Information Security and Compliance Lead
1 week ago
Information Security and Compliance LeadJoin to apply for the Information Security and Compliance Lead role at HCRG Care GroupJob IntroductionThis is one UK-wide remote role advertised across multiple locations to reach a broad pool of candidates. If you have already applied and see the role listed elsewhere, you do not need to apply again.We’re looking for a motivated and detail-driven Information Security & Compliance Lead to help us strengthen the way we govern, protect and assure our digital environment. You’ll play a key role in ensuring our systems, services and processes meet the national standards and regulatory expectations we work to, including DSPT, Cyber Essentials Plus, and the Cyber Assessment Framework.Working closely with our Head of Information Security & Enterprise Architecture, you’ll provide senior support across policy development, assurance activity, supplier governance and risk management. You’ll help us maintain a robust and well-evidenced Information Security Management System (ISMS), ensuring our approach to compliance is consistent, well-structured and embedded across the organisation.This is an excellent opportunity for someone with hands‑on security or infrastructure experience who now wants to broaden their impact across compliance, governance and operational assurance. You’ll collaborate with technical teams, service operations and transformation colleagues, helping to embed secure‑by‑design thinking and maintain a strong security posture across our hybrid digital estate.From time to time, you may need to visit our Runcorn office or another HCRG site as part of the role.Main ResponsibilitiesSupport the delivery and monitoring of secure infrastructure services across cloud, on‑premises and hybrid environmentsEnsure security and compliance controls are applied consistently across networks, servers, endpoints and backup environmentsContribute to the maintenance of the ISMS, including policies, procedures and risk registersSupport internal and external audit activity, evidence gathering and assurance reviewsMonitor compliance with frameworks such as DSPT, Cyber Essentials Plus (CE+) and the Cyber Assessment Framework (CAF)Provide clear, practical security and compliance input for supplier reviews, contract renewals and new technology onboardingSupport incident management processes, including root cause analysis and follow‑up improvementsContribute to business continuity and disaster recovery planning with relevant technical teamsCollaborate closely with Infrastructure, Service Operations, Business Systems and Transformation teams to embed secure‑by‑design principles across services and projectsShare guidance, raise awareness and promote good security and compliance practices across the organisationThe Ideal CandidateWe’re looking for someone who is genuinely confident working in a compliance‑led security role, who understands how to apply standards, manage evidence, guide colleagues, and keep us aligned with national requirements. You’ll be comfortable balancing practical security with robust governance, and you’ll bring a steady, structured approach to maintaining assurance across our digital environment.Essential RequirementsStrong understanding of information security principles, with the ability to apply them in a compliance and governance contextHands‑on experience supporting compliance with frameworks such as:Data Security and Protection Toolkit (DSPT)Cyber Essentials Plus (CE+)Cyber Assessment Framework (CAF) or ISO 27001Confident reviewing controls, assessing risks, and producing clear, well‑evidenced mitigation plansFamiliarity with public sector or NHS data protection responsibilities, including GDPR and NHS Data Security StandardsExperience contributing to incident response and ensuring that lessons learned are properly documented and embeddedStrong documentation skills – able to produce accurate policies, procedures, risk records and audit evidenceComfortable working with Infrastructure, Service Operations and Transformation teams to ensure security and compliance requirements are understood and built in from the startAble to work effectively with auditors, suppliers and governance groups, presenting information clearly and professionallyDesirableExperience working within private cloud or hybrid environments, particularly where compliance requirements vary across servicesFamiliarity with toolsets such as EDR, vulnerability scanning, SIEM or MDM, particularly in relation to evidence gathering and assurance reportingRelevant professional certifications (e.g., Security+, SSCP, ISO 27001, CISMP, CISSP Associate)Understanding of backup and disaster recovery security principles, including compliance considerationsPackage DescriptionAs our new Information Security & Compliance Lead, you’ll be part of our valued team at HCRG Care Group.Salary: £50,000 – £55,000 with group pensionPrivate medical insurance with fast access to specialist support, including musculoskeletal and mental health services, available at locations across the UKMembership of My Reward Hub, giving you discounts on everyday purchases such as groceries, plus cashback and voucher offers for you and your loved onesAccess to your wages as you earn them, helping you manage unexpected expenses without high interest or overdraft feesOnline and face‑to‑face wellbeing support for both mental and physical health, from healthy recipes and activity challenges to counselling, trauma support, career coaching and moreAccess to eLearning, bespoke career pathways and professional development through our Outstanding Learning Enterprise teamAn open, supportive culture where your ideas and contributions can shape how we deliver our purpose: changing lives through transforming health and care, supported by at least £100,000 of ring‑fenced innovation funding each yearThe pride of working for an organisation committed to the highest clinical and quality standards, with the majority of our services rated “Good” or “Outstanding” by the Care Quality CommissionAbout the CompanyWe change lives by transforming health and care.Established in 2006, we are one of the UK's leading independent providers of community health and care services, working with health and care commissioners and communities to transform services with a focus on experience, efficiency and improved outcomes. We deliver and transform adult and children community health services, primary care services including urgent care, sexual health, dermatology and MSK services as well as adult social care and wellbeing services. Across England, we support communities of many millions and directly help more than half a million people each year – guided by our simple values: we care, we think, we do.We’re committed to equal opportunities and welcome applications from a broad, diverse range of people who want to join our team. We’re a Disability Confidence company, so we work to provide facilities, work environment adjustments and technical solutions to be as inclusive of everyone.Safeguarding and protecting the children, young people and vulnerable adults that we work with is of the utmost importance. We have policies and procedures in place to promote safeguarding and safer working practices and everyone who joins the team is subject to a safer recruitment process, including the disclosure of criminal records and vetting checks.Finally, we need to let you know that the company you’ll work for is part of HCRG Care Group Holdings Limited and by applying for this job we’ll need to process and hold information about you. If you would like to know a little more about how we use your information, please see our website’s privacy policy. #J-18808-Ljbffr
-
Remote Information Security
1 week ago
Greater London, United Kingdom HCRG Care Group Full timeA leading community health services provider is looking for an Information Security and Compliance Lead. You will oversee governance and compliance, ensuring systems meet national standards. The role is UK-wide remote with occasional office visits. Required skills include expertise in information security principles, compliance frameworks, and strong...
-
Information Risk Specialist
2 weeks ago
London, United Kingdom Information Security Solutions Full timeCompany: Financial Services Location: Hybrid - City of London Reports to Information Risk Manager **Salary**: £80,000 Benefits: Generous No. Required: 1 Start Date: ASAP **The Role** As the Information Security Risk Specialist, you shall support the Information Risk Manager which has responsibility for all Governance Risk and Compliance activities in the...
-
Senior Information Security Officer
1 week ago
Greater London, United Kingdom Cyber Security training courses Full timeYour new role - Permanent - ON SITE 5 Days per week. You will be required to undergo vigorous onboarding checks - UK Only. Sponsorship NOT available. The main purpose of this job mainly focusses on information security, cybersecurity, and data security from a Greenfield perspective. We are on a journey to secure Cyber Essentials plus and ISO27001...
-
Lead Information Security Engineer
1 week ago
Greater London, United Kingdom Picture More Full timeLead Information Security Engineer Location: London Hybrid (3 days office / 2 WFH) Salary: Competitive + benefits Are you an experienced information security professional ready to make an impact on a global scale? Our client, a leading international law firm, is seeking a Lead Engineer – Information Security to join their London–based global technology...
-
Security Manager
7 days ago
London, Greater London, United Kingdom Information Security Solutions Full time £120,000 - £160,000 per yearWe are searching for candidates that match the role below:Title………………………Security ManagerCompany………………Financial ServicesLocation………………..LondonWorking pattern……Hybrid – 2 days per week in the officeSalary……………………£120,000 - £160,000The RoleWe are seeking a Security Manager to lead security...
-
Information Security Lead, Europe
5 hours ago
Greater London, United Kingdom Corpay Full timeYour role Responsible for monitoring, reacting and reporting on information security events as well as supporting the management of security operations activities within the core business lines in the U.K., Europe, Australia and New Zealand. Provide governance and support for regulatory and industry compliance requirements, facilitate audit activities and...
-
Greater London, United Kingdom Navro Full timeA fast-growing fintech startup in London seeks an Information Security Manager to lead security governance and compliance efforts. This role offers the freedom to implement security measures and policies while ensuring compliance with international standards. Join a dynamic team focused on innovative payments solutions, where your expertise will directly...
-
Information Security Compliance Manager
2 days ago
London, United Kingdom Sopra Steria Full timeAre you a Security and Compliance Manager looking for your next challenge? Come and join our well-established IA team within the SSCL sector! As an Information Security Compliance Manager, you will be responsible for implementing the strategy, policies and working practices defined within the Information Security Management System (ISMS) and Cyber Security...
-
Information Security Analyst — Hybrid, Risk
1 week ago
Greater London, United Kingdom WH Smith PLC Full timeA leading retail company in Greater London is seeking an Information Security Analyst to oversee information security policies, manage risk assessments, and ensure compliance with regulations. Responsibilities include maintaining security standards and documentation, along with facilitating corporate training programs. This role offers a hybrid working...
-
Senior Information Security Compliance Analyst
2 weeks ago
London, Greater London, United Kingdom WiseTech Global Full time £60,000 - £120,000 per yearThe RoleWe're looking for a technically-grounded Senior IS Compliance Analyst who speaks both security operations and compliance language fluently. This role sits at the critical intersection of technical security and governance, requiring someone who can translate complex security architectures into compliance frameworks and vice versa.You'll be...