Cyber and Information Security Officer

3 days ago


Remote, United Kingdom AKG (UK) EMPLOYMENT LIMITED Full time £35,000 - £70,000 per year

JOB DESCRIPTION

AKG Group UK Company:

AKG UK Shared Services

Position Title:

Cyber & Information Security Officer

Job Level

7

Role Status:

Full Time

Reports To:

Information Security Manager and DPO

Roles Reporting to this Position:

None

Primary Objective:

To support the Information Security and IT Managers and assist with the implementation and maintenance of cyber and information security controls across all AKG UK entities and monitor compliance.

To deputise for the Information Security Manager when required and in their absence act as the point of contact for the Information Commissioners Office, Department for Work & Pensions (DWP) and other commissioners and stakeholders in relation to information security and data protection.

To contribute to the achievement and continuation of required Security Certifications including Cyber Essentials Plus and ISO27001:2022, supporting with the provision of evidence for external audit and attending external meetings.

Key Relationships/Interactions

Internal

  • IT Department including internal Helpdesk
  • IT Support Provider
  • Facilities & Procurement
  • Delivery Partners
  • Audit & Risk
  • Operations

External

  • DWP
  • Contract Commissioners
  • ICO
  • Accreditation Bodies and External Auditors

Key Responsibilities

  • Work closely with the Information Security Manager and IT Department to ensure that data security requirements are met across all data management systems
  • Provide cover for the Delivery Systems Owner to support with ticket resolution as and when required
  • Work with IT Team to develop and implement cyber security strategies
  • Implement and maintain information security framework requirements, ensuring governance and compliance requirements are met
  • Assisting with the implementation and review of data processing processes ensuring compliance with GDPR, DPA, and ISO27001
  • Propose and draft a range of policies, procedures and processes and undertake annual reviews of existing documentation
  • Actively promote training and awareness to a range of stakeholders
  • Assist with the provision of materials and tools for the ongoing education programme for all staff regarding cyber and information security and monitor compliance with mandatory training
  • Undertake auditing of premises, processes and departments to ensure ISO27001 compliance
  • Support with Data Retention and Records Management procedures and processes
  • Assist with responses to Data Subject Access Requests and other information requests, including provision of e-Discovery searches, extraction of data from the CMS, and subsequent review and redaction
  • Undertake the investigation, management and response to security incidents, including analysis and feedback to the organisation
  • Undertake information security risk management and maintain the information security risk register
  • Produce reports in relation to performance targets, effectiveness measurements and trends analysis for the information security governance group, including for example starters, leavers, training completions.
    Undertake regular access, account and activity reviews.

Essential/Desirable Skills, Knowledge and Experience

  • Able to quickly identify problems, think flexibly and resolve issues.
  • Clear communication skills in providing advice, guidance and resolutions to a range of staff and stakeholders.
  • Flexibility to cope with the varying demands of the role, managing time effectively to achieve the desired results.
  • Comfortable working remotely using a range of digital channels including phone, video conferencing, instant messaging, and email.
  • Excellent IT, administration and organisational skills with practical experience of using MS office software.
  • Solid understanding of ISO27001.
  • Knowledge of data governance policies and procedures.
  • IT literate and proficient in the use of Microsoft Office 365 products and services, including:

  • Microsoft Defender for Office 365: threat protection, alert management

  • Microsoft Purview Compliance Portal: DLP, eDiscovery, audit logs, compliance tools
  • Azure Active Directory / Microsoft Entra ID: identity and access management, conditional access, MFA
  • Microsoft Intune: device compliance, security baselines
  • Microsoft 365 audit logs: activity and access reviews, reporting
  • Incident response: investigating and managing security incidents using Microsoft 365 tools
  • Secure user lifecycle management: permissions, starters/leavers, access reviews

  • Good verbal and written communication skills.

  • Team player comfortable working with minimum supervision using personal drive, enthusiasm and presence to succeed.
  • Bring energy, dynamism and creative problem solving to issues.
  • Minimum of 3 years similar experience in the field of IT, cyber security or information security.
  • Practical experience in managing risk.
  • Compliance background.
  • Effective and clear communicator with good negotiation skills.
    Experience of leading on audits undertaken by external third parties

Compliance

  • It is the responsibility of all staff to abide by organisational policies to ensure compliance with relevant standards e.g. ISO Information Security), ISO 9001 (Quality) and ISO Environmental) as well as adhering to statutory duties in relation to safeguarding, Prevent and health and safety.


  • Remote, United Kingdom UK Health Security Agency Full time

    **Details**: **Reference number**: - 267312**Salary**: - £29,160 - £35,612- National banding £29,160 - £35,612 - per annum. Outer London £31,070 - £37,829 per annum. Inner London - £32,978 - £39,691**Job grade**: - Higher Executive Officer**Contract type**: - Permanent**Type of role**: - Analytical - Architecture and Data - Digital - Information...


  • Remote, United Kingdom Police Digital Service Full time

    **Join Police Digital Service as PDS Information Security Officer** **About Police Digital Service** To protect people from harm in our rapidly changing world, police services must not only keep up with technology and business changes but develop capabilities and ways of working that will enable them to adapt to and deal with the complexity of modern...


  • Remote, United Kingdom Induction Healthcare Group plc Full time

    **Purpose**: As an Information Security Officer/Specialist, you will support the delivery of the Information Security vision and strategy and roadmap, whilst also contributing to the definition of the security programme. You will be a key member of a small team of security professionals, delivering global Information Security services to Induction...


  • Remote, United Kingdom Appoint Consulting Ltd Full time

    **ICT/Cyber Security Tutor - Fulltime - Permanent** Our client is looking for a Cyber Security Tutor to join their well-established team of Tutors, delivering funded and non-funded courses online. The role is full-time over seven days a week and requires flexibility as learners may require lessons on evenings or weekends. Good time management is key to this...


  • Remote, United Kingdom Induction Healthcare Group PLC Full time

    UK (Remote with occasional travel) - Posted 1 week ago **Job Title**: Information Security Officer / Specialist **Business Area**: Product & Technology **Reporting to**: Head of Information Security **Location**: UK (Remote with occasional travel) **Purpose**: As an Information Security Officer/Specialist, you will support the delivery of the...

  • Cyber Security Trainer

    20 hours ago


    Remote, United Kingdom Imeta Training and Solution Ltd Full time

    Job Summary: - **Summary of Post**:_ Working within a busy department, the role of a Technical Tutor is to ensure there is effective learning delivered online and ensure that learners achieve their maximum potential throughout the programme. Our courses are delivered in three hour sessions and evening delivery will be part of shift pattern e.g 6.00pm...


  • Remote, United Kingdom Littlefish Full time

    **Come and join the Littlefish team!** **Work location: Remote** Here at Littlefish, we look for people who can make a real difference and become a giant slayer. As the world around us continues to change, we look for people who grab that change with optimism and excitement. These are the passionate and high performing people who enjoy and thrive on thinking...


  • Remote, United Kingdom Doncasters Full time £80,000 - £150,000 per year

    Are you an experience Head of Information Security looking for your next opportunity?At Doncasters we have an exciting opportunity for a Head of Information Security to join our Group Head Office Team working remotely in the UK.Working hours: Monday – Thursday – 8:30 – 17:00, Friday – 8:30 – 14:10Place of work: remote to the UK, this role will...


  • Remote, United Kingdom FORM3 Full time £60,000 - £120,000 per year

    Location100% Remote (UK)Join Form3's Information Security Governance, Risk and Compliance team and build the frameworks that protect our people, technology, and customers as we power the future of payments.THE ROLEAs an Information Security Officer at Form3, you'll play a pivotal role in strengthening and evolving our information security governance, risk,...


  • Remote, United Kingdom Synapri Full time £60,000 - £120,000 per year

    Location: Remote (occasional site visits nationally - likely Birmingham)Duration: 6 months +Vetting: SC security clearance will be requiredRole DescriptionGovernance Lead with the GRC team, under direction of the Head Of GRC.Experience / Skills / QualificationsAt least 10 years of experience in cyber security.At least 7 years of experience in technical roles...