Cyber Security Lead / Information Security Lead
Bedford | Hybrid β 1β2 Days per Week in the Office
Cyber Security | Information Security | GRC | ISO 27001 | ISMS | Security Audits | Infrastructure Security
Are you an experienced Cyber Security / Information Security professional with a technical background and strong GRC, ISO 27001 and security audit experience?
We're recruiting a Cyber Security Lead / Information Security Lead for a leading international SaaS software house, offering the opportunity to take broader ownership across Information Security, Cyber Security, GRC and security assurance.
The ideal candidate will have 5+ years' Cyber Security / Information Security experience, ideally having started within Infrastructure, Networks or Security Engineering before progressing into broader Information Security responsibilities.
Strong GRC and audit experience is essential. You'll need practical experience across ISO 27001, ISMS, internal/external security audits, risk management, policies, controls and compliance, combined with the technical credibility to work effectively with Infrastructure, IT Operations and Software Engineering teams.
The Role
Working closely with the Head of Information Security, you'll help strengthen the security posture of an international SaaS environment across Information Security, Cyber Security, GRC and technical security. You'll support and improve the ISMS and ISO 27001, lead/support security audits, risk and assurance activities, and work with technical teams across vulnerability management, patching, penetration testing, incident response and infrastructure security.
You'll also have involvement across supplier assurance, Cyber Essentials, business continuity, disaster recovery, DPIAs, BIAs, security policies and security awareness.
Skills & Experience
We're particularly interested in experience across:
- GRC & Audit: ISO 27001, ISMS, Internal/External Audits, Risk Management, Security Governance, Policies, Controls, Compliance and Assurance.
- Technical Security: Infrastructure Security, Network Security, Vulnerability Management, Patch Management, Penetration Testing, IAM, Endpoints and Cloud Security.
- Security & Resilience: Incident Response, Cyber Essentials, Supplier Assurance, Business Continuity and Disaster Recovery.
- Technical Background: Infrastructure, Networks, Security Engineering, IT Operations, Cyber Security or SaaS/Software environments.
The balance is important. We're not looking for a purely technical Security Engineer with limited GRC/audit exposure, or a purely compliance-led GRC candidate with limited technical understanding.
You may currently be working as an Cyber Security Lead, Information Security Lead, Senior Information Security Analyst, Senior Cyber Security Analyst, Information Security Consultant, Cyber Security Consultant, Technical Security Lead, Security Engineer or Infrastructure Security Engineer.
Why Consider It?
A great opportunity to join a leading international SaaS software business and step into a broader Information Security leadership position, combining your technical security background with greater ownership across GRC, ISO 27001, ISMS, audits and security strategy.
Bedford | Hybrid β 1β2 Days per Week in the Office
#J-18808-Ljbffr
Information Security Manager in Bedford employer: Nuvion Tech
As a Senior Project Manager in Central London, you will join a forward-thinking company that prioritises employee well-being with an excellent work-life balance and generous benefits, including 30 days of annual leave and a robust pension scheme. The collaborative work culture fosters professional growth, allowing you to lead transformative technology projects while engaging with diverse teams and stakeholders, making it an ideal environment for those seeking meaningful and impactful work.