Information Security & Assurance Officer in Ipswich

Information Security & Assurance Officer in Ipswich

Ipswich Full-Time 45000 - 55000 € / year (est.) No home office possible
Bachy Soletanche

At a Glance

  • Tasks: Ensure cybersecurity controls and compliance for a major infrastructure project.
  • Company: Join the world's largest specialist geotechnical contractor with a global community.
  • Benefits: Enjoy competitive salary, bonuses, private medical insurance, and generous leave.
  • Other info: Dynamic environment with opportunities for professional growth and development.
  • Why this job: Make a real impact on the UK's clean energy future while advancing your career.
  • Qualifications: Degree in computer or cybersecurity and familiarity with key security standards.

The predicted salary is between 45000 - 55000 € per year.

The Geotechnical Sub Alliance (GSA) is at the forefront of the Sizewell C nuclear power station development—one of the UK’s largest and most exciting infrastructure programmes. We’re responsible for preparing the foundations of the entire site: designing and constructing cut‑off walls, retaining structures, soil improvements and more. Using advanced geotechnical engineering and world‑class construction technologies, this is a rare opportunity to contribute to a national project that will shape the UK’s clean‑energy future.

The Information Security & Assurance Officer ensures GSA implements all mandatory information and cybersecurity controls required under the client Information Security Management Plan (ISMP), associated security documents and all security governance requirements agreed by parent company representatives.

Key Responsibilities
  • Assurance of GSA systems, including O365, identity, MFA, endpoint controls and office locations.
  • Integration with client SOC monitoring, log availability, incident reporting.
  • Compliance across onshore and offshore teams.
  • Ensuring flow‑down to downstream subcontractors.
  • IS027001 alignment, implementing an ISMS and leading on incident management to provide a business wide, good cyber security posture.
Governance & Compliance
  • Implement client ISMP controls across GSA, enforcing SAL, export‑control, classification and data‑handling rules.
  • Ensure subcontractor security flow‑downs and maintain governance evidence, documentation and audit materials.
  • Support client/partner security reviews and monitor compliance with GDPR/DPA, NIS2 (as applicable), and sector standards (PSN/NHS DSPT).
O365 Security
  • Provide assurance and governance over identity & access, O365 baseline compliance, data protection, logging and monitoring.
SOC Integration
  • Oversee log availability, security monitoring, alerting, incident response and SOC standards.
Assurance & Risk
  • Own the ISMS (policies, standards, procedures).
  • Complete required assessments (TPSA, SRA, DPIA, ECIA) and submit evidence for approval.
  • Track remediation, review suppliers, manage security awareness, and govern tooling/technology.
Stakeholder Engagement
  • Act as a trusted adviser to IT, projects and business units.
  • Deliver security awareness and phishing campaigns and manage actions with suppliers, MSSPs, SOC and auditors.
Continuous Improvement
  • Identify optimisation and automation opportunities; contribute to roadmap and stay current with industry trends.
Core
  • Promote company/client values and support a positive safety culture.
  • Demonstrable experience in information security assurance and technical cyber operations within a UK organisation.
  • Working knowledge of ISO/IEC 27001, Cyber Essentials Plus, NIST CSF, and UK GDPR / DPA 2018.
  • Hands‑on familiarity with modern security tooling (e.g., Microsoft Defender suite, Sentinel SIEM, EDR/XDR, vulnerability scanners).
  • Experience conducting/leading security incident response, root‑cause analysis, and post‑incident reviews including with SOC (internal or MSSP).
  • Ability to produce clear assurance reports, policies/standards, and executive‑level dashboards.
  • Excellent stakeholder management; able to translate technical risk into business impact and pragmatic actions.
Qualifications & Experience
  • A degree (or suitable experience) in a computer or cybersecurity subject.
  • Familiarity with ISO 27001, Cyber Essentials Plus, NIST CSF, and UK GDPR.
  • Familiarity with SANS 20 critical security controls and UK Top 10/Cyber Essentials.
Why us?

When you join the world’s largest specialist geotechnical contractor, you’re part of an international community of over 10,000 experts, based in 31 countries around the world. You’ll have the opportunity to contribute to prestigious, ground‑breaking projects, using the very latest tools and technology to solve complex problems, constantly learn new skills and take your career in any direction.

Benefits
  • Discretionary annual bonus (based on personal/project performance).
  • Salary Sacrifice Pension Scheme (min. 5% company contribution).
  • Enhanced Sick Pay (after probation).
  • Income Protection, Private Medical Insurance and Life Assurance.
  • Employee Assistance Programme.
  • 25‑days annual leave + Bank Holidays per year (increasing with service).
  • Option to purchase additional annual leave.
  • Paid annual professional memberships.
  • Volunteering days.
  • Professional growth and development.

Bachy Soletanche is committed to equal opportunities in employment with the aim of ensuring that everyone who applies to work for us receives fair treatment. We positively encourage applications from suitably qualified and eligible candidates regardless of age, disability, ethnicity, sex, gender identity, sexual orientation, religion or belief and pregnancy/maternity.

Information Security & Assurance Officer in Ipswich employer: Bachy Soletanche

At Bachy Soletanche, we pride ourselves on being an exceptional employer, offering a dynamic work culture that fosters innovation and collaboration. As part of the Geotechnical Sub Alliance for the Sizewell C project, you will not only contribute to a landmark infrastructure initiative but also benefit from comprehensive professional development opportunities, a generous benefits package including enhanced sick pay and private medical insurance, and a commitment to equal opportunities in the workplace.

Bachy Soletanche

Contact Detail:

Bachy Soletanche Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Security & Assurance Officer in Ipswich

Tip Number 1

Network like a pro! Reach out to people in the industry, attend events, and connect on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Prepare for interviews by researching the company and its projects. Understand their values and how your skills align with their goals. This will help you stand out as a candidate who truly gets what they’re about.

Tip Number 3

Practice your responses to common interview questions, especially those related to information security and compliance. Use the STAR method (Situation, Task, Action, Result) to structure your answers and showcase your experience effectively.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our team at GSA.

We think you need these skills to ace Information Security & Assurance Officer in Ipswich

Information Security Management
Cybersecurity Controls
ISO/IEC 27001
GDPR Compliance
NIST CSF
O365 Security
Incident Response

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Information Security & Assurance Officer role. Highlight your experience with ISO/IEC 27001, Cyber Essentials Plus, and any relevant cybersecurity projects you've worked on. We want to see how your skills align with what we're looking for!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how you can contribute to our mission at GSA. Be sure to mention specific experiences that relate to the job description.

Showcase Your Technical Skills:Don’t forget to highlight your hands-on experience with modern security tools like Microsoft Defender and Sentinel SIEM. We love seeing candidates who can demonstrate their technical prowess and how it relates to the role.

Apply Through Our Website:We encourage you to apply through our website for the best chance of getting noticed. It’s super easy, and you’ll be able to keep track of your application status. Plus, we love seeing applications come directly from our site!

How to prepare for a job interview at Bachy Soletanche

Know Your Stuff

Make sure you brush up on your knowledge of ISO/IEC 27001, Cyber Essentials Plus, and NIST CSF. Familiarity with these standards will not only help you answer technical questions but also show that you're serious about the role.

Showcase Your Experience

Prepare to discuss specific examples from your past work where you've successfully managed information security incidents or compliance issues. Use the STAR method (Situation, Task, Action, Result) to structure your answers clearly.

Engage with Stakeholders

Since stakeholder management is key for this role, think of ways you've effectively communicated technical risks to non-technical audiences. Be ready to share how you’ve built trust and collaborated with different teams.

Stay Current

Demonstrate your commitment to continuous improvement by discussing recent trends in cybersecurity or new tools you've explored. This shows that you're proactive and eager to bring fresh ideas to the table.