At a Glance
- Tasks: Manage security risks and ensure compliance in a fast-paced health-tech environment.
- Company: Join Accurx, a pioneering tech company transforming NHS healthcare productivity.
- Benefits: Competitive salary, flexible working, generous holiday, and free meals.
- Other info: Be part of a mission-driven team dedicated to improving healthcare for everyone.
- Why this job: Make a real impact on patient care while developing your skills in information security.
- Qualifications: 3-5 years in information security, risk management, and familiarity with Cyber Essentials Plus.
The predicted salary is between 50000 - 50000 £ per year.
Accurx is solving healthcare productivity for the NHS. For decades, the NHS has struggled with fragmented systems that make simple tasks feel impossible. At Accurx, we’re changing that by building a single, system-wide platform that helps every patient get gold-standard, efficient, and joined-up care. What started as a way for GPs to text a patient has now evolved into an all-in-one digital toolkit used by 98% of GP practices. Our platform now powers Total Triage to manage patient demand, and Self-Book, which lets patients schedule their own appointments in seconds. We’ve automated routine care with Patient Questionnaires for long-term conditions, while Accumail finally allows staff-to-staff communication to happen instantly across different care settings. We’re now pushing the boundaries of the consultation itself with Accurx Scribe, our AI-powered note-taker that drafts medical notes in real-time. We’re not just shipping features. We’re giving clinicians their time back and ensuring every patient journey is as smooth as it should be.
How this role sits within the function:
- Reports to: Senior Information Security Officer
- Function: Privacy & Information Security
- Contract type: Six-month fixed-term contract
This role works day‑to‑day alongside the Senior Information Security Officer, who owns the GRC framework, ISO 27001 programme, CE+ and DSPT compliance, and the security risk register. It provides dedicated capacity to push forward priority workstreams - particularly risk management, CE+ audit readiness, and data strategy delivery.
Challenges you’ll solve…
- Own the security risk register: Facilitate risk assessment sessions with technical and non-technical stakeholders across the business, keep the register current and accurate, and prepare clear risk reporting that translates technical risk into business language.
- Drive Cyber Essentials Plus readiness: Coordinate evidence gathering across IT, Platform and Security Engineering ahead of the CE+ deep‑dive audit, reviewing controls against requirements and flagging gaps with practical remediation guidance.
- Deliver our data classification programme: Work with data owners to classify information assets in line with policy, and push the access control programme forward by reviewing current access patterns and identifying gaps.
- Keep risk treatment moving: Track risk treatment actions and follow up with owners so items progress rather than stall, managing milestones and blockers across the risk, CE+, and data workstreams.
- Support the wider security programme: Contribute to ISO 27001 and DSPT activities where your work intersects, including evidence collection and control documentation, and support policy and process documentation as needed.
- Be a translator between security and the business: Communicate security requirements clearly to engineers, and help non-technical stakeholders understand risk well enough to act on it.
You should apply if…
- You have 3–5 years of hands‑on experience in information security and risk management, ideally in health‑tech or a regulated SaaS environment.
- You’ve run risk sessions, owned a risk register, and prepared risk reporting for senior stakeholders.
- You’ve worked through a Cyber Essentials Plus audit cycle yourself.
- You understand cloud infrastructure, endpoint management, identity and access controls, and network boundaries well enough to hold your own in a technical conversation – you don't need to be a developer.
- You have working knowledge of ISO 27001 and Cyber Essentials Plus, and know what 'proportionate' looks like in a fast‑moving product company.
- You write and communicate clearly, structuring your thinking logically so people know what's expected of them and why.
- You’re comfortable working at pace and without extensive hand‑holding, managing your own workload and flagging blockers early.
- You care about what Accurx does, and understand that the data we protect belongs to patients and clinicians who trust us with it.
What’s in it for me?
- You’ll be joining an established but fast‑growing Tech for Good movement, led by our Principles and our mission to solve healthcare productivity.
- £50k salary
- Benefits to suit you: adjust your healthcare cover, your pension or life insurance, whatever stage you’re at in life.
- Flexible working: We are an office‑first culture and ask that you’re in our (dog‑friendly) Shoreditch office 3 days a week, with core hours of 10 am – 4 pm.
- Time off: You’ll get 28 days of holiday (plus bank holidays) and up to 4 weeks to work from anywhere per year.
- We have our very own Chef! Free healthy breakfasts, snacks and lunches will be provided, with the occasional sweet treat.
Information Security & Risk Specialist (6-month FTC) employer: Accurx Limited.
Accurx Limited is an exceptional employer located in the vibrant city of London, offering a dynamic work culture that fosters collaboration and innovation within the Privacy & Information Security function. Employees benefit from a supportive environment that prioritises professional growth, with opportunities to enhance their skills in information security and risk management while working on impactful projects. The company's commitment to data security and its focus on employee development make it a rewarding place for those seeking meaningful employment.
StudySmarter Expert Advice🤫
We think this is how you could land Information Security & Risk Specialist (6-month FTC)
✨Get Engaged in Cybersecurity Communities
Dive into online forums or local meetups, like OWASP events or Cybersecurity conferences. These spaces are packed with pros who can share insights and might even know about temporary roles at places like Accurx Limited..
✨Showcase Your Skills Publicly
Link your GitHub or create a series of blogs sharing your knowledge on cybersecurity topics. It’s a great way to demonstrate your expertise and attract attention from hiring managers, especially when they see your passion in action.
✨Stay On Top of Temp Opportunities
Keep an eye on platforms that list temporary positions specifically in tech. Websites focusing on contract roles in cybersecurity can lead straight to employers like Accurx Limited..
✨Make Contact with Recruiters Specialising in Cybersecurity
Reach out to recruitment agencies that focus on cybersecurity roles. They often have insights into temporary roles before they’re advertised and can put your name forward to companies like Accurx Limited..
We think you need these skills to ace Information Security & Risk Specialist (6-month FTC)
Some tips for your application 🫡
Show Off Your Technical Skills:In cybersecurity, it's vital to highlight your skills with relevant tools and technologies. Make sure your CV showcases your experience with firewalls, intrusion detection systems, and any cybersecurity frameworks you've worked with. This gives Accurx Limited. a clear view of your capabilities right off the bat.
Certifications Matter:If you’ve got any cybersecurity certifications, like CompTIA Security+ or CISSP, flaunt them! These not only validate your skills but also show that you’re committed to the field. Add a section to your CV specifically for this, because in a temporary role like this, those credentials can really set you apart.
Tailor Your Cover Letter to the Role:For a temporary position, we want to see your willingness to learn and adapt quickly. Make your cover letter specific to the role at Accurx Limited.; mention why you’re excited about the opportunity and how it fits your career goals. A personal touch can make a big difference!
Don’t Forget the Soft Skills:In cybersecurity, technical skills are crucial, but so are soft skills like teamwork and communication. Make sure to weave examples of how you've collaborated with teams or communicated complex ideas into your application. This shows that you're not just a tech whizz but also a great team player, perfect for a temporary role at Accurx Limited..
How to prepare for a job interview at Accurx Limited.
✨Brush Up on Technical Skills
Make sure you’re familiar with the latest cybersecurity tools and techniques, like firewalls, intrusion detection systems, and malware analysis. During the interview with Accurx Limited. for the Information Security & Risk Specialist (6-month FTC), be prepared to discuss specific scenarios where you tackled security threats or vulnerabilities.
✨Show Your Problem-Solving Prowess
Cybersecurity is all about thinking on your feet. Expect technical questions that require you to demonstrate your problem-solving abilities. You might be presented with a mock security breach scenario, so practising your responses to potential threats can be a game changer!
✨Demonstrate Your Adaptability
As this is a temporary role, showing that you're adaptable and quick to learn is crucial. Talk about times you've picked up new skills or reacted to changing situations quickly. Employers want to know you can hit the ground running and keep things secure during your short stay at Accurx Limited..
✨Bring Relevant Certifications
If you have any relevant cybersecurity certifications, like CompTIA Security+ or CEH, be sure to mention them. This can really help you stand out during a temporary hiring process, as it showcases your commitment to the field and your readiness to take on the Information Security & Risk Specialist (6-month FTC) role at Accurx Limited..