Information Security Officer

Information Security Officer

Full-Time 50000 - 60000 € / year (est.) Home office (partial)
Royal BAM Group

At a Glance

  • Tasks: Identify and manage information security risks while collaborating with key stakeholders.
  • Company: Join BAM, a leading construction company focused on building a sustainable future.
  • Benefits: Enjoy a competitive salary, company car, pension, health benefits, and generous holiday allowance.
  • Other info: Inclusive culture with opportunities for personal growth and development.
  • Why this job: Make a real impact in information security and help shape a safer digital environment.
  • Qualifications: Degree or equivalent certifications in information security; strong knowledge of security frameworks required.

The predicted salary is between 50000 - 60000 € per year.

BAM UK & Ireland is recruiting an Information Security Officer to join our Team. This role can be based out of any of our UK office locations. Working 37.5 hours per week Monday - Friday. This position requires some international travel within Europe, and the successful applicant will be required to undergo security clearance.

Making Possible

  • Work with key stakeholders in the business, IT team and externally where required.
  • Identifying and registering new and emerging risks and trends in the field of information security and developing appropriate measures.
  • Develop and maintain security risk frameworks, policies, and standards, aligned with regulatory and industry best practices (e.g., ISO 27001, NIST CSF).
  • Taking care of management and documentation of Information Security Management System.
  • Managing external audits like CE+, ISO27001 as per the Group requirements of maintaining security certifications.
  • Partner with internal audit, compliance, and enterprise risk functions to ensure a coordinated approach to risk management.
  • Support in answering appropriate information issues in tenders and various other government projects.
  • Performing third party risk assessments of external suppliers to make sure they are compliant.
  • Managing and promoting security awareness programme Group Wide.
  • Executing phishing campaigns, communications and remedial actions.
  • Drawing up reports and dashboards on the basis of approved KPIs and KRIs.

What’s in it for you?

  • Company Car or Car Allowance.
  • Contributory Pension.
  • BUPA.
  • Life Assurance.
  • 26 days holiday (increases with length of service) plus 2 Wellbeing days and 1 Volunteering day.
  • Gym subsidy and BAM social club membership.
  • Health and Well Being Programme.
  • Learning and Development Opportunities.

What do you bring to the role?

  • Bachelor’s degree or equivalent combination of education and industry standard certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Auditor/Implementer, or equivalent ISO27001 implementor.
  • Strong knowledge of information security frameworks and standards (ISO 27001, NIST, COBIT, CIS Controls).
  • Proven experience in second line of defence, risk management, assurance, or audit functions.
  • A professional and mature attitude to deal with a range of internal and external stakeholders.
  • Ability to work independently, manage competing priorities, and deliver high-quality assurance outputs.
  • Team-oriented and able to collaborate with different departments.
  • Excellent organisational and communication skills.

About BAM

Building a sustainable tomorrow. That’s our mission and our promise at BAM. It’s how we engineer vital infrastructure and construct high-quality buildings as one of the largest construction companies in Europe. We strive to create an environment where everybody feels welcome and valued. We’re on an exciting journey to employ the best talent to join us regardless of social background, race, colour, religion, national or ethnic origin, sexual orientation, gender identity or expression, age, disability or other characteristics.

The application process

BAM is committed to ensuring a fully inclusive recruitment and onboarding process, so if at any time you feel you may need any reasonable adjustments, do not hesitate to speak with one of our team, and we will do our best to support you.

Information Security Officer employer: Royal BAM Group

BAM UK & Ireland is an exceptional employer that prioritises employee well-being and professional growth, offering a comprehensive benefits package including a company car or allowance, contributory pension, and extensive health programmes. With a strong commitment to inclusivity and a collaborative work culture, employees are encouraged to develop their skills through learning opportunities while contributing to meaningful projects that shape sustainable infrastructure across the UK and Europe.

Royal BAM Group

Contact Detail:

Royal BAM Group Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Security Officer

Tip Number 1

Network like a pro! Reach out to folks in the industry, attend events, and connect with BAM employees on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Prepare for interviews by researching BAM's values and recent projects. Show us that you’re not just another candidate but someone who genuinely cares about building a sustainable tomorrow with us.

Tip Number 3

Practice your pitch! Be ready to explain how your skills in information security align with our mission. Highlight your experience with frameworks like ISO 27001 and how you can contribute to our risk management efforts.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows us you’re serious about joining our team.

We think you need these skills to ace Information Security Officer

Information Security Management
Risk Management
ISO 27001
NIST CSF
CISSP
CISM
CRISC

Some tips for your application 🫡

Tailor Your CV:Make sure your CV reflects the skills and experiences that align with the Information Security Officer role. Highlight your knowledge of frameworks like ISO 27001 and any relevant certifications you hold. We want to see how you can contribute to our mission!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how your background makes you a great fit for BAM. Don’t forget to mention your ability to work with stakeholders and manage risks effectively.

Showcase Your Experience:When detailing your experience, focus on specific examples where you've successfully managed security risks or led audits. We love seeing real-world applications of your skills, so don’t hold back on the details!

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, you’ll find all the info you need about the role and our company culture there!

How to prepare for a job interview at Royal BAM Group

Know Your Frameworks

Make sure you brush up on key information security frameworks like ISO 27001 and NIST. Be ready to discuss how you've applied these in your previous roles, as this will show your understanding of industry standards and your ability to implement them effectively.

Showcase Your Risk Management Skills

Prepare examples of how you've identified and managed risks in past positions. Think about specific incidents where you developed measures to mitigate risks, as this will demonstrate your proactive approach and problem-solving skills.

Communicate Clearly

Since you'll be working with various stakeholders, practice explaining complex security concepts in simple terms. This will help you convey your ideas effectively during the interview and show that you can bridge the gap between technical and non-technical teams.

Be Ready for Scenario Questions

Expect scenario-based questions that assess your decision-making in real-world situations. Prepare by thinking through potential challenges you might face in the role and how you would address them, especially regarding third-party risk assessments and compliance.