At a Glance
- Tasks: Guide on information security, manage risks, and conduct audits.
- Company: Join a forward-thinking organisation focused on data protection and security.
- Benefits: Enjoy flexible working options and opportunities for professional development.
- Why this job: Make a real impact in safeguarding information while collaborating with diverse teams.
- Qualifications: A Levels or equivalent; recognised qualifications in information security required.
- Other info: Regular travel may be needed across operational areas.
The predicted salary is between 36000 - 60000 £ per year.
JOB PURPOSE: To provide expert guidance and specialist advice on all aspects of information assurance, security, and risk management. The role ensures the development and implementation of relevant policies, procedures, and processes necessary for compliance with national standards and codes of connection for information systems. This role includes maintaining the Information Security Incident Register, coordinating investigations into reported incidents, and recommending corrective measures to prevent recurrence. The postholder will also undertake onsite audits of facilities and assessments of third-party suppliers to ensure compliance with expected security and assurance standards. Additionally, the role supports departments with completing Data Protection Impact Assessments and offers professional advice on information assurance and security-related matters.
MAIN RESPONSIBILITIES:
- Support the Information Security and Assurance programme to ensure assurance and compliance processes meet national standards and reporting requirements (e.g. SyAP).
- Develop, review, and implement policies and best practices for managing information and cyber security, in alignment with organisational needs.
- Establish and apply techniques to regularly assess compliance of information assets with legal, regulatory, and best practice requirements.
- Serve as a point of contact for queries on information security and assurance.
- Plan and conduct information security audits and compliance checks, ensuring the security of systems, data, and physical assets across the organisation and third-party entities.
- Identify and assess security requirements, producing Risk Assessment Reports and reviewing related documentation for new or evolving systems, assets, and processes.
- Coordinate the investigation and reporting of information security incidents, ensuring appropriate remedial action is taken and trends are monitored.
- Prepare and deliver training, education, and awareness sessions related to information security, assurance, and risk management.
- Work collaboratively with key internal and external stakeholders-including third-party suppliers-ensuring best practices and compliance with relevant legislation and standards.
- Stay informed on developments in legislation, practices, and tools related to information security and data protection, fostering continuous improvement and innovation.
- Represent the organisation in internal and external meetings, promoting information security standards and contributing to relevant partnerships and working groups.
- Perform other duties as appropriate to the nature and level of the role.
Regular travel across operational areas may be required.
PERSON SPECIFICATION
Knowledge:
- A Levels or equivalent.
- Recognised qualification in information security, data protection, or risk (e.g. CISM, CISSP, CRISC, BCS DPO, etc.).
- In-depth understanding of ISO 27001, NIST, or other relevant security frameworks.
- Up-to-date knowledge of data protection legislation and associated best practices.
- Understanding of cross-functional areas affecting security (e.g. HR, procurement, tech infrastructure).
- Familiarity with principles of information confidentiality, integrity, and availability.
Experience:
- Operational delivery of security assurance in a multi-site environment.
- Managing compliance with standards like PSN or SyAP.
- Developing and enforcing information security and assurance policies.
- Performing internal audits and managing accreditation processes.
- Facilitating high-level stakeholder engagement.
- Collaborating with external agencies and partners on security issues.
Key Skills:
- Ability to manage workloads, meet deadlines, and adapt to changing priorities.
- Strong communication and interpersonal skills for influencing and explaining complex topics.
- Discretion and professionalism when handling sensitive information.
- Capability to work independently on complex investigations.
Information Security and Assurance Advisor employer: Jumar Solutions
Contact Detail:
Jumar Solutions Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Information Security and Assurance Advisor
✨Tip Number 1
Familiarise yourself with the latest information security frameworks like ISO 27001 and NIST. Understanding these standards will not only help you in interviews but also demonstrate your commitment to staying updated in the field.
✨Tip Number 2
Network with professionals in the information security sector. Attend relevant conferences or webinars, and engage with industry groups on platforms like LinkedIn. This can provide insights into the role and may even lead to referrals.
✨Tip Number 3
Prepare to discuss real-world scenarios where you've managed compliance or conducted audits. Having specific examples ready will showcase your practical experience and problem-solving skills during the interview.
✨Tip Number 4
Stay informed about recent developments in data protection legislation. Being able to discuss current trends and their implications for information security will set you apart as a knowledgeable candidate.
We think you need these skills to ace Information Security and Assurance Advisor
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience and qualifications that align with the job description. Emphasise your knowledge of information security frameworks like ISO 27001 and any recognised certifications you hold.
Craft a Compelling Cover Letter: In your cover letter, explain why you're passionate about information security and how your skills can contribute to the organisation's goals. Mention specific experiences where you've successfully managed compliance or conducted audits.
Showcase Relevant Skills: Highlight key skills such as risk assessment, incident management, and stakeholder engagement. Use examples from your past roles to demonstrate your ability to handle complex investigations and communicate effectively.
Proofread Your Application: Before submitting, carefully proofread your application for any spelling or grammatical errors. A polished application reflects your attention to detail, which is crucial in the field of information security.
How to prepare for a job interview at Jumar Solutions
✨Showcase Your Knowledge of Security Frameworks
Make sure to highlight your understanding of ISO 27001, NIST, and other relevant security frameworks during the interview. Be prepared to discuss how you've applied these standards in previous roles, as this will demonstrate your expertise and suitability for the position.
✨Prepare for Scenario-Based Questions
Expect questions that ask you to respond to hypothetical security incidents or compliance challenges. Practise articulating your thought process and the steps you would take to resolve such issues, as this will showcase your problem-solving skills and practical knowledge.
✨Emphasise Your Communication Skills
Since the role involves liaising with various stakeholders, be ready to discuss how you've effectively communicated complex security concepts to non-technical audiences. Share examples of training sessions or presentations you've delivered to illustrate your ability to engage and inform others.
✨Demonstrate Your Commitment to Continuous Improvement
Stay updated on the latest developments in information security and data protection legislation. During the interview, mention any recent training or certifications you've pursued, as well as how you plan to keep your skills current, showing your dedication to professional growth.