At a Glance
- Tasks: Manage security risks and ensure compliance in a fast-paced health-tech environment.
- Company: Join Accurx, a leader in transforming NHS healthcare productivity.
- Benefits: Enjoy a £50k salary, flexible working, and free meals in our Shoreditch office.
- Other info: Be part of a Tech for Good movement with excellent career growth opportunities.
- Why this job: Make a real impact on patient care while developing your skills in information security.
- Qualifications: 3-5 years in information security, with experience in risk management and Cyber Essentials Plus.
The predicted salary is between 48661 - 59475 £ per year.
Accurx is solving healthcare productivity for the NHS. For decades, the NHS has struggled with fragmented systems that make simple tasks feel impossible. At Accurx, we’re changing that by building a single, system-wide platform that helps every patient get gold-standard, efficient, and joined-up care. What started as a way for GPs to text a patient has now evolved into an all-in-one digital toolkit used by 98% of GP practices. Our platform now powers Total Triage to manage patient demand, and Self-Book, which lets patients schedule their own appointments in seconds. We’ve automated routine care with Patient Questionnaires for long-term conditions, while Accumail finally allows staff-to-staff communication to happen instantly across different care settings. We’re now pushing the boundaries of the consultation itself with Accurx Scribe, our AI-powered note-taker that drafts medical notes in real-time. We’re not just shipping features. We’re giving clinicians their time back and ensuring every patient journey is as smooth as it should be.
How this role sits within the function:
- Reports to: Senior Information Security Officer
- Function: Privacy & Information Security
- Contract type: Twelve-month fixed-term contract
This role works day-to-day alongside the Senior Information Security Officer, who owns the GRC framework, ISO 27001 programme, CE+ and DSPT compliance, and the security risk register. It provides dedicated capacity to push forward priority workstreams - particularly risk management, CE+ audit readiness, and data strategy delivery.
Challenges you’ll solve:
- Own the security risk register: Facilitate risk assessment sessions with technical and non-technical stakeholders across the business, keep the register current and accurate, and prepare clear risk reporting that translates technical risk into business language.
- Drive Cyber Essentials Plus readiness: Coordinate evidence gathering across IT, Platform and Security Engineering ahead of the CE+ deep-dive audit, reviewing controls against requirements and flagging gaps with practical remediation guidance.
- Deliver our data classification programme: Work with data owners to classify information assets in line with policy, and push the access control programme forward by reviewing current access patterns and identifying gaps.
- Keep risk treatment moving: Track risk treatment actions and follow up with owners so items progress rather than stall, managing milestones and blockers across the risk, CE+, and data workstreams.
- Support the wider security programme: Contribute to ISO 27001 and DSPT activities where your work intersects, including evidence collection and control documentation, and support policy and process documentation as needed.
- Be a translator between security and the business: Communicate security requirements clearly to engineers, and help non-technical stakeholders understand risk well enough to act on it.
You should apply if:
- You have 3–5 years of hands-on experience in information security and risk management, ideally in health-tech or a regulated SaaS environment.
- You've run risk sessions, owned a risk register, and prepared risk reporting for senior stakeholders.
- You've worked through a Cyber Essentials Plus audit cycle yourself.
- You understand cloud infrastructure, endpoint management, identity and access controls, and network boundaries well enough to hold your own in a technical conversation - you don't need to be a developer.
- You have working knowledge of ISO 27001 and Cyber Essentials Plus, and know what 'proportionate' looks like in a fast-moving product company.
- You write and communicate clearly, structuring your thinking logically so people know what's expected of them and why.
- You're comfortable working at pace and without extensive hand-holding, managing your own workload and flagging blockers early.
- You care about what Accurx does, and understand that the data we protect belongs to patients and clinicians who trust us with it.
What’s in it for me?
- You'll be joining an established but fast-growing Tech for Good movement, led by our Principles and our mission to solve healthcare productivity.
- £50k salary
- Benefits to suit you: adjust your healthcare cover, your pension or life insurance, whatever stage you’re at in life.
- Flexible working: We are an office-first culture and ask that you’re in our (dog-friendly) Shoreditch office 3 days a week, with core hours of 10 am - 4 pm.
- Time off: You’ll get 28 days of holiday (plus bank holidays) and up to 4 weeks to work from anywhere per year.
- We have our very own Chef! Free healthy breakfasts, snacks and lunches will be provided, with the occasional sweet treat!
Information Security & Risk Specialist (12-month FTC) in London employer: Jackalope Digital LLC
MoonPay is an exceptional employer that fosters a dynamic and collaborative work culture in the heart of London. With a strong emphasis on employee growth, you will have the opportunity to lead innovative projects in real-time fraud detection while working alongside talented professionals. The company offers competitive benefits and a commitment to high-velocity delivery, making it an ideal place for those seeking meaningful and rewarding employment.
StudySmarter Expert Advice🤫
We think this is how you could land Information Security & Risk Specialist (12-month FTC) in London
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Jackalope Digital LLC, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Jackalope Digital LLC
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Jackalope Digital LLC. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Information Security & Risk Specialist (12-month FTC) in London
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Jackalope Digital LLC insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Jackalope Digital LLC that you’re committed to staying ahead in the game.
How to prepare for a job interview at Jackalope Digital LLC
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Jackalope Digital LLC to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Jackalope Digital LLC.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.