Information Security Officer

1 month ago


Glasgow, Scotland, United Kingdom Ashurst Full time

About Ashurst:

Ashurst is a leading progressive global law firm with a rich history spanning more than 200 years. We are proud of our history and are future-focused, having expanded into new technologies through our NewLaw division, Ashurst Advance, and our consulting arm. Our in-depth understanding of our clients and commitment to providing excellent standards of service have seen us become a trusted adviser to local and global corporates, financial institutions and governments in all areas of commercial law.

In order to comply with regulatory and client requirements, Ashurst will undertake appropriate vetting of staff. When applicants accept a job offer, Ashurst, alongside a specialist provider, will undertake professional verification and background checks. These checks are only undertaken with consent, and in accordance with our legal and regulatory obligations.

Role Overview

The successful candidate will play a crucial role in ensuring the security of our systems and data by evaluating the risks associated with third-party vendors and internal projects, and recommending appropriate risk mitigation strategies.

The Information Security Officer will work closely with cross-functional teams, including the IT, Risk & Compliance, project management, and technical teams, to ensure compliance with security standards and best practices.

Responsibilities and Key Skills

Assessing Security Risks (SCTY - Level 4, BURM - Level 4)

  • Conduct vendor risk assessments and project security risk assessments based on established methodologies and frameworks.
  • Evaluate security risks associated with third-party vendors and internal projects, considering factors such as security, privacy, and compliance.
  • Identify vulnerabilities and potential risks and provide recommendations for risk mitigation strategies.
  • Apply knowledge of industry best practices and regulatory requirements to assess and mitigate security risks.

Information Security (SCTY - Level 4)

  • Ensure compliance with security policies, standards, and procedures in vendor relationships and project activities.
  • Develop and maintain security assessment frameworks and methodologies for vendor risk assessments and project security risk assessments.
  • Stay informed about emerging security threats, industry trends, and regulatory requirements related to vendor management and project security.
  • Participate in incident response activities and contribute to security incident investigations and remediation efforts.

Supplier Relationship Management (SUPP - Level 4)

  • Collaborate with procurement teams to assess and manage security risks associated with vendors.
  • Review vendor security documentation, such as questionnaires, audits, and certifications, to evaluate their security posture.
  • Provide guidance to procurement teams regarding security requirements and standards for vendor selection and ongoing monitoring.

Risk Management (BURM - Level 4)

  • Apply risk management principles to identify, assess, and prioritise security risks.
  • Collaborate with project managers and technical teams to assess security risks and propose appropriate risk mitigation strategies.
  • Track and monitor the implementation of security remediation plans.

Security Compliance Management (SCAD - Level 3, SCTY - Level 4, AUDT - Level 4)

  • Conduct periodic reviews and audits to ensure compliance with security policies, standards, and regulatory requirements.
  • Support the development and enforcement of security policies, standards, and procedures related to vendor management and project security.
  • Support Security audit activities conducted by Internal audit, clients and certification bodies e.g. ISO27001
  • Provide security awareness training and guidance to staff as required.

Qualifications and Experience

  • Bachelor's degree in Computer Science, Information Technology, or a related field (or equivalent work experience).
  • Professional certifications such as CISA, CISM, or similar credentials are preferred.
  • Strong knowledge of information security principles, best practices, and standards (e.g., ISO 27001, NIST).
  • Experience in co-ordinating and participating in Security audits.
  • Experience in conducting vendor risk assessments and project security risk assessments.
  • Familiarity with security frameworks and assessment methodologies.
  • Knowledge of regulatory requirements related to data privacy and protection (e.g., GDPR, CCPA) is a plus.
  • Strong analytical and problem-solving skills.
  • Excellent written and verbal communication skills.
  • Ability to work independently and collaboratively in a team-oriented environment.
  • Attention to detail and a commitment to maintaining high-quality standards.

Other Responsibilities (as required)

  • Other suitable duties, consistent with the duties and responsibilities of the position as directed by the supervisor or nominated delegate.




  • Glasgow, Scotland, Scotland, United Kingdom Next Ventures Full time

    We are seeking a Telecom Security Engineer for a 12 months project in Glasgow.A highly skilled Commissioning Engineer with background in telecom and/or physical security systems. Minimum of 3 years of experience in overseeing the installation, testing, and commissioning of complex telecommunications and security infrastructures.Adept at ensuring systems meet...


  • Glasgow, Scotland, United Kingdom Ashurst Full time

    About AshurstAshurst is a leading progressive global law firm with a rich history spanning more than 200 years. We are proud of our history and are future-focused, having expanded into new technologies through our NewLaw division, Ashurst Advance, and our consulting arm. Our in-depth understanding of our clients and commitment to providing excellent...


  • Glasgow, Scotland, United Kingdom Thales Part time

    Location: Glasgow, United KingdomIn fast changing markets, customers worldwide rely on Thales. Thales is a business where brilliant people from all over the world come together to share ideas and inspire each other. In aerospace, transportation, defence, security and space, our architects design innovative solutions that make our tomorrow's...

  • Senior Bid Manager

    2 weeks ago


    Glasgow, Scotland, United Kingdom Thales Part time

    Location: Glasgow, United KingdomThales people architect solutions that are relied upon to deliver operational advantage at every decisive moment throughout the mission. Defence and armed forces customers rely on us to deliver the full range of defensive systems for land, sea, and air. From early warning, to threat neutralisation, our platforms cover all...

  • Sales Administrator

    3 days ago


    Glasgow, Scotland, Scotland, United Kingdom Acumen Full time

    About Acumen CyberAcumen Cyber is one of the UK's fastest growing cyber security businesses. We are a managed security services provider specialising in advanced cyber security solutions, dedicated to protecting organisations’ critical assets. As a CREST-accredited leader in the cyber security space, we work with clients to deliver responsive,...

  • Work Cell Manager

    2 weeks ago


    Glasgow, Scotland, United Kingdom Thales Part time

    Location: Glasgow, United KingdomThales people architect solutions that are relied upon to deliver operational advantage at every decisive moment throughout the mission. Defence and armed forces customers rely on us to deliver the full range of defensive systems for land, sea, and air. From early warning, to threat neutralisation, our platforms cover all...

  • Work Package Manager

    2 weeks ago


    Glasgow, Scotland, United Kingdom Thales Part time

    Location: Glasgow, United KingdomThales people architect solutions that are relied upon to deliver operational advantage at every decisive moment throughout the mission. Defence and armed forces customers rely on us to deliver the full range of defensive systems for land, sea, and air. From early warning, to threat neutralisation, our platforms cover all...


  • Glasgow, Scotland, Scotland, United Kingdom Venesky Brown Full time

    Venesky-Brown’s client, a public sector organisation in Glasgow, is currently looking to recruit an Admin Assistant – Events & Facilities for an initial 3 month contract on a rate of £13.91/hour PAYE – working 37 hours per week. This role will be based onsite in Glasgow.Responsibilities:- Administer complex travel and accommodation requirements as...

  • Senior Analyst

    2 weeks ago


    Glasgow, Scotland, United Kingdom Ofgem Full time

    The successful candidate will help to implement regulatory policy for electricity transmission networks, establishing positive working relationships with a broad range of internal and external stakeholders, and representing Ofgem with robust, confident and accurate analysis. You can expect to be involved in technical analysis and statistical/econometric...


  • Glasgow, Scotland, United Kingdom Thales Part time

    Location: Glasgow, United KingdomThales people architect solutions that are relied upon to deliver operational advantage at every decisive moment throughout the mission. Defence and armed forces customers rely on us to deliver the full range of defensive systems for land, sea, and air. From early warning, to threat neutralisation, our platforms cover all...


  • Glasgow, Scotland, United Kingdom Thales Part time

    Location: Glasgow, United KingdomThales people architect solutions that are relied upon to deliver operational advantage at every decisive moment throughout the mission. Defence and armed forces customers rely on us to deliver the full range of defensive systems for land, sea, and air. From early warning, to threat neutralisation, our platforms cover all...


  • Glasgow, Scotland, Scotland, United Kingdom identifi Global Resources Full time

    Senior GRC Consultant / GRC Lead - Secure by the Design projectPermanent, full time role offering £70 000Location: Scotland, with visits to secured site 2-3 days a weekMust have current/active SC or DV clearanceBritish National needed due to security requirementsAbout opportunityWe’re working with our cyber security client who provide expertise and...


  • Glasgow, Scotland, United Kingdom Thales Part time

    Location: Glasgow, United KingdomThales people architect solutions that are relied upon to deliver operational advantage at every decisive moment throughout the mission. Defence and armed forces customers rely on us to deliver the full range of defensive systems for land, sea, and air. From early warning, to threat neutralisation, our platforms cover all...

  • AWS DevOps Engineer

    1 week ago


    Glasgow, Scotland, Scotland, United Kingdom eTeam Full time

    AWS DevOps Engineer6 monthsGlasgow - Hybrid - 2 days in office£400/Day (Inside iR35)(Via Umbrella) Please provide a detailed Job Spec - 6. AWS DevOps Engineera. AWS Expertisea. DevOps Data Governancea. Requirements Analysisa. Machine Learninga. Data Mininga. Strategic Thinkinga. Data Warehousing (DW)a. Change and Transformationa. Professional...


  • Glasgow, Scotland, United Kingdom Siemens Full time

    We know that a business only thrives, when it's people are thriving. That's why we always put our people first. Our global and diverse team would be happy to support you and challenge you to grow in many ways. Who knows where our joint journey will take you? Siemens Mobility have an exciting opportunity for a Specialist Engineer for our Rail...


  • Glasgow, Scotland, United Kingdom Siemens Full time

    We know that a business only thrives, when it's people are thriving. That's why we always put our people first. Our global and diverse team would be happy to support you and challenge you to grow in many ways. Who knows where our joint journey will take you? Siemens Mobility have an exciting opportunity for a Specialist Engineer for our Rail...

  • IAM Specialist

    3 weeks ago


    Glasgow, Scotland, Scotland, United Kingdom Venesky Brown Full time

    Venesky-Brown’s client, a public sector organisation in Glasgow / Dundee, is currently looking to recruit an IAM Specialist for an initial 4 month contract with potential to extend on a rate of £681/day (Inside IR35). This role will be hybrid working with 2 days per week in the office.Responsibilities:- Play a leading role in scoping, defining, and...

  • Python Developer

    1 month ago


    Glasgow, Scotland, United Kingdom Meraki Talent Full time

    Python Developer (Financial Services) Excellent Day Rate (Inside IR35) Glasgow (Hybrid, 50% of time in office) Contract, 6 months+ Posted Tue 17 Sep 24 CVs ASAP Start date Sep – Oct 24 Meraki Talent’s financial services client is actively looking for an experienced Python Developer to help support a new application...


  • Glasgow, Scotland, United Kingdom Eden Scott Full time

    Flexi-time, Flexible Hybrid WorkingEden Scott is delighted to be partnering with our public sector client, serving the public 24/7, 365 days per year, they are integral to our society and are on a mission to create a safer Scotland. This is a fantastic time to join the evolving organisation as they continue their journey of strategic business and technology...

  • Financial Analyst

    2 days ago


    Glasgow, Glasgow City, Scotland, United Kingdom Hays Accountancy and Finance Full time

    Your new company This is an exciting opportunity to join a busy finance team working for one of Glasgow's most prestigious employers. This role is key to the department and involves both financial analysis and business partnering, having a chance to get involved in commercial aspects which have a big impact on the organisation. This role is available on...