At a Glance
- Tasks: Lead IT security initiatives and enhance our security posture across various domains.
- Company: Join Unity Advisory, a forward-thinking firm embracing AI-driven solutions.
- Benefits: Flexible hybrid work, collaborative culture, and career growth opportunities.
- Why this job: Make a real impact in cybersecurity while working with cutting-edge technologies.
- Qualifications: Strong knowledge of security frameworks and excellent communication skills required.
- Other info: Inclusive recruitment process ensuring equal opportunities for all candidates.
The predicted salary is between 48000 - 72000 £ per year.
Unity Advisory is a challenger advisory firm built for the AI-enabled world, operating a lean, conflict-free, and client-centric model that embeds AI across all workstreams. Our culture is highly collaborative and flat-structured, pursuing the best outcomes for our clients.
The Security Lead (Fixed Term Contractor) will play a pivotal role in strengthening Unity Advisory’s security posture by working across technical, governance, and operational domains. Acting as the primary liaison between Unity Advisory and its Managed SOC provider, this role will lead the implementation of Cyber Essentials certification and alignment with ISO 27001 standards. The contractor will establish, operationalise, and embed sustainable security practices while building organisational readiness for formal audit and certification. They will also lead on operational Information Security practices including identity management and vulnerability management.
This is both a strategic and hands-on role that requires the ability to bridge governance, technology, and stakeholder engagement, ensuring Unity Advisory’s security maturity evolves in line with regulatory and business objectives.
What You’ll Do- Security Governance & Alignment
- Lead the development and rollout of a security governance framework aligned with ISO 27001 controls and Cyber Essentials requirements.
- Conduct gap analyses and implement corrective action plans to achieve compliance milestones.
- Draft and maintain security policies, standards, and procedures.
- Liaison with SOC and Incident Management
- Act as the central point of contact with the Managed Security Operations Centre (SOC), ensuring effective triage, response, and reporting of security incidents.
- Oversee configuration and optimisation of SIEM/SOAR tools to ensure actionable alerting.
- Run periodic tabletop exercises and incident simulations to validate response capability.
- Ensure Vulnerability Management activities are carried out, in conjunction with the wider team and managed services function.
- Cyber Essentials Implementation
- Coordinate the technical and procedural controls required to meet Cyber Essentials Plus certification.
- Liaise with external assessors, IT operations, and third-party providers to ensure readiness for audit.
- ISO 27001 Readiness & ISMS Development
- Build an Information Security Management System (ISMS) tailored to Unity Advisory’s business model.
- Map existing processes and documentation to ISO 27001 Annex A controls.
- Prepare the organisation for internal and external audits, including documentation, risk treatment plans, and asset registers.
- Risk & Compliance Management
- Conduct and maintain an enterprise-wide information security risk register.
- Support Data Protection Impact Assessments (DPIAs) and privacy alignment activities in collaboration with the CPO.
- Support contractual security clauses and third-party vendor due diligence.
- Awareness & Training
- Deliver a targeted security awareness programme, including phishing simulations, staff training, and policy communications.
- Foster a culture of shared security responsibility across departments.
- Strong knowledge of information security frameworks including ISO 27001, Cyber Essentials, NIST CSF, and CIS Controls.
- Experience liaising with SOCs, managing SIEM/SOAR tools, and handling incident response workflows.
- Proven experience leading security maturity assessments and implementing ISO 27001-aligned controls.
- Understanding of risk-based security management, policy design, and compliance reporting.
- Excellent communication and stakeholder management skills—able to engage both technical and non-technical audiences.
- Experience in cloud and SaaS security, ideally within Microsoft 365 and Azure environments.
- Familiarity with third-party risk management and contract security provisions.
- Desirable: experience with ISO 42001 (AI Management) or emerging AI governance frameworks.
- Security certifications preferred (e.g., CISSP, CISM, ISO 27001 Lead Implementer, CompTIA Security+).
We offer a truly hybrid and flexible working environment and the opportunity to be at the forefront of AI-driven advisory services. You’ll be part of a highly collaborative, flat-structured culture, empowered to contribute to the way we scale our business and support our clients.
At Unity Advisory, we are committed to providing an inclusive and accessible recruitment process. In line with the Equality Act 2010, we will accommodate any suitable candidate requiring assistance to attend or conduct an interview. If you need any adjustments or support, please let us know when either scheduling your interview or in your application cover letter.
IT Security Lead - 6 month contract employer: Unity Advisory
Contact Detail:
Unity Advisory Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land IT Security Lead - 6 month contract
✨Tip Number 1
Network like a pro! Reach out to your connections in the industry, attend relevant events, and engage with professionals on platforms like LinkedIn. You never know who might have the inside scoop on job openings or can refer you directly.
✨Tip Number 2
Prepare for interviews by researching the company and its culture. Understand their values and how they align with your skills, especially in areas like security governance and compliance. This will help you tailor your responses and show you're a perfect fit.
✨Tip Number 3
Practice your pitch! Be ready to explain your experience with ISO 27001 and Cyber Essentials in a way that highlights your strategic and hands-on approach. Confidence is key, so rehearse until it feels natural.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining Unity Advisory and contributing to our mission.
We think you need these skills to ace IT Security Lead - 6 month contract
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the IT Security Lead role. Highlight your experience with ISO 27001 and Cyber Essentials, as well as any relevant security certifications. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how you can contribute to our team. Be sure to mention your experience with SOCs and incident response, as these are key for us.
Showcase Your Communication Skills: Since this role involves liaising with various stakeholders, it's important to demonstrate your communication skills. In your application, give examples of how you've effectively engaged both technical and non-technical audiences in the past.
Apply Through Our Website: We encourage you to apply directly through our website. This helps us keep track of applications and ensures you get the best chance to showcase your talents. Plus, it’s super easy to do!
How to prepare for a job interview at Unity Advisory
✨Know Your Frameworks
Make sure you brush up on your knowledge of ISO 27001 and Cyber Essentials. Be ready to discuss how you've implemented these frameworks in past roles, as this will show your understanding of the requirements and your ability to lead compliance efforts.
✨Showcase Your Communication Skills
Since this role involves liaising with various stakeholders, practice articulating complex security concepts in simple terms. Prepare examples of how you've successfully communicated with both technical and non-technical audiences in previous positions.
✨Prepare for Scenario Questions
Expect questions that assess your problem-solving skills in real-world scenarios. Think about past incidents you've managed or vulnerabilities you've addressed, and be ready to explain your thought process and the outcomes.
✨Demonstrate Your Leadership Style
As a Security Lead, you'll need to inspire and guide your team. Be prepared to discuss your leadership approach, how you foster collaboration, and any training programmes you've implemented to enhance security awareness within an organisation.