At a Glance
- Tasks: Strengthen information security governance and collaborate across teams to ensure secure operations.
- Company: Join Form3, a leader in innovative payment technology.
- Benefits: Competitive salary, remote work options, and a supportive team culture.
- Why this job: Make a real impact on security practices in a fast-paced tech environment.
- Qualifications: 5+ years in Information Security with strong knowledge of security frameworks.
- Other info: Dynamic team with opportunities for growth and development.
The predicted salary is between 36000 - 60000 ÂŁ per year.
As an Information Security Officer at Form3, you will play a pivotal role in strengthening and evolving our information security governance, risk, and compliance practices. Working within the Information Security team, you will help ensure that Form3 continues to operate securely and maintain the trust of our customers and partners.
You will work closely with teams across the organisation, from Engineering and Product to Legal and Risk teams, to embed security into business and technology decisions. This is a handsâon role that combines strategic oversight with practical execution, ensuring our controls, frameworks, and awareness initiatives remain industry leading as we scale globally.
What you will do:
- Apply expert knowledge of security frameworks and controls such as NIST, ISO22301, ISO27001, ISO27017/18, ISAE3000/SOC2, and GDPR to support security governance.
- Support the development, maintenance, and continual improvement of the ISMS and BCMS.
- Assist in drafting and maintaining Information Security Policies and ensure alignment with business and customer requirements.
- Contribute to the planning and execution of external audits, engaging directly with auditors and customers.
- Monitor and report on adherence to security controls across all areas of the business via risk assessments and internal audits.
- Assess and support the remediation of information security risks, nonâconformities, and issues across systems and services.
- Support vulnerability management processes, from triage and tracking to remediation reporting, in partnership with Offensive Security and Engineering teams.
- Conduct vendor and thirdâparty security assessments, ensuring suppliers meet Form3's security and compliance requirements.
- Partner with the Defensive Engineering team to ensure security requirements are built into product developments.
- Deliver and enhance security awareness and training initiatives to promote a strong security culture across Form3.
- Collaborate with the Security Operations team to maintain situational awareness of emerging threats and vulnerabilities, ensuring timely escalation and riskâbased response.
We are looking for:
- 5+ years' experience in Information Security, ideally within a fastâpaced technology or financial services industry.
- Strong working knowledge of frameworks such as ISO27001, ISO22301, SOC 1, SOC 2, NIST, and GDPR.
- Proven experience developing, implementing, and improving information security policies, standards, and controls aligned to recognised frameworks.
- Handsâon experience conducting audits, risk assessments, and business impact analyses.
- Handsâon experience with vulnerability management within a complex and dynamic cloud environment.
- Broad understanding of cloud security.
- Excellent communication and stakeholder engagement skills, with the confidence to influence at all levels of the organisation.
- Analytical mindset with a focus on continual improvement and measurable outcomes.
Desirable:
- Securityârelated qualifications such as CISSP, CISM, CISA, or ISO27001 Lead Implementer/Auditor.
- Experience leading certification and attestation programmes such as ISO27001, ISO22301 or SOC 2.
- Experience operating in regulated or highâavailability environments such as financial services, payments, or critical infrastructure.
- Familiarity with GRC tooling and automation to streamline compliance, risk, and control management activities.
This role sits within Form3's Information Security Governance, Risk and Compliance (GRC) team and reports directly to the Head of GRC. As part of a highly collaborative security function, you will play a key role in shaping how Form3 manages information security risk, compliance, and assurance across all areas of the business.
The GRC team underpins Form3's security standards, designing and maintaining the frameworks, policies, and controls that keep our people, systems, and customers safe. Joining at this stage offers the opportunity to make a significant impact, strengthening governance and compliance across a cloudânative environment while helping define how security scales with the business.
Interview Process:
- Stage 1: Screening Call with Talent Team
- Stage 2: Interview with Principal Security Officer
- Stage 3: Interview with Head of GRC
We always aim to stick to the above process; however, there may be occasions when an additional interview stage is needed for us to be sure we are hiring the right person!
Hiring Locations:
We are able to accept applications from the UK only. All new joiners start their first day in our office to collect the equipment needed to work remotely. We will also arrange for some of your team to come in to say hi, ensuring you are supported and have a positive first few days with Form3!
About Form3:
Revolutionising the world of payments with our cuttingâedge technology and innovative solutions.
Our DEI&B Commitment:
We hire talented people from a variety of backgrounds and experiences and are committed to a work environment based on diversity, openâmindedness and curiosity. We are united by our company values and we celebrate our unique differences.
Our employee lifecycle processes are designed to embrace equal opportunity and prevent discrimination against our people regardless of personal characteristics. It is our strong belief that the more inclusive and belonging we are as a business, the better our work will be.
As an inclusive employer, we guarantee to interview all neurodiverse and physically disabled applicants who meet the minimum criteria for this role. We also encourage candidates to notify us of any reasonable adjustments that may be required during the recruitment process.
Information Security Officer in London employer: Form3 - External
Contact Detail:
Form3 - External Recruiting Team
StudySmarter Expert Advice đ¤Ť
We think this is how you could land Information Security Officer in London
â¨Tip Number 1
Network like a pro! Reach out to your connections in the industry, attend relevant events, and engage with professionals on platforms like LinkedIn. We all know that sometimes itâs not just what you know, but who you know that can help you land that dream job.
â¨Tip Number 2
Prepare for those interviews! Research Form3 thoroughly, understand their security frameworks, and be ready to discuss how your experience aligns with their needs. Practising common interview questions can also give you the confidence boost you need.
â¨Tip Number 3
Showcase your skills! If youâve got hands-on experience with security audits or risk assessments, make sure to highlight that during your conversations. We want to see how you can bring value to the team right from the get-go.
â¨Tip Number 4
Donât forget to follow up! After your interviews, drop a quick thank-you email to express your appreciation for the opportunity. Itâs a simple gesture that can leave a lasting impression and keep you top of mind for the hiring team.
We think you need these skills to ace Information Security Officer in London
Some tips for your application đŤĄ
Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience with security frameworks like ISO27001 and NIST. We want to see how your skills align with what we're looking for, so donât hold back on showcasing your relevant achievements!
Show Your Passion: Let us know why you're excited about the role of Information Security Officer at Form3. Share your enthusiasm for driving security excellence and how you can contribute to our mission. A bit of personality goes a long way!
Be Clear and Concise: When writing your application, keep it straightforward and to the point. Use bullet points where possible to make it easy for us to read through your qualifications and experiences. We appreciate clarity!
Apply Through Our Website: We encourage you to submit your application directly through our website. This ensures that your application gets to the right people quickly and efficiently. Plus, itâs super easy to do!
How to prepare for a job interview at Form3 - External
â¨Know Your Frameworks
Make sure you brush up on your knowledge of security frameworks like ISO27001, NIST, and GDPR. Be ready to discuss how you've applied these in your previous roles, as this will show your expertise and understanding of the industry standards.
â¨Showcase Your Hands-On Experience
Prepare to share specific examples of your hands-on experience with audits, risk assessments, and vulnerability management. Highlight any complex situations you've navigated and how you contributed to improving security practices in your past roles.
â¨Engage with Stakeholders
Since this role involves collaboration across various teams, think about how you've successfully engaged with different stakeholders in the past. Be ready to discuss your communication style and how you influence decisions at all levels of an organisation.
â¨Demonstrate Your Analytical Mindset
Be prepared to talk about how you approach problem-solving and continuous improvement in information security. Share examples of measurable outcomes you've achieved and how you've used data to drive decisions and enhance security measures.