Information Security Officer

Information Security Officer

Full-Time 50000 - 65000 £ / year (est.) No working from home possible
Toyota (GB) plc

At a Glance

  • Tasks: Lead and manage Information Security for Toyota Financial Services UK, ensuring compliance and promoting security culture.
  • Company: Join Toyota Financial Services, a leader in automotive finance with a commitment to innovation.
  • Benefits: Enjoy competitive salary, hybrid working, generous leave, and extensive health benefits.
  • Other info: Embrace a vibrant workplace culture with opportunities for personal development and fun events.
  • Why this job: Make a real impact on information security while working with cutting-edge technology and a dynamic team.
  • Qualifications: Experience in ISMS, strong analytical skills, and stakeholder management abilities required.

The predicted salary is between 50000 - 65000 £ per year.

Responsible for all aspects of Information Security within Toyota Financial Services UK, including compliance with Corporate Policies, the ongoing promotion of Information Security across the organisation and to operate an effective Information Security Management System (ISMS).

About the ‘Department’: The Business Technology Solutions (BTS) department are responsible for delivering end-to-end business technology and change through their four key functions of Governance, Projects & Change, Delivery and Technical Operations. They look after both TFSUK and KINTO UK. The mission of BTS is to Give (the Business the technology, applications and services it needs), to Guide (the Business through Change using their expertise and experience) and to Guard (always protect the Business, its Customers & its Data).

What you’ll be doing:

  • Maintain, mature and align the BTS’ ISMS with ISO27001:2022 through management and evolution of the company’s Information Security policies, maintaining best practice and alignment with Corporate and Regulatory requirements, including the Global Information Security Group framework (GISG), General Data Protection Regulation (GDPR), Sarbanes-Oxley (SOX) PCI-DSS & Cyber Essentials Plus.
  • Manage Information Security aspects of the third-party due diligence process, including subject matter expertise to support onboarding of new suppliers, ongoing assessment of existing suppliers, contract reviews.
  • Manage/Co-ordinate or provide reporting material for regular information security meetings including supplier security reviews, risk register reviews, metrics.
  • Provide clear and actionable information security reporting to senior leadership.
  • Manage/operate Information Security related tools such as GRC tool and Supplier assessment tool.
  • Own and maintain the BTS Risk register, ensuring risks are identified, assessed and documented in accordance with internal risk methodology, including exception handling.
  • Working in partnership with the Data Protection Officer (DPO) & Legal & Compliance to protect the organisation’s information.
  • Overseeing Audit Findings and any associated remediation across BTS including gathering, management and submission of control evidence to support assurance activities, internal compliance reviews (GISG) and any regulatory requirements.
  • Manage the Information Security Awareness programme, including maintenance of the training schedule, annual employee training, creation of materials and assist with co-ordination of monthly phishing campaigns.
  • Proactively raising the profile of Information Security across the organisation, its stakeholders, vendors and customers.
  • Working in partnership with the Business & BTS teams to ensure all Projects, Changes, policies and procedures are compliant with corporate information security policies.
  • Management of the annual Security Incident Response Test (SIRT), as well as ensuring the remediation of any findings.
  • Undertake Security related Testing, including Phishing, Security Incident Response Tests.
  • Co-ordinate response to security incidents and breaches to ensure any impact is contained and relevant information obtained to facilitate analysis and improvement plans.
  • Maturing the Information Security mindset across TFS UK.

What you’ll get to own:

  • Management of TFSUK’s ISO27001 certification, ensuring the ongoing certification is retained.
  • Management of TFSUK’s GISG posture, ensuring compliance against the extensive control set.
  • Management of the GISG Vendor Assessment process for Information Security assurance of all TFSUK vendors.
  • Development & Management of the Information Security Strategy and subsequent annual reviews.
  • Oversight of remediation work for all open IT audit findings.
  • Management of IT Risk Register and ongoing monthly reviews.
  • Information Security Reporting & Performance KPIs.

Key Experience & Skills:

  • Proven experience in developing, implementing, maintaining and leading an effective ISMS and information security control assurance programme.
  • Strong stakeholder management skills, including technical members of staff and senior executives, stakeholder negotiation and influencing.
  • Good analytical skills.
  • Strong understanding of ISO27001, GDPR, SOX & Information Security Risk Management.
  • Understanding of information security tools.
  • Experience with business continuity, third party risk management and incident management.

Attributes & Behaviours:

  • Strong written and verbal communication skills.
  • Ability to interact professionally with a broad range of technical and non-technical stakeholders across the business.
  • Keen problem solver and critical thinker.
  • Strong multi-tasker, able to work effectively on several projects at one time in a busy and time-driven work environment.
  • Proactive, determined and self-motivated.

At Toyota Financial Services (TFS) it is more than just an externally bench-marked salary and bonus, we also offer:

  • Hybrid working pattern is 2 days in the office and 3 days from a location of your choice.
  • Access to attractive car schemes for you (& your family) for Toyota & Lexus cars.
  • Excellent pension scheme (up to 6% employee contribution and 15% employer contribution).
  • Generous annual leave of 25 days which increases with service and holiday purchase option.
  • Private Medical Healthcare (single, partner/spouse and dependent children) with Digital GP Service.
  • Group Income Protection cover with Aviva including physical, mental, and financial wellbeing services.
  • Employee Assistance Program.
  • Eye tests.
  • Onsite gym, Sports and Social Club, & flu jabs to keep you healthy.
  • Wellbeing hour each month and many more initiatives throughout the year to encourage a healthy mind and body, and to raise awareness and celebrate diversity, equity and inclusion.
  • Dress for your day policy to make you feel comfortable at work.
  • Eco HQ, free parking & restaurant.
  • Two volunteering days per year.
  • Reward gateway voucher discounts.
  • Flexible working scheme and we welcome flexible working conversations at interview.
  • Regular 121s with your manager, a personal development review (PReview) each quarter.
  • A wide range of learning & development opportunities including Linked In Learning courses.
  • £250 contribution towards you learning something new outside of work.
  • Annual events (e.g., summer party, BBQ & Xmas party) including Countdown to Christmas events every December - it is so much fun!

At Toyota Financial Services (TFS) we value everyone and are pleased to be recognised as a Disability Confident Employer.

Information Security Officer employer: Toyota (GB) plc

At Toyota Financial Services UK, we pride ourselves on being an exceptional employer, offering a competitive salary, annual bonus, and extensive benefits package that includes hybrid working options and generous leave. Our vibrant work culture fosters employee growth through regular development reviews, learning opportunities, and a commitment to diversity and inclusion, all while ensuring a supportive environment where your contributions to Information Security are valued and impactful.

Toyota (GB) plc

Contact Details:

Toyota (GB) plc Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Security Officer

Tip Number 1

Network like a pro! Reach out to people in the industry, attend events, and connect on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Prepare for interviews by researching the company and its culture. Understand their values and how they align with your skills, especially in Information Security. This will help you stand out as a candidate who truly gets what they're about.

Tip Number 3

Practice your responses to common interview questions, but keep it natural. Use the STAR method (Situation, Task, Action, Result) to structure your answers, especially when discussing your experience with ISMS and compliance.

Tip Number 4

Don’t forget to follow up after your interview! A quick thank-you email can leave a lasting impression and show your enthusiasm for the role. Plus, it keeps you on their radar as they make their decision.

We think you need these skills to ace Information Security Officer

Information Security Management System (ISMS)
ISO27001:2022
General Data Protection Regulation (GDPR)
Sarbanes-Oxley (SOX)
PCI-DSS
Cyber Essentials Plus
Third-party Risk Management

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Information Security Officer role. Highlight your experience with ISMS, compliance, and any relevant certifications like ISO27001. We want to see how your skills align with what we’re looking for!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you’re passionate about information security and how your background makes you a perfect fit for our team. Don’t forget to mention your understanding of GDPR and risk management!

Showcase Your Communication Skills:Since this role involves interacting with various stakeholders, make sure to demonstrate your strong written communication skills in your application. We love seeing clear and concise language that reflects your ability to convey complex information simply.

Apply Through Our Website:We encourage you to apply through our website for the best chance of getting noticed. It’s super easy, and you’ll be able to keep track of your application status. Plus, we love seeing candidates who take the initiative!

How to prepare for a job interview at Toyota (GB) plc

Know Your ISO27001 Inside Out

Make sure you’re well-versed in ISO27001:2022 standards. Brush up on how they apply to the role and be ready to discuss your experience with implementing and maintaining an ISMS. This will show that you understand the core of what Toyota Financial Services is looking for.

Showcase Your Stakeholder Management Skills

Prepare examples of how you've successfully managed relationships with both technical and non-technical stakeholders. Highlight any negotiation or influencing tactics you've used, as this is crucial for the role. Being able to communicate effectively across different levels will set you apart.

Demonstrate Your Analytical Prowess

Be ready to discuss specific instances where your analytical skills have helped identify risks or improve security measures. Use real-life examples to illustrate your problem-solving abilities, especially in relation to information security tools and risk management.

Prepare for Scenario-Based Questions

Expect questions that put you in hypothetical situations related to security incidents or compliance challenges. Think through your responses ahead of time, focusing on your critical thinking and multi-tasking abilities. This will help you convey your proactive approach to managing information security.