Information Security Officer
2 days ago
THE ROLE
As an Information Security Officer at Form3, you'll play a pivotal role in strengthening and evolving our information security governance, risk, and compliance practices. Working within the Information Security team, you'll help ensure that Form3 continues to operate securely and maintain the trust of our customers and partners.
You'll work closely with teams across the organisation, from Engineering and Product to Legal and Risk teams, to embed security into business and technology decisions. This is a hands-on role that combines strategic oversight with practical execution, ensuring our controls, frameworks, and awareness initiatives remain industry leading as we scale globally.
What you'll do
- Apply expert knowledge of security frameworks and controls such as NIST, ISO22301, ISO27001, ISO27017/18, ISAE3000/SOC2, and GDPR to support security governance.
- Support the development, maintenance, and continual improvement of the ISMS and BCMS.
- Assist in drafting and maintaining Information Security Policies and ensure alignment with business and customer requirements.
- Contribute to the planning and execution of external audits, engaging directly with auditors and customers.
- Monitor and report on adherence to security controls across all areas of the business via risk assessments and internal audits.
- Assess and support the remediation of information security risks, non-conformities, and issues across systems and services.
- Support vulnerability management processes, from triage and tracking to remediation reporting, in partnership with Offensive Security and Engineering teams.
- Conduct vendor and third-party security assessments, ensuring suppliers meet Form3's security and compliance requirements.
- Partner with the Defensive Engineering team to ensure security requirements are built into product developments.
- Deliver and enhance security awareness and training initiatives to promote a strong security culture across Form3.
- Collaborate with the Security Operations team to maintain situational awareness of emerging threats and vulnerabilities, ensuring timely escalation and risk-based response.
WE'RE LOOKING FOR
Form3's Information Security Governance, Risk and Compliance (GRC) team plays a critical role in protecting the organisation, so we're looking for someone who is analytical, collaborative, and passionate about driving security excellence. You'll thrive on solving complex problems, balancing deep technical knowledge with strong governance principles, and finding ways to make security scalable across a fast-moving, cloud-native business.
Essential
- 5+ years' experience in Information Security, ideally within a fast-paced technology or financial services industry.
- Strong working knowledge of frameworks such as ISO27001, ISO22301, SOC 1, SOC 2, NIST, and GDPR.
- Proven experience developing, implementing, and improving information security policies, standards, and controls aligned to recognised frameworks.
- Hands-on experience conducting audits, risk assessments, and business impact analyses.
- Hands-on experience with vulnerability management within a complex and dynamic cloud environment
- Broad understanding of cloud security
- Excellent communication and stakeholder engagement skills, with the confidence to influence at all levels of the organisation.
- Analytical mindset with a focus on continual improvement and measurable outcomes.
Desirable
- Security-related qualifications such as CISSP, CISM, CISA, or ISO27001 Lead Implementer/Auditor.
- Experience leading certification and attestation programmes such as ISO27001, ISO22301 or SOC 2
- Experience operating in regulated or high-availability environments such as financial services, payments, or critical infrastructure.
- Familiarity with GRC tooling and automation to streamline compliance, risk, and control management activities.
THE TEAM
This role sits within Form3's Information Security Governance, Risk and Compliance (GRC) team and reports directly to the Head of GRC. As part of a highly collaborative security function, you'll play a key role in shaping how Form3 manages information security risk, compliance, and assurance across all areas of the business.
The GRC team underpins Form3's security standards, designing and maintaining the frameworks, policies, and controls that keep our people, systems, and customers safe. Joining at this stage offers the opportunity to make a significant impact, strengthening governance and compliance across a cloud-native, environment while helping define how security scales with the business.
INTERVIEW PROCESS
Stage 1: Interview with Principal Security Officer
Stage 2: Interview with Head of GRC
We always aim to stick to the above process, however there may be occasions when an additional interview stage is needed for us to be sure we're hiring the right person
OUR DEI&B COMMITMENT
We hire talented people from a variety of backgrounds and experiences and are committed to a work environment based on diversity, open-mindedness and curiosity. We're united by our company values (we even created them together) and we celebrate our unique differences.
Our employee lifecycle processes are designed to embrace equal opportunity and prevent discrimination against our people regardless of personal characteristics. It is our strong belief that the more inclusive and belonging we are as a business, the better our work will be.
As an inclusive employer, we guarantee to interview all neurodiverse and physically disabled applicants who meet the minimum criteria for this role. We also encourage candidates to notify us of any reasonable adjustments that may be required during the recruitment process. This includes providing job adverts in alternative, accessible formats or adjustments required at interview stage.
If you consider yourself to be neurodiverse or physically disabled under the UN definition of disability and would like to be considered under this scheme and/or require any reasonable adjustments please let us know by sending an email to clearly stating your consent for us to process this data. For more information please refer to our Recruitment Data Policy.
-
Information Security Officer
6 days ago
% Remote (UK), United Kingdom Form3 Full time £60,000 - £120,000 per yearTHE ROLE As an Information Security Officer at Form3, you'll play a pivotal role in strengthening and evolving our information security governance, risk, and compliance practices. Working within the Information Security team, you'll help ensure that Form3 continues to operate securely and maintain the trust of our customers and...
-
Information Security Officer
3 days ago
Remote, United Kingdom Induction Healthcare Group plc Full time**Purpose**: As an Information Security Officer/Specialist, you will support the delivery of the Information Security vision and strategy and roadmap, whilst also contributing to the definition of the security programme. You will be a key member of a small team of security professionals, delivering global Information Security services to Induction...
-
Information Security Officer
5 days ago
Remote, United Kingdom FORM3 Full time £60,000 - £120,000 per yearLocation100% Remote (UK)Join Form3's Information Security Governance, Risk and Compliance team and build the frameworks that protect our people, technology, and customers as we power the future of payments.THE ROLEAs an Information Security Officer at Form3, you'll play a pivotal role in strengthening and evolving our information security governance, risk,...
-
Information Security Engineer
1 week ago
UK - Remote, United Kingdom Xiatech Full time £60,000 - £90,000 per yearDescriptionAbout us We're a culture-first organisation and put our people at the forefront of everything we do. We believe that a great working environment leads to a happy and productive team which is why we offer our staff the flexibility to work remotely or from our beautiful office in Fitzrovia, Central London. Xiatech is the pioneer of Xfuze, the...
-
Cyber and Information Security Officer
5 days ago
Remote, United Kingdom AKG (UK) EMPLOYMENT LIMITED Full time £35,000 - £70,000 per yearJOB DESCRIPTIONAKG Group UK Company:AKG UK Shared ServicesPosition Title:Cyber & Information Security OfficerJob Level7Role Status:Full TimeReports To:Information Security Manager and DPORoles Reporting to this Position:NonePrimary Objective:To support the Information Security and IT Managers and assist with the implementation and maintenance of cyber and...
-
Information Security Officer/specialist
2 weeks ago
Remote, United Kingdom Induction Healthcare Group PLC Full timeUK (Remote with occasional travel) - Posted 1 week ago **Job Title**: Information Security Officer / Specialist **Business Area**: Product & Technology **Reporting to**: Head of Information Security **Location**: UK (Remote with occasional travel) **Purpose**: As an Information Security Officer/Specialist, you will support the delivery of the...
-
Pds Information Security Officer
1 week ago
Remote, United Kingdom Police Digital Service Full time**Join Police Digital Service as PDS Information Security Officer** **About Police Digital Service** To protect people from harm in our rapidly changing world, police services must not only keep up with technology and business changes but develop capabilities and ways of working that will enable them to adapt to and deal with the complexity of modern...
-
Manager - Information Security
1 day ago
Remote, United Kingdom Cencora Full timeOur team members are at the heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on that purpose. If you want to make a difference at the center of health, come join our innovative company and help us improve the lives of people and animals...
-
Regional Information Security Officer
1 week ago
Brunel St, Birmingham B, UK, United Kingdom Konsento Full time £80,000 - £120,000 per yearCompany Description Konsento is searching a talented candidate for our client.Our client is a global life-science company, with employees all over the globe and with presence in 47 countries at the moment. Job Description The Regional Information Security Officer will be responsible for the implementation and running of IT Risk Management...
-
Chief Information Security Officer
5 days ago
Remote, United Kingdom Nasstar Full time**WE’RE RECRUITING!** **Do you have experience operating as a Chief Information Security Officer (CISO) within a company of 1000+ employees? If so, we have an opportunity where you will drive compliance and awareness across the Group with a rapidly growing MSP that is going places!** **Salary**:Competitive base + bonus + benefits **Job...