Business Information Security Officer
Business Information Security Officer

Business Information Security Officer

Full-Time 36000 - 60000 £ / year (est.) No home office possible
Go Premium
P

At a Glance

  • Tasks: Lead security initiatives and ensure compliance with industry standards in a dynamic tech environment.
  • Company: Join Precisely, a forward-thinking software company focused on data security and compliance.
  • Benefits: Enjoy competitive pay, flexible working options, and opportunities for professional growth.
  • Why this job: Make a real impact on data security while working with cutting-edge technology.
  • Qualifications: Experience in information security management and a strong understanding of compliance frameworks.
  • Other info: Collaborative team culture with excellent career advancement opportunities.

The predicted salary is between 36000 - 60000 £ per year.

Engage is a business unit within Precisely Software Incorporated, which produces a suite of SaaS and on-prem software products that handle personal data. We are looking for a Business Information Security Officer with experience aligning product design and delivery to information security compliance frameworks and privacy regulations. As part of the R&D team, the Business Information Security Officer will manage a team responsible for overseeing a range of technical and process security controls.

You will operate as one of several business unit and functional Business Information Security Officers and work within the Federated Infosec and Governance architecture under the guidance and governance frameworks of the Precisely Chief Information Security Officer and Chief Privacy Officer. You will be expected to align and maintain controls within the Precisely information security management system, ensuring compliance with company information security policies and efficacy of standard controls.

You will work with the Precisely InfoSec Compliance and Privacy teams as well as Precisely’s external auditors to maintain current and future certification to compliance frameworks and regulations. You will collaborate with internal product management, product development, and professional services teams to ensure that team practices are in line with policies and will communicate the security risks to Precisely InfoSec risk boards and management.

The role requires a thorough understanding of the technology underpinning the Engage software products, as well as a broad, up-to-date knowledge of information security frameworks, pertinent regulation and legislation, vulnerability management, incident management and response, secure development techniques and approaches, Cyber Security engineering and operations, and management and governance of Cyber Risk and Cyber Security. Having performed a similar role in a distributed organisation, you will have a strong information security background.

What you will do:

  • Information and Cyber Security Strategic Direction
    • Align to Precisely Information Security Management System across the Engage business unit that addresses the needs of Engage, staff, partners, customers, and other external stakeholders in line with relevant legislation and industry standards.
    • Maintain current SOC 1 & 2 Type II, HIPAA HITECH and ISO 27001 & 27701 certification for Engage software products.
    • Maintain documentation and processes necessary to comply with contractual obligations and customer security requirements.
    • Implement additional compliance in coordination with Precisely InfoSec Compliance as needed for each software product.
    • Maintain robust and fit-for-purpose operational procedures.
    • Ensure that the structures and reporting systems are in place to allow the Engage Information Security team to work with the Precisely CISO Office in maintaining the highest standards of quality, legal and regulatory compliance and corporate governance in all areas.
    • Provide advice and direction to the Engage Product Management team on how software products can comply with regulations.
    • Propose changes to the Engage Information and Cyber Security systems, processes and procedures by continuously analysing and reviewing appropriate security technologies and practices as informed by Precisely standards.
  • Security Operations
    • Ensure that information and Cyber Security risks to Engage are identified and managed appropriately.
    • Use and improve Precisely measures and metrics to support the assessment, reporting and ongoing improvement of the Engage information security posture.
    • Work closely with internal stakeholders to keep abreast of planned changes to technologies, working practices, and business activities that could have an impact on Engage’s Information Security or risk profile.
    • Maintain the Precisely information assurance framework for Engage, enforcing compliance with policies in conjunction with internal audit.
    • Align to Precisely standards and oversee Cloud Governance procedures for all infrastructure running in the cloud.
    • Coordinate quarterly DAST scans, annual internal pen testing and annual third-party penetration testing across all Engage products.
    • Maintain accurate security scorecards across all products. Work with product teams to prioritise work to improve security score. Communicate security risks to Precisely InfoSec Risk Board and senior leadership.
    • Coordinate monthly vulnerability scans for all internal and cloud-hosted infrastructure.
    • Achieve high scores in third party cybersecurity ratings including BitSight to maintain brand reputation for Engage assets.
    • Maintain accurate inventory of open-source component usage across Engage products. Coordinate legal review for use of components that breach policies.
    • Coordinate annual legal review of privacy across Engage products.
    • Ensure all Engage products comply with US cryptography export regulations.
    • Assist investigations into information security breaches under Precisely Incident Response process with Precisely CyberSecurity Operations Center ensuring root-causes of such breaches are understood and addressed.
  • Presales Subject Matter Expert
    • Assist as SME in responding to information security questionnaires during RFP process.
    • Write and maintain technical security whitepapers for Engage software products.

What we are looking for:

  • Experience
    • Management of an Information Security Management System in a complex IT organisation encompassing service delivery, application development and IT infrastructure.
    • Completion of Information Security questionnaires as part of RFP responses.
    • Line management of team members.
  • Knowledge
    • An excellent understanding of best practice within Information Security and risk management including standards such as ISO 27001.
    • A strong understanding of one or more areas of legislation and regulations that impact information Security E.g. GDPR, HIPAA, PCIDSS, CCPA.
    • An understanding of current and emerging threats and countermeasures and the product challenges to addressing these threats.
    • An understanding of Application Security threats and countermeasures.
    • A good practical knowledge of security technologies and wider business solutions including DevOps, Identity and Access Management, penetration testing tools, remote working and cloud technologies.
  • Skills
    • The ability to work within a compliance or regulatory framework and to evidence continuous improvement.
    • Excellent communication skills, both written and verbal. Ability to present complex or highly technical issues in simple and easy-to-understand formats.
    • An ability to think and plan strategically and systematically while recognising the need to deliver to the business requirements.
    • The ability to be pragmatic while balancing the needs of the business against security.
    • The ability to cut through organisational and political barriers to achieve the overall goal.
  • Qualifications
    • An appropriate degree, equivalent qualification or experience.
  • Preferred requirements
    • One or more of the following qualifications are highly desirable: Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Certified Information systems Auditor (CISA), Achieved Senior or Lead level certification in the NCSC’s Certified Cyber Professional scheme in one or more of Security and Information Risk Advisor (SIRA), IA Architect, IA Auditor, IT Security Officer.
    • Experience using GRC platforms to define and manage InfoSec policies, prepare for audits and manage risk.
    • Experience of tooling to manage RFP responses.
    • Perform SAST/DAST scans & Pen Test assessments.
    • Experience with automated cloud compliance.

The personal data that you provide as a part of this job application will be handled in accordance with relevant laws. For more information about how Precisely handles the personal data of job applicants, please see the Precisely Candidate Privacy Notice.

Business Information Security Officer employer: Precisely

At Precisely, we pride ourselves on fostering a dynamic and inclusive work culture that prioritises employee growth and development. As a Business Information Security Officer, you will be part of a collaborative R&D team dedicated to maintaining the highest standards of information security compliance, while enjoying comprehensive benefits and opportunities for professional advancement in a cutting-edge technology environment. Our commitment to innovation and excellence ensures that you will play a vital role in shaping the future of our software products, all within a supportive and forward-thinking organisation located in a vibrant tech hub.
P

Contact Detail:

Precisely Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Business Information Security Officer

✨Tip Number 1

Network like a pro! Get out there and connect with people in the industry. Attend events, join online forums, and don’t be shy about reaching out on LinkedIn. You never know who might have the inside scoop on job openings!

✨Tip Number 2

Prepare for interviews by researching the company and its products. Understand their security frameworks and compliance needs. This will help you tailor your answers and show that you're genuinely interested in the role.

✨Tip Number 3

Practice makes perfect! Conduct mock interviews with friends or use online platforms to get comfortable with common questions. The more you practice, the more confident you'll feel when it’s time to shine.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who are proactive about their job search!

We think you need these skills to ace Business Information Security Officer

Information Security Management System
Compliance Frameworks
ISO 27001
GDPR
HIPAA
PCIDSS
CCPA
Vulnerability Management
Incident Management
Cyber Security Engineering
Risk Management
DevOps
Identity and Access Management
Penetration Testing
Excellent Communication Skills

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the Business Information Security Officer role. Highlight your experience with information security compliance frameworks and any relevant certifications. We want to see how your background aligns with what we're looking for!

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how your skills can benefit our team. Keep it concise but impactful – we love a good story!

Showcase Relevant Experience: When filling out your application, be sure to showcase your experience in managing information security systems and compliance. Mention specific projects or achievements that demonstrate your expertise. We’re keen to see what you’ve accomplished!

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, it shows us you’re serious about joining the StudySmarter family!

How to prepare for a job interview at Precisely

✨Know Your Compliance Frameworks

Make sure you brush up on the key compliance frameworks relevant to the role, like ISO 27001 and HIPAA. Be ready to discuss how you've aligned product design with these regulations in your previous roles.

✨Showcase Your Technical Knowledge

Demonstrate a solid understanding of the technology behind the Engage software products. Be prepared to talk about security technologies, incident management, and secure development techniques that you've used in past experiences.

✨Prepare for Scenario Questions

Expect scenario-based questions where you'll need to explain how you'd handle specific security risks or compliance challenges. Think through examples from your past work where you successfully navigated similar situations.

✨Communicate Clearly and Confidently

Since excellent communication skills are crucial for this role, practice explaining complex security concepts in simple terms. This will help you convey your ideas effectively during the interview and show that you can bridge the gap between technical and non-technical stakeholders.

Business Information Security Officer
Precisely
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

P
  • Business Information Security Officer

    Full-Time
    36000 - 60000 £ / year (est.)
  • P

    Precisely

    500-1000
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>