Information Security Lead
Information Security Lead

Information Security Lead

Runcorn Full-Time 36000 - 60000 £ / year (est.) Home office (partial)
C

At a Glance

  • Tasks: Lead the design and delivery of secure infrastructure services across various environments.
  • Company: Join a top UK provider transforming health and care services for millions.
  • Benefits: Enjoy remote work, private medical insurance, and access to discounts and wellbeing support.
  • Why this job: Make a real impact on security practices while working in a supportive, innovative culture.
  • Qualifications: Strong knowledge of cyber security principles and experience with compliance frameworks required.
  • Other info: This role is remote with occasional office visits; we value diversity and inclusivity.

The predicted salary is between 36000 - 60000 £ per year.

Overview

We are seeking a skilled and motivated Information Security Lead to support the strategic and operational delivery of information security and infrastructure controls across our digital estate. Reporting to the Head of Information Security and Enterprise Architecture, this role is responsible for driving compliance with cyber and data protection standards (including DSPT, CE+, and CAF), supporting the secure delivery of IT services, and embedding robust security practices across business-as-usual operations and new service transitions. Working within the Information Security and Architecture team, the postholder will serve as a senior technical lead across key domains, including cyber assurance, infrastructure security, policy development, and risk mitigation. You will collaborate with technical teams, service management, suppliers, and transformation programmes to deliver a resilient and secure digital environment. This role is ideal for a technically capable security practitioner or infrastructure expert looking to influence organisation-wide practices while supporting the Head of Information Security in delivering a future-ready, compliant, and secure service model.Base: This is a remote working role with occasional requirements to attend the head office in Runcorn.

Responsibilities

  • Support the design, delivery, and monitoring of secure infrastructure services across cloud, on-premises, and hybrid environments.
  • Ensure that security controls are applied consistently across networks, servers, endpoints, and backup environments (including Acronis and Barracuda solutions).
  • Support the implementation of technical standards and frameworks aligned with NHS DSPT, Cyber Essentials Plus (CE+), and the Cyber Assessment Framework (CAF).
  • Collaborate with the Infrastructure and Service Operations teams to deliver secure-by-design solutions.
  • Assist in maintaining the Information Security Management System (ISMS), policies, procedures, and risk registers.
  • Contribute to internal and external security audits, assessments, and evidence gathering.
  • Monitor and report on compliance status, raising risks and recommending mitigations where appropriate.
  • Deliver technical security input into supplier reviews, contract renewals, and new technology onboarding.

Qualifications

Essential

  • Strong understanding of information and cyber security principles, including access controls, network security, encryption, endpoint protection, and vulnerability management.
  • Practical experience supporting compliance with regulatory and best practice frameworks, including:
  • Data Security and Protection Toolkit (DSPT)
  • Cyber Essentials Plus (CE+)
  • Cyber Assessment Framework (CAF) or ISO 27001
  • Ability to assess security risks, develop mitigation plans, and communicate recommendations to technical and non-technical audiences.
  • Familiarity with NHS and public sector data protection responsibilities (e.g. NHS Data Security Standards, GDPR, DSP roles).
  • Experience participating in security incident response, post-incident reviews, and technical root cause analysis.
  • Knowledge of identity and access management, security logging/monitoring, and asset/information classification.
  • Strong documentation skills able to produce policies, procedures, risk registers, and audit evidence clearly and accurately.
  • Experience collaborating with Infrastructure, Digital Transformation, and Service Operations teams to embed secure-by-design principles.
  • Confident in engaging with external auditors, suppliers, and governance bodies to represent the organisation\\\’s security posture.

Desirable

  • Exposure to private cloud environments and related security tooling.
  • Experience in security toolsets such as antivirus/EDR, vulnerability scanners, SIEM, or MDM solutions.
  • Relevant industry qualifications (e.g. CompTIA Security+, SSCP, CISSP Associate, ISO 27001 Lead Implementer).
  • Knowledge of backup and DR security principles (experience with Acronis, Barracuda, or equivalent welcome).

About us

We change lives by transforming health and care. Established in 2006, we are one of the UKs leading independent providers of community health and care services, working with health and care commissioners and communities to transform services with a focus on experience, efficiency and improved outcomes. We deliver and transform adult and children community health services, primary care services including urgent care, sexual health, dermatology and MSK services as well as adult social care and wellbeing services. Across England, we support communities of many millions and directly help more than half a million people each year – guided by our simple values: we care, we think, we do. We are committed to equal opportunities and welcome applications from a broad, diverse range of people who want to join our team. We are a Disability Confident Committed company, so we work to provide facilities, work environment adjustments and technical solutions to be as inclusive of everyone.

Rewards and benefits

  • £45,000 – £55,000 with group pension
  • Private medical insurance with fast access to specialists across the country
  • Free tea, coffee and milk at your base location in Runcorn
  • Membership of My Reward Hub with discounts and cashback
  • Access to wages as you earn them to help cover life emergencies
  • Online and face-to-face wellbeing support, career coaching and counselling
  • Access to eLearning, career pathways, and continuing professional development
  • An open, just culture encouraging ideas to help deliver our purpose, backed by innovation funding
  • A reputation for high clinical and quality standards, with many services rated good or outstanding by the Care Quality Commission

Job description and responsibilities (summary)

  • See above: responsibilities include security design, compliance and risk management, audits, and supplier engagements.

#J-18808-Ljbffr

Information Security Lead employer: Cyber UK

As a leading independent provider of community health and care services, we pride ourselves on fostering a supportive and inclusive work culture that prioritises employee wellbeing and professional growth. Our remote working flexibility, combined with competitive benefits such as private medical insurance and access to ongoing career development, makes us an excellent employer for those looking to make a meaningful impact in the health sector. Join us in transforming lives while enjoying a collaborative environment that values innovation and diverse perspectives.
C

Contact Detail:

Cyber UK Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Information Security Lead

✨Tip Number 1

Familiarise yourself with the specific compliance frameworks mentioned in the job description, such as DSPT, CE+, and CAF. Understanding these standards will not only help you in interviews but also demonstrate your commitment to the role.

✨Tip Number 2

Network with professionals in the information security field, especially those who have experience in NHS or public sector environments. Engaging with them can provide insights into the role and may even lead to referrals.

✨Tip Number 3

Stay updated on the latest trends and technologies in information security, particularly those related to cloud and hybrid environments. This knowledge will be crucial when discussing secure-by-design solutions during interviews.

✨Tip Number 4

Prepare to discuss your experience with security incident response and risk mitigation strategies. Be ready to share specific examples that highlight your problem-solving skills and technical expertise in this area.

We think you need these skills to ace Information Security Lead

Information Security Principles
Cyber Security Compliance
Data Protection Standards (DSPT, CE+, CAF)
Risk Assessment and Mitigation
Technical Documentation Skills
Incident Response and Root Cause Analysis
Identity and Access Management
Security Logging and Monitoring
Collaboration with Technical Teams
Knowledge of NHS Data Security Standards
Experience with Security Toolsets (e.g. EDR, SIEM)
Backup and Disaster Recovery Security Principles
Strong Communication Skills
Ability to Engage with External Auditors and Suppliers

Some tips for your application 🫡

Tailor Your CV: Make sure your CV highlights relevant experience in information security, compliance with frameworks like DSPT and CE+, and any technical skills that align with the job description. Use specific examples to demonstrate your expertise.

Craft a Strong Cover Letter: In your cover letter, express your passion for information security and how your background makes you a perfect fit for the role. Mention your experience with risk mitigation and collaboration with technical teams, as these are key aspects of the position.

Highlight Relevant Qualifications: If you have industry qualifications such as CompTIA Security+ or CISSP Associate, be sure to mention them prominently in your application. This will show your commitment to professional development and expertise in the field.

Showcase Soft Skills: The role requires strong communication skills to convey technical information to non-technical audiences. Highlight experiences where you've successfully communicated complex security concepts or collaborated with diverse teams.

How to prepare for a job interview at Cyber UK

✨Showcase Your Technical Expertise

As an Information Security Lead, it's crucial to demonstrate your strong understanding of information and cyber security principles. Be prepared to discuss specific frameworks like DSPT, CE+, and CAF, and share examples of how you've applied these in previous roles.

✨Prepare for Scenario-Based Questions

Expect questions that assess your ability to handle real-world security incidents. Prepare to discuss past experiences where you participated in incident response or post-incident reviews, highlighting your problem-solving skills and technical root cause analysis.

✨Emphasise Collaboration Skills

This role requires working closely with various teams, so be ready to talk about your experience collaborating with Infrastructure, Digital Transformation, and Service Operations teams. Share examples of how you've successfully embedded secure-by-design principles in past projects.

✨Demonstrate Strong Documentation Abilities

Since the role involves producing policies, procedures, and risk registers, highlight your documentation skills. Bring samples of your work if possible, and explain how clear documentation has contributed to compliance and security in your previous positions.

Information Security Lead
Cyber UK

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

C
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>