with the latest cybersecurity frameworks like NIST and ISO 27001. Being well-versed in these standards will not only help you understand our security policies better but also demonstrate your proactive approach to potential challenges.
✨Tip Number 2
Showcase your experience with incident response and risk management during networking opportunities. Engaging in discussions about real-world scenarios can highlight your expertise and make you a memorable candidate.
✨Tip Number 3
Connect with professionals in the fintech or financial services industry. Building relationships with individuals in these sectors can provide insights into specific security challenges and trends that are relevant to our organization.
✨Tip Number 4
Consider obtaining relevant certifications like CISSP or CISM if you haven't already. These credentials not only enhance your knowledge but also signal to us that you're committed to continuous professional development in the field of information security.
We think you need these skills to ace InfoSec Officer
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in information security, particularly in leadership roles. Emphasize your understanding of cybersecurity frameworks and any hands-on experience with security tools.
Craft a Strong Cover Letter: In your cover letter, express your passion for cybersecurity and detail how your skills align with the responsibilities outlined in the job description. Mention specific experiences that demonstrate your ability to develop security policies and manage risks.
Showcase Certifications: If you have relevant certifications like CISSP, CISM, or CEH, make sure to include them prominently in your application. This will strengthen your candidacy and show your commitment to professional development.
Prepare for Technical Questions: Be ready to discuss your technical knowledge and experience during the interview process. Familiarize yourself with common cybersecurity challenges and be prepared to explain how you would address them.
How to prepare for a job interview at Harnham
✨Showcase Your Cybersecurity Knowledge
Be prepared to discuss your understanding of cybersecurity frameworks like NIST and ISO 27001. Highlight any relevant experience you have with regulatory compliance, such as GDPR and PCI DSS, as this will demonstrate your expertise in the field.
✨Demonstrate Leadership Skills
Since the role requires leadership, share examples from your past experiences where you led a team or project related to information security. Discuss how you managed risks and implemented security policies effectively.
✨Prepare for Incident Response Scenarios
Expect questions about how you would handle security breaches or incidents. Be ready to outline your approach to incident response, including how you would minimize impact and ensure a swift recovery.
✨Communicate Complex Concepts Simply
As part of the role involves training and awareness, practice explaining complex security concepts in simple terms. This will show your ability to communicate effectively with non-technical audiences, which is crucial for fostering a security-conscious culture.