At a Glance
- Tasks: Lead security assurance in tech projects and ensure real-world risk management.
- Company: Fora, a forward-thinking company prioritising work-life balance and employee wellbeing.
- Benefits: Flexible working hours, 28 days leave, health cash plan, and gym discounts.
- Other info: Dynamic role with opportunities for personal growth and meaningful contributions.
- Why this job: Make a tangible impact on security while enjoying a hybrid work environment.
- Qualifications: Hands-on experience in information security and strong communication skills.
The predicted salary is between 60000 - 75000 £ per year.
The role is 4 days in the office and 1 day working from anywhere. As an Information Security Analyst, you will sit at the point where technology, delivery, and governance meet – embedding pragmatic security assurance into vendor selection, SaaS adoption, and project delivery. Your job is to make sure security risks are identified early, articulated clearly, and driven through to real, implemented controls. This is a hands-on, delivery-focused role. You will work closely with engineers, delivery teams, IT operations, and business owners to ensure security commitments translate into action – not just documents.
If you are technically credible, comfortable challenging designs constructively, and prefer practical outcomes over theoretical risk language, this role is built for you.
What you’ll be doing:
- Vendor & SaaS Security Assurance
- Identity and access controls
- Data protection
- Hosting environments
- Vulnerability management
- Incident response
Translate technical findings into clear risk statements, practical mitigations, and informed acceptance options, maintaining evidence suitable for investor, audit, and assurance review.
Secure Project Delivery:
- Secrets management and credential handling
- Access lifecycle and permissions
- Key rotation and logging expectations
You will engage early in projects and technical change, shaping security before designs are finalised. You will work pragmatically with delivery teams (including those using tools like Azure DevOps), integrating security into delivery plans – not adding friction at the end.
Operational Risk Follow-Through:
- Tracking remediation actions
- Following up on overdue items
- Escalating issues with evidence, impact, and clear options – not abstract theory
Risk & Governance Support:
- Maintain a decision-focused risk register, ensuring it reflects real control posture and delivery reality.
- Prepare concise risk summaries and evidence packs for senior decision-makers and contribute to improving governance processes where they genuinely help clarity, accountability, and delivery.
Why this role is different:
- Not policy-only
- Not compliance-led
- Focused on real delivery, real controls, and real outcomes
Requirements:
Essential experience:
- Hands-on experience in information security roles spanning technical and assurance responsibilities
- Experience assessing vendors, SaaS platforms, or third parties
- Strong understanding of:
- Cloud and SaaS security
- Identity and access management
- Secrets management and key rotation
- Vulnerability management
- Comfortable working with engineers and delivery teams
- Able to communicate risk clearly, pragmatically, and credibly
Desirable:
- Experience supporting investor-led, audit, or assurance requirements
- Familiarity with modern delivery tooling (e.g. Azure DevOps)
- Exposure to secure design or architecture reviews
- Comfortable in fast-moving environments with low tolerance for heavy process
Benefits:
At Fora, we believe work should enhance your life – not compete with it. Our benefits support your wellbeing, fuel your ambitions, and give you the freedom to live and work your way.
- Work Your Way: Core working hours with flexibility – because life doesn’t run 9-5. Two weeks ‘Work from Anywhere’ – swap your desk for a beach, a mountain, or anywhere that inspires you.
- Time to Rest & Recharge: 28 days’ annual leave + bank holidays. Your birthday off – celebrate you. Buy additional annual leave to create even more time for what matters.
- Wellbeing & Security: 5% matched pension scheme – supporting your future. Life assurance for peace of mind. Discounted gym membership to keep you feeling your best. Health cash plan – supporting day-to-day medical expenses. Mental wellbeing support – confidential in-person or online therapy sessions.
- Smarter, Greener Commuting: Cycle to Work Scheme. Season Ticket Loan to make your journey easier and more affordable.
- Perks That Make You Smile: 25% off at Fora cafés – your morning coffee just got better. 2 volunteer days/year.
InfoSec Governance & Delivery Lead (Hybrid) employer: Fora Space Limited
At Fora, we prioritise a work culture that enhances your life, offering a hybrid working model that allows for flexibility and personal growth. With generous benefits including 28 days of annual leave, a matched pension scheme, and mental wellbeing support, we empower our employees to thrive both personally and professionally. Join us in a hands-on role where your contributions directly impact security outcomes, all while enjoying the unique advantage of working from inspiring locations.
StudySmarter Expert Advice🤫
We think this is how you could land InfoSec Governance & Delivery Lead (Hybrid)
✨Tip Number 1
Get your networking game on! Connect with folks in the InfoSec space, especially those who work at companies you're eyeing. LinkedIn is a goldmine for this – drop them a message, ask about their experiences, and see if they can give you the inside scoop on the hiring process.
✨Tip Number 2
Prepare for those interviews like a pro! Research the company’s security practices and be ready to discuss how you can add value. Think about real-world examples where you've tackled security challenges and be ready to share them – it shows you’re not just about theory but practical outcomes.
✨Tip Number 3
Don’t underestimate the power of follow-ups! After an interview, shoot a quick thank-you email to express your appreciation and reiterate your interest in the role. It keeps you fresh in their minds and shows you’re genuinely keen on the position.
✨Tip Number 4
Apply through our website! We love seeing candidates who take that extra step. Plus, it gives you a chance to showcase your enthusiasm for the role right from the start. So, don’t hold back – get your application in and let’s make things happen!
We think you need these skills to ace InfoSec Governance & Delivery Lead (Hybrid)
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in information security, especially around vendor assessment and SaaS platforms. We want to see how your skills align with the role, so don’t hold back on showcasing your hands-on experience!
Be Clear and Concise:When writing your application, keep it straightforward. Use clear language to articulate your technical findings and risk assessments. We appreciate candidates who can communicate complex ideas simply, as this reflects the practical outcomes we value.
Show Your Passion for Delivery:This role is all about real delivery and outcomes, so make sure to express your enthusiasm for embedding security into project delivery. Share examples of how you've integrated security into past projects and how you’ve worked closely with delivery teams.
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it gives you a chance to explore more about our culture and values!
How to prepare for a job interview at Fora Space Limited
✨Know Your Stuff
Make sure you brush up on your knowledge of information security, especially around vendor and SaaS security assurance. Be ready to discuss specific examples from your past experience where you've identified risks and implemented controls. This will show that you're not just familiar with the theory but can apply it in real-world scenarios.
✨Speak Their Language
When discussing technical findings, focus on translating complex risk statements into clear, actionable insights. Use practical examples to illustrate your points, and avoid jargon that might confuse your audience. This will demonstrate your ability to communicate effectively with both technical teams and business stakeholders.
✨Show Your Hands-On Experience
Since this role is delivery-focused, be prepared to share specific instances where you've worked closely with engineers and delivery teams. Highlight how you've integrated security into project plans without causing friction, showcasing your ability to balance security needs with operational efficiency.
✨Prepare for Real-World Scenarios
Expect questions that challenge you to think critically about security risks in practical situations. Prepare to discuss how you would handle various scenarios, such as tracking remediation actions or escalating issues. This will help you demonstrate your problem-solving skills and readiness for the hands-on nature of the role.