At a Glance
- Tasks: Lead security governance and risk management to protect groundbreaking scientific technology.
- Company: Join a pioneering organisation at the forefront of Big Science and information security.
- Benefits: Enjoy a competitive salary, generous leave, and flexible working options.
- Other info: Dynamic hybrid working environment with excellent career growth opportunities.
- Why this job: Make a real impact in safeguarding the future of research and innovation.
- Qualifications: Degree in a related field and relevant professional qualifications required.
The predicted salary is between 58589 - 58589 £ per year.
Corporate Hub
Salary: £58,589
Band: UKRI Band F
Contract Type: Open Ended‑Permanent (Compressed hours & flexible working patterns available)
Hours: Full‑time (flexible working available)
Location: Keyworth, Nottingham or Polaris House, Swindon – Hybrid working available.
Closing Date: Sunday 14th June 2026.
Step into the world where cutting‑edge science meets robust information security. Protect the technology that powers groundbreaking discoveries and be part of the team that safeguards the future of Big Science. Collaborate with leading engineers, researchers, and technologists to tackle the most pressing security challenges in a fast‑paced, innovative environment.
Role Summary
The UKRI CIO Group manages and optimises the organisation’s critical enterprise technical services. Within the group, a team of Information Security Professionals support the delivery of modern, secure, resilient and scalable services across a federated team of Digital, Data and Technology professionals to deliver impact across the organisation and the wider UK research and innovation system.
Key Responsibilities
- Own and lead UKRI’s Information Security Governance, Risk and Assurance framework.
- Operate and continuously improve the Information Security Management System (ISMS).
- Provide end‑to‑end security assurance for cloud and enterprise services (AWS and Azure).
- Define and maintain UKRI’s security policy and control framework.
- Enable and support risk ownership across UKRI’s federated technology and business teams.
- Develop and maintain meaningful security metrics, dashboards and management information.
- Define, deliver and track a multi‑year security governance, risk and assurance roadmap.
- Lead security assessment, testing and remediation activity.
- Provide ongoing oversight of supplier and third‑party security risk.
- Establish and maintain enterprise visibility of assets, services and data risk context.
- Provide governance leadership across incident management, people, suppliers and assurance partnerships.
- Ensure governance‑level oversight of significant security incidents.
Security Clearance
Applicants must be eligible for clearance in line with UK National vetting guidelines and willing to undertake the process. Candidates not meeting this level of clearance will not be considered.
Personal Specification (Essential)
- Degree in a related subject or relevant comparable education.
- Professional qualification (e.g., CISM, CISSP, CCSP, ISO 27001 Lead Implementer/Lead Auditor).
- Effective decision‑making, communication and interpersonal skills, with the ability to adapt communication style and approach to different environments and audiences.
- Self‑motivated, shows initiative and works with minimal direction, demonstrating strong customer focus.
- Changing and improving processes, systems, and people to achieve positive outcomes.
- Strong knowledge of information security governance, risk management and compliance, including operating within an ISO/IEC 27001 management system.
- In‑depth understanding of cloud security principles and practices for AWS and Azure, including secure configuration, identity, logging, network controls and data protection.
- Ability to coordinate and communicate security risk issues at a senior level and propose solutions that are appropriate, proportionate and effective.
- Strong problem‑solving and analytical skills, including interpreting technical evidence and translating it into business risk.
Benefits
- An outstanding defined benefit pension scheme.
- 30 days annual leave in addition to 10.5 public and privilege days (full‑time equivalent).
- Employee discounts and offers on retail and leisure activities.
- Employee assistance programme, providing confidential help and advice.
- Flexible working options.
- Many more benefits and wellbeing initiatives that enable our employees to have a great work‑life balance.
Offensive Security and Threat Intelligence Specialist employer: UK Research and Innovation
Join a forward-thinking organisation where your expertise in offensive security and threat intelligence will play a crucial role in safeguarding groundbreaking scientific advancements. With a strong commitment to employee wellbeing, we offer flexible working patterns, an outstanding pension scheme, and ample annual leave, all within a collaborative environment that fosters professional growth and innovation. Located in Keyworth or Swindon, you will be part of a dynamic team dedicated to tackling the most pressing security challenges in a hybrid working model.
Contact Details:
UK Research and Innovation Recruitment Team
StudySmarter Expert Advice🤫
We think this is how you could land Offensive Security and Threat Intelligence Specialist
✨Tip Number 1
Network like a pro! Reach out to professionals in the field of information security and threat intelligence. Attend industry events, webinars, or even local meetups to connect with potential employers and learn about job openings that might not be advertised.
✨Tip Number 2
Show off your skills! Create a portfolio or a personal website showcasing your projects, certifications, and any relevant experience. This is a great way to demonstrate your expertise in cloud security and risk management to potential employers.
✨Tip Number 3
Prepare for interviews by brushing up on common security scenarios and challenges. Be ready to discuss how you would handle specific situations related to information security governance and risk management. Practice makes perfect!
✨Tip Number 4
Don’t forget to apply through our website! We’ve got loads of opportunities waiting for you, and applying directly can sometimes give you an edge. Plus, it’s super easy to keep track of your applications this way.
We think you need these skills to ace Offensive Security and Threat Intelligence Specialist
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Offensive Security and Threat Intelligence Specialist role. Highlight your relevant experience, especially in information security governance and risk management. We want to see how your skills align with our needs!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how you can contribute to our mission at UKRI. Keep it engaging and personal – we love to see your personality come through!
Showcase Your Qualifications:Don’t forget to mention your professional qualifications like CISM or CISSP. These are key for us! Make sure they stand out in your application so we can see you’re the right fit for the technical challenges we face.
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you don’t miss any important updates. Plus, it shows you’re keen on joining our team!
How to prepare for a job interview at UK Research and Innovation
✨Know Your Stuff
Make sure you brush up on your knowledge of information security governance, risk management, and compliance. Familiarise yourself with ISO/IEC 27001 and be ready to discuss how you've applied these principles in past roles.
✨Showcase Your Cloud Security Skills
Since the role involves cloud services like AWS and Azure, be prepared to talk about your experience with secure configurations, identity management, and data protection. Have specific examples ready that demonstrate your expertise in these areas.
✨Communicate Effectively
This position requires strong communication skills, so practice articulating complex security concepts in a way that's easy to understand. Think about how you can adapt your communication style to different audiences, especially when discussing risk issues.
✨Demonstrate Problem-Solving Abilities
Be ready to tackle hypothetical scenarios or case studies during the interview. Show how you approach problem-solving by breaking down technical evidence and translating it into business risks, along with proposing effective solutions.