At a Glance
- Tasks: Lead the implementation and management of ISO 27001 accreditation, ensuring robust information security.
- Company: Join a forward-thinking organisation committed to excellence in information security.
- Benefits: Competitive salary, professional development opportunities, and a collaborative work environment.
- Other info: Dynamic role with opportunities for career growth and skill development.
- Why this job: Make a real impact by enhancing information security across the organisation.
- Qualifications: Strong knowledge of ISO 27001 and experience in managing information security systems.
The predicted salary is between 59576 - 70089 £ per year.
We are looking to appoint a senior role to lead both the implementation and ongoing management of our ISO 27001 accreditation. This role will play a key part in designing and embedding the management system, before taking full ownership of its day‑to‑day operation, governance, and continuous improvement. Working closely with IT, Professional Standards and teams across the business, the role will ensure controls are robust, risks are effectively managed, and audit requirements are consistently met. There will be a significant focus on implementation in the initial phase, transitioning into long‑term ownership of the standard. This includes driving compliance, leading audit activities, overseeing risk management, and delivering clear reporting, alongside embedding a culture of information security across the organisation.
Candidates must have strong working knowledge of ISO 27001 and demonstrable experience in implementing and managing compliant information security management systems. You will develop a strong understanding of Gateley’s ISO 27001 accreditation and play a central role in both its implementation and ongoing management.
Key Responsibilities- Leading the implementation, embedding and ongoing management of the ISO 27001 Information Security Management System (ISMS)
- Managing, maintaining and continuously improving ISO 27001 certification, ensuring ongoing compliance with the standard
- Owning and developing the firm’s ISO 27001 documentation, ensuring policies, procedures, records and controls are robust, up to date and effectively managed
- Leading internal audit activity, including planning, execution, reporting and ensuring timely closure of actions, with clear updates to senior stakeholders
- Preparing for and managing external audits, acting as the primary point of contact for assessors and coordinating internal stakeholders
- Chairing and supporting governance forums, including preparing agendas, papers, and tracking actions through to completion
- Providing expert guidance to teams across the business on ISO 27001 and information security requirements, ensuring controls are understood and consistently applied
- Driving awareness and engagement across the organisation to embed a strong information security culture
- Managing client and supplier assurance activity, including responding to ISO 27001 security questionnaires and due diligence requests
- Working closely with IT, Professional Standards, Risk, HR and Operations to ensure controls are effectively embedded and operating as intended
- Leading the implementation and ongoing oversight of the ISO 27001 risk management framework and associated documentation
- Driving risk identification, assessment, treatment and monitoring activities across the business
- Working closely with risk owners to ensure risk registers, incident logs and supporting records are accurate, up to date and effectively managed
- Facilitating regular risk reviews and ensuring timely progression of mitigation and improvement actions
Quality Officer employer: Gateley
At Gateley, we pride ourselves on being an exceptional employer that fosters a culture of collaboration and continuous improvement. As a Quality Officer, you will not only lead the implementation of our ISO 27001 accreditation but also enjoy a supportive work environment that prioritises professional development and employee well-being. With a strong focus on information security and risk management, you'll have the opportunity to make a meaningful impact while working alongside dedicated teams in a dynamic and innovative setting.