At a Glance
- Tasks: Lead the development and improvement of our Information Security Management System.
- Company: Join Ricoh, a global leader in innovative technology and digital workplaces.
- Benefits: Enjoy a competitive salary, industry-leading benefits, and career development opportunities.
- Why this job: Make a real impact on information security while working in a dynamic environment.
- Qualifications: Experience in information security and knowledge of ISO/IEC 27001 standards required.
- Other info: Be part of a diverse team that values innovation and collaboration.
The predicted salary is between 36000 - 60000 Β£ per year.
Ricoh transforms organisations, using innovative technologies and services enabling you as an individual to work smarter. This is what we call \βempowering digital workplaces\β.
In fact the entire Ricoh workforce enjoys our pioneering and innovative ways of working. We like to call it: imagine. change., it\βs the ethos of our brand and how we drive positive change for ourselves and others. Our teams are embracing change, fostering new ways of working and we have never been more resolute in our mission β \βyou work for us, and we`ll work for you\β.
- Audit & Compliance Experience: Conducting internal audits and working with external auditors.
- Policy Development: Drafting and enforcing security policy, standards and procedures.
- Incident Response Knowledge: Leading or coordinating responses to security breaches or events.
- Lead the maintenance, development, and enhancement of the ISMS to ensure continued ISO/IEC 27001
- Conduct regular internal audits and risk assessments, ensuring timely remediation of any identified vulnerabilities or non-conformities.
- Establish and enforce information security policies, standards, and controls across the organisation.
- Act as the central authority and subject matter expert on information security within Ricoh Europe PLC.
- Monitor the threat landscape and coordinate incident response planning, including investigation, mitigation, and communication of security incidents.
- Oversee the security assurance programme, including third-party risk management and vendor assessments.
- Collaborate with IT, legal, HR, and business teams to integrate security principles into operational processes and projects.
- Promote a strong culture of security awareness through training and awareness campaigns and quarterly Phishing Simulations.
- Provide reporting on ISMS performance, risks, and assurance activities to senior stakeholders and auditors.
- Demonstrate a deep understanding of information security standards and management systems, particularly ISO/IEC 27001, and the ability to operationalise policies, manage risks, and ensure compliance within a complex enterprise setting.
- Perform risk assessments and tracking risk treatment plans.
- Prepare documentation and evidence for ISO 27001 audits.
- Demonstrate experience with data protection principles and delivering privacy impact assessments Process and Policy Level and design and implement security controls in line with policy requirements.
- Develop and maintain the ISMS manual and associated procedures.
- Align security strategies with business continuity and data protection programmes.
- Interpret IT governance and control frameworks such as: ITGC, NIST, COBIT, CSTAR, ITIL, and other standards to shape policy and monitor conformance.
- Analyse threat intelligence and risk trends to anticipate and prevent security breaches and advise on emerging technologies and their potential impact on security posture.
- Demonstrate and utilise foundational knowledge of project management frameworks such as: Lean Six Sigma, PRINCE2 and Cyber Essentials and Cyber Essentials Plus frameworks.
- Candidates will ideally have a proven background working in an EMEA wide organisation or larger enterprises with complex operations across an IT landscape / environment.
- You will ideally be educated to bachelor\βs degree (or equivalent) ideally in relevant field such as: Cyber Security, Information Technology, Computer Science or Information Systems
- Candidates will have ISO 27001 Lead Implementer or β ISO27001 Lead Auditor, with further qualifications across CISM, CISA, CRISC, CCAK, ISO 27701, Data Protection Practitioner, ISO 22301 Lead Implementer, ISO 27005 Risk Manager a distinct advantage.
- Ideally successful candidates will have exceptional interpersonal and communication skills are indispensable in this role. The Information Security Manager must interact with a wide spectrum of individuals, ranging from technical engineers and legal advisors to C-level executives and end-users.
- Preferably candidates will have the ability to tailor communication-presenting detailed technical risk in a non-technical, business-relevant format-is essential.
- Successful candidate will have assertiveness balanced with diplomacy, especially when challenging decisions, enforcing compliance, or navigating resistance to change.
- Trust-building is a critical success factor, as the Information Security Manager often has to advise, influence, and lead without formal authority.
- Conflict resolution, negotiation, and consensus-building are recurring themes in the role, as are empathy and cultural awareness-especially when operating across the diverse cultural landscape of Ricoh\βs European operations.
- Active listening, a collaborative mindset, and the ability to motivate others to engage with security initiatives underpin the role\βs success in promoting a security-first culture.
- Successful candidates must also demonstrate, ethical behaviour, confidentiality, integrity and take due professional care in all interactions relating to Auditing as per the principles of ISO 19011.
β’ A competitive salary package
β’ Industry leading benefits
Ricoh is an exceptional place to work. A place where there is strong emphasis on career development for the right individuals. This is a role where you can excel within a fast-paced environment and succeed within a thriving organisation.
This is an excellent opportunity to join a global company where you can truly capitalise and build on your own experience.
Ready to make that change? Apply now for a confidential conversation with our Recruitment Team.
At Ricoh, we embrace and respect the collective and unique talents, experience, and perspectives of all people. Together we inspire remarkable innovation. That\βs how we live the Ricoh Way.
Ricoh have removed the disclosure of convictions box from their application process (ban the box β http://www.bitc.org.uk/programmes/ban-box) offering equal opportunities to all.
For all roles, we will judge each individual on their skills and ability before taking into account their history. However some roles are subject to sensitive and restrictive information and, if successful, you may be required to undertake pre-employment vetting checks which include but are not limited to residency check, credit reference check, financial sanctions` check and a DBS Check. Further information on Employment Vetting can be accessed by contacting the Ricoh Recruitment Team.
#J-18808-Ljbffr
Information Security Officer employer: Ricoh
Contact Detail:
Ricoh Recruiting Team
StudySmarter Expert Advice π€«
We think this is how you could land Information Security Officer
β¨Tip Number 1
Network like a pro! Reach out to your connections in the industry, attend events, and join online forums. You never know who might have the inside scoop on job openings or can put in a good word for you.
β¨Tip Number 2
Prepare for interviews by researching the company and its culture. Understand their values and how they align with your own. This will help you tailor your responses and show that you're genuinely interested in being part of their team.
β¨Tip Number 3
Practice your interview skills with a friend or mentor. Get comfortable discussing your experience and how it relates to the role. The more you practice, the more confident you'll feel when it's time to shine!
β¨Tip Number 4
Don't forget to apply through our website! Itβs the best way to ensure your application gets noticed. Plus, we love seeing candidates who are proactive about their job search.
We think you need these skills to ace Information Security Officer
Some tips for your application π«‘
Tailor Your CV: Make sure your CV is tailored to the Information Security Officer role. Highlight your experience with ISO/IEC 27001 and any relevant certifications. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how you can contribute to our mission at Ricoh. Keep it engaging and relevant to the job description.
Showcase Your Soft Skills: Don't forget to highlight your interpersonal and communication skills. As an Information Security Officer, you'll need to interact with various teams, so let us know how you can build trust and foster collaboration!
Apply Through Our Website: We encourage you to apply directly through our website. Itβs the best way to ensure your application gets the attention it deserves. Plus, it makes the process smoother for both of us!
How to prepare for a job interview at Ricoh
β¨Know Your ISO Standards
Make sure you have a solid understanding of ISO/IEC 27001 and how it applies to the role. Be prepared to discuss how you've implemented or improved ISMS in previous positions, as this will show your practical experience and alignment with Ricoh's needs.
β¨Showcase Your Audit Experience
Since the role involves conducting internal audits, be ready to share specific examples of audits you've led or participated in. Highlight any challenges you faced and how you overcame them, as this demonstrates your problem-solving skills and attention to detail.
β¨Communicate Effectively
Ricoh values strong interpersonal skills, so practice explaining complex security concepts in simple terms. Think about how you can tailor your communication style to different audiences, from technical teams to C-level executives, to show that you can bridge the gap between tech and business.
β¨Demonstrate a Security-First Mindset
Prepare to discuss how you've promoted a culture of security awareness in past roles. Share any initiatives you've led, such as training sessions or awareness campaigns, to illustrate your proactive approach to information security and your ability to motivate others.