At a Glance
- Tasks: Maintain and verify IT security controls and ensure operational readiness.
- Company: Join Ecosurety, a leading company committed to sustainability in Bristol's vibrant city centre.
- Benefits: Enjoy competitive salary, generous holiday, flexible working, and wellness support.
- Other info: Dynamic team culture focused on outputs and personal growth.
- Why this job: Make a real impact on sustainability while developing your IT compliance skills.
- Qualifications: Experience in IT operations or DevOps; familiarity with governance frameworks is a plus.
The predicted salary is between 45000 - 45000 £ per year.
This is a hands-on technical role in Ecosurety's IT team, focused on the day-to-day operational maintenance of our security posture, governance controls, and Business Continuity and Disaster Recovery (BCDR) programme. We are looking for a practical, detail-oriented technologist who enjoys the essential work of verifying controls in the real world. The successful candidate will be the checker who ensures our controls are not just documented, but verified, tested, and working.
Ecosurety is an industry leading company of 95+ people, based in the heart of Bristol's vibrant city centre, with a mission to accelerate change towards an environmentally and socially sustainable world. Our clients are many of the UK big brands and retailers, often facing particularly big challenges over their use of packaging. We are a Certified B Corp, committed to balancing profit with our social and environmental impact.
Job Description:
- Own the technical runbooks for our BCDR plan - ensuring backup, restoration, and off-site procedures are regularly tested and documented.
- Manage and resolve IT governance tasks flowing from Vanta, our compliance automation platform, maintaining a green status across all IT controls.
- Conduct regular access and identity reviews; enforce multi-tenant data isolation and least-privilege principles.
- Support audit readiness against NCSC Cyber Assessment Framework (CAF), CSA CAIQ, NIST, and our roadmap towards SOC 2.
- Establish and track quantifiable technical baselines - encryption coverage, log retention, API compliance (OWASP) and source-code analysis checks.
- Verify data input/output integrity routines across critical business systems.
- Turn high-level policies into step-by-step operational checklists and repeatable procedures for the IT team.
Person Specification:
- Broad exposure to IT operations, DevOps principles, or a related technical discipline.
- Familiarity with one or more governance frameworks (ISO 27001, NCSC CAF, NIST, SOC 2 or similar) - you do not need to be an expert in all of them.
- Process-driven mindset - able to translate policy into repeatable technical checklists.
- Strong communicator - comfortable writing clear evidence documentation for internal and client audits.
We do not recruit based only on skills. We give equal weight to behaviours and the successful candidate must be well aligned with the Ecosurety Values Framework. Specifically, we will be looking for examples of: Responsibility; Diligence; Clarity.
Package:
- c. £45,000 per year
- 12 month fixed term, full-time contract (would consider some flexibility for the right candidate)
- 28 days holiday plus 8 bank holidays
- 5 x salary life insurance, 7% employer pension contribution, up to 10% bonus, employee health cash plan, paid sick leave, critical illness cover, 2 weeks workcation, options to buy additional holiday or unpaid leave, 3 days volunteer leave, happy to talk flexible working, remote working, wellbeing support, great office location, £250 home working set up payment.
- Hybrid working: Employees are expected to work with colleagues (primarily at the office) at least 50% of the month.
Ecosurety offers a working environment that enables our team to perform at their best, with flexible hours, remote working options, access to training and employee benefits. We focus on outputs, rather than work location or hours. If you are well organised, enjoy working with others and eager to make a meaningful contribution, please get in touch!
We are an Equal Opportunities employer and welcome applications from all. We embrace flexibility and diversity in the workplace and aim to create a working environment in which all individuals can make best use of their skills, free from discrimination, harassment or bullying.
We reserve the right to bring forward the closing date of any of our job vacancies if we receive a suitable number of high-quality applications from which to make a shortlist. Therefore, we recommend that you apply for one of our roles as soon as possible rather than wait until the published closing date.
Junior IT Compliance & Assurance Specialist in Bristol employer: Ecosurety
Contact Detail:
Ecosurety Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Junior IT Compliance & Assurance Specialist in Bristol
✨Tip Number 1
Get to know the company inside out! Research Ecosurety's mission and values, and think about how your skills align with their goals. This will help you stand out in interviews and show that you're genuinely interested in being part of their team.
✨Tip Number 2
Network like a pro! Connect with current employees on LinkedIn or attend industry events. Building relationships can give you insider info about the company culture and even lead to referrals, which can be a game-changer in landing that job.
✨Tip Number 3
Prepare for practical assessments! Since this role is hands-on, brush up on your technical skills and be ready to demonstrate your knowledge during interviews. Think about real-world scenarios where you've applied your skills effectively.
✨Tip Number 4
Apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you're proactive and serious about joining the Ecosurety team. Don’t wait too long; get your application in ASAP!
We think you need these skills to ace Junior IT Compliance & Assurance Specialist in Bristol
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience with IT operations and governance frameworks. We want to see how your skills align with the role of Junior IT Compliance & Assurance Specialist, so don’t hold back on showcasing relevant projects!
Showcase Your Attention to Detail: Since this role is all about verifying controls and ensuring they work in the real world, be sure to include examples that demonstrate your meticulous nature. Whether it’s a project where you implemented a process or conducted audits, we love seeing that diligence in action!
Communicate Clearly: As a strong communicator, your application should reflect your ability to write clear and concise documentation. Use straightforward language and structure your application well, making it easy for us to see your qualifications and fit for the team.
Apply Early!: We recommend applying as soon as possible since we might close the vacancy early if we find the right candidate. Don’t wait until the deadline; get your application in through our website and show us why you’d be a great addition to Ecosurety!
How to prepare for a job interview at Ecosurety
✨Know Your Governance Frameworks
Familiarise yourself with the key governance frameworks mentioned in the job description, like ISO 27001 and NIST. Be ready to discuss how you've interacted with these frameworks in past roles or projects, even if you’re not an expert.
✨Demonstrate Your Process-Driven Mindset
Prepare examples that showcase your ability to turn high-level policies into actionable checklists. Think of specific instances where you’ve implemented processes or improved operational efficiency in IT settings.
✨Communicate Clearly
Practice articulating your thoughts clearly and concisely. Since strong communication is vital for this role, consider preparing a brief presentation on a technical topic relevant to the position, ensuring you can explain complex ideas simply.
✨Show Your Diligence and Responsibility
Reflect on past experiences where you demonstrated responsibility and diligence. Be ready to share stories that highlight your attention to detail and commitment to maintaining security and compliance standards.