Information Security Governance Risk and Compliance
7 months ago
**Information Security Governance Risk and Compliance Officer **(£35,000pa)
**Commercial Services Group** (Hybrid/Kings Hill, Kent)
**About Commercial Services Group**
Commercial Services Group (CSG) is one of the largest providers of public sector and education procurement services globally, with revenues of c£500M, 1800 staff and six trading divisions: Global Education Supplies, Procurement, Energy & Carbon, Community Services, Professional Services and People Services.
Wholly owned by Kent County Council, CSG supports over 15,000 customers in 86 countries and collaborates with a supply chain of c1,000 suppliers.
**The Role**
We are a highly recognised public sector focused business whose mission is to always deliver a quality and seamless customer service, and protecting our information, users and client data is critical to our success.
The Information Security GRC Officer is responsible for supporting our Group CISO in establishing and maintaining a Group-wide information risk management program to ensure that information assets are adequately protected. This individual will be responsible for identifying, evaluating, and reporting on information security risks in a manner that meets compliance and regulatory requirements, and aligns with and supports the risk posture of CSG Group.
As part of our team, you will be responsible for supporting our Group CISO in identifying Information Security Risks and ensuring appropriate governance structures are in place to manage these risks. Your role will involve ensuring compliance with legislation, regulation, and security certifications (e.g., ISO27001 and Cyber Essentials+)
**Key Duties**
- Developing and driving a comprehensive risk management program that includes ongoing information system risk assessments for both existing and newly integrated systems
- Working with the Group CISO to develop and coordinate Group-wide information security risk assessments, controls, policies, standards, processes, and guidelines.
- Ensuring consistent compliance with legislation, regulations, and certification requirements
- Regularly conducting audits to maintain and enhance security practices to ensure they are compliant and meet the high standards of our organisation
- Reporting risk management issues and internal control deficiencies identified directly to governance groups and supporting the Group CISO in providing recommendations for enhancing our information security and risk management strategies
**What we need from you**
- A genuine passion for Information and Cyber Security, with a keen eye for detail
- A mindset that is strongly orientated towards security risk management and compliance
- Security Certifications (ISO27001, CISM etc.) are desirable but no essential
- Knowledge of Information Security Principles, Standards and Frameworks
- Knowledge of legislative and regulatory requirements pertaining to Information Security and Data Protection
- Experience of ISO27001 is desirable, but not essential
- Proven experience of Information Security Risk Management
- Proven experience of security policy development and process management
- Experience of communicating with senior stakeholders
- Experience of engaging with technical teams
- Excellent IT skills, particularly Microsoft Excel, PowerPoint and other Office packages
- Excellent telephone manner and strong communication skills both oral and written
- Able to build rapport quickly within teams, with peers and stakeholders
- Resilient nature - able to overcome obstacles and barriers and to maintain pace and momentum
- Ability to multitask, prioritise and manage time effectively
- Display integrity - is sincere in own behaviour and in dealings with others - role models values and behaviours and questions the actions of others
- Self-motivated and self-aware - recognises own strengths and weaknesses, is committed to personal development
- Creativity and innovation
- Adaptable work style with the ability to operate with tact and sensitivity where required
- Team player who exhibits, and instils in others, a ‘whatever it takes’ attitude to exceed targets
**In return, CSG will offer you**:
- 25 days holiday, plus bank holidays
- Birthday off work
- Life assurance cover
- Company pension
- Flexible first, hybrid working
- A culture of progression & development
- Shopping discounts & retailer offers
- Team & company events
- eLearning portal
- EAP programme
- Referral scheme
- Health & Wellbeing platform
- Health Cash Plan initiative
- Discounted gym membership
-
Information Security Risk Officer
5 days ago
West Midlands, United Kingdom SEVERN TRENT Full time**LET’S CUT STRAIGHT TO IT** **Want to do the best work of your life? Playing your part in making a big difference to the environment and communities we serve. Our people make Severn Trent a truly exciting and inclusive place to work - a place where you can be yourself and let your skills shine.** Our purpose is taking care of one of life’s essentials,...
-
Head of Compliance and Risk
1 month ago
West Malling, Kent, United Kingdom Charities Aid Foundation Full time£110k salary">The UK's economy is vulnerable to various types of financial crime. These crimes pose a threat to national security, fuel organised crime, and cause significant harm to individuals and businesses.">We're looking for an exceptional candidate to lead our economic crime prevention efforts. This individual will be responsible for developing and...
-
Information Security Officer
3 days ago
West Yorkshire, United Kingdom Erin Associates Full time**Information Security Officer - Hybrid / Yorkshire or Midlands** **Circa £40,000 + Benefits such as 35-hour work week, flexible hours, 25 days Holidays + Bank holidays, Life assurance and more** Some of the responsibilities of the Information Security Officer will include but not be limited to: - Developing the company’s Information Security Consultancy...
-
Information Compliance Officer
3 days ago
West Midlands Combined Authority, United Kingdom Dougie Mac Full timeJob SummaryWe are seeking an experienced Information Governance Administrator to join our team at Dougie Mac. As a key member of our IG framework, you will be responsible for supporting the delivery of our IG action plan and ensuring compliance with data management standards.Key ResponsibilitiesSupporting the IG Framework: Assist in delivering the IG action...
-
Information Security Analyst
1 week ago
West Devon, United Kingdom Cinque Ports Vets Full timeCinque Ports VetsEstimated salary: £60,000 - £80,000 per annum.About the Role:We are seeking an experienced Information Security Analyst to join our team in certain locations within the UK. As a key member of our Information Security Team, you will be responsible for identifying and mitigating security threats to ensure the confidentiality, integrity, and...
-
IT Security Governance Specialist
3 weeks ago
West Bromwich, Sandwell, United Kingdom concept resourcing Full timeJob Summary">">We are seeking a highly accomplished IT Security Assurance/Governance Lead to assist our client in the Midlands with their Datacentre Exit programme.">">About You">">You will be a UK-based technical SME with experience in IT security assurance and governance, possessing excellent knowledge of datacentre operations.">">The Role">">This 6-month...
-
Risk and Compliance Coordinator
2 weeks ago
West Malling, Kent, United Kingdom Envar Full time £35,000 - £40,000Job Summary: Risk and Compliance CoordinatorWe are seeking a highly organized and detail-oriented Risk and Compliance Coordinator to join our team at Envar. As a key member of our operations team, you will be responsible for identifying and mitigating risks across our operations, ensuring compliance with regulatory requirements, and developing and...
-
Risk and Governance Specialist
2 weeks ago
West Midlands Combined Authority, United Kingdom ACS Staffing Solutions Full timeAbout the Opportunity:We are delighted to offer an exciting opportunity for a Risk and Governance Specialist to join our team at ACS Staffing Solutions. This is a chance to take on a key role in ensuring our company's risk management and governance practices are world-class.Key Responsibilities:Develop and implement risk management strategies to minimize...
-
Information Security Manager
5 days ago
West Midlands (Region), United Kingdom Hays Specialist Recruitment Limited Full timeBirmingham - Up to £65k + Bonus - Hybrid Hays Technology are partnering with a global environmental services organisation based on the outskirts of Birmingham recruiting for an Information Security Manager to lead a team of SME's within the Security Department. **What you'll be doing: - The role's technical focus is matched by its appreciation of business...
-
Operational Risk/ Governance Manager
2 weeks ago
West Sussex, United Kingdom InterQuest Group Full timeAre you ready to take on a pivotal role within one of the UK’s leading financial networks? As the Enterprise Risk & Governance Manager , you’ll play a critical role in strengthening our second line of defence, driving risk maturity, and ensuring we maintain a robust risk management culture. Own and enhance the Group Risk Management Framework (RMF),...
-
Information Security Lead Work From Home
7 days ago
West Midlands (Region), United Kingdom Experis LTD Full time**I nformationSecurityLead (work from home)** I am seeking **an InfoSec**Lead** to join their expanding **security** consultancy. You will work closely with Business Leadership and IT to facilitate regulatory and contractual compliance, **riskaudits**, assuring the **level of control effectiveness** as well as ensuring continuous improvement of standards....
-
Information Security Officer
1 week ago
North West, United Kingdom Millbank Group Full timeOur Client is a leading engineering and maintenance provider, supporting customers across the chemical & petrochemical, nuclear, oil & gas, pharmaceuticals & biopharma, power & energy, utilities, renewables and food & beverage markets. We enhance the efficiency of assets, ensuring a high level of availability and reducing maintenance costs. We have...
-
Regional Information Security and Assurance Lead
7 months ago
West Midlands, United Kingdom HM Prison & Probation Service Full time**Details**: **Reference number**: - 303976**Salary**: - £30,812 - £38,289- pro-rata- A Civil Service Pension with an average employer contribution of 27%**Job grade**: - Other- NPS Pay Band 4 National**Contract type**: - Fixed Term - Secondment**Length of employment**: - For a period of up to 10 months (possible extension)**Type of role**: -...
-
Information Security Analyst Contract
2 weeks ago
Solihull, West Midlands, United Kingdom Spinks Full time €35,000 - €45,000Job Title: Information Security Analyst I'm working with a large, well-known business to find a Security Analyst for their growing technology team. In this role, you'll be assisting the Head of Information Security. Experience in an Information Security Team. Maintaining security policies and conducting risk assessments. Managing security logs in...
-
Information Asset Lead
6 days ago
West Midlands, United Kingdom Eden Brown Synergy Full time**Information Asset Lead** Eden Brown Synergy is currently working in partnership with an NHS Organisation based in the West Midlands area which is seeking to an Information Asset Lead to join their Information Governance Department. The post holder will ensure the organisation holds reliable and up-to-date data covering all information assets held by the...
-
Risk Governance Specialist
4 days ago
West Blatchington, Brighton and Hove, United Kingdom Sanderson Recruitment Full timeRisk Governance Specialist Job SummaryWe are seeking a seasoned Risk Governance Specialist to join our client's risk management team. This role involves developing and implementing risk management policies and procedures that ensure compliance with regulatory requirements.The successful candidate will have a strong background in risk management, including...
-
Risk & Compliance
1 month ago
West Bromwich, United Kingdom Robert Half Full timeRisk & Compliance Officer Robert Half are partnering with a leading organisation to find a talented Risk & Compliance Officer. This role offers the chance to shape risk management and compliance processes, ensuring the business stays aligned with regulatory standards and internal policies. It's an excellent opportunity for career growth in a dynamic ...
-
Cyber Security Risk Consultant
7 days ago
South West England, United Kingdom Experis LTD Full time**Cyber Security Risk Consultant - DV cleared IR35 Status - PAYE Engagement only Duration - 6 Months + Start Date - ASAP Location - Wiltshire** **Must hold valid DV Clearance** **Job Specification**: Understand and advise on cyber security vulnerability, risks, audit & compliance in a business or operational context and cyber security threat...
-
Cyber Security Risk Consultant
6 days ago
South West England, United Kingdom Experis LTD Full time**Cyber Security Risk Consultant - SC cleared IR35 Status - Inside Duration - 6 Months + Start Date - ASAP Location - Wiltshire/Remote** **Must hold valid SC Clearance** **Job Specification**: Understand and advise on cyber security vulnerability, risks, audit & compliance in a business or operational context and cyber security threat environment **Key...
-
Enterprise Risk and Governance Manager
2 weeks ago
West Sussex, United Kingdom InterQuest Group Full timeAre you ready to take on a pivotal role within one of the UK’s leading financial networks? As the Enterprise Risk & Governance Manager , you’ll play a critical role in strengthening our second line of defence, driving risk maturity, and ensuring we maintain a robust risk management culture. Key Responsibilities: Own and enhance the Group Risk...