About the Role
We are seeking a highly skilled Senior IT Security Officer to support the day-to-day management of the Information Security Management System (ISMS), regulatory compliance, and security governance.
This role is critical in ensuring the confidentiality, integrity, and availability of our information assets while maintaining compliance with ISO/IEC 27001:2022, UK GDPR, the Data Protection Act 2018, and internal security policies.
You will operate our Drata GRC platform, manage security risks, coordinate vulnerability testing, support incident response, contribute to access governance, and collaborate cross-functionally — working alongside our external vCISO/GRC partner under a clearly defined division of responsibilities. This is a hands-on and strategic role ideal for professionals passionate about security, governance, and continuous improvement.
Key Responsibilities
ISMS & Compliance Management (ISO/IEC 27001:2022, UK GDPR, TISAX, ISO 9001)
Security Risk & Asset Management
Vulnerability Management & Penetration Testing
Access Control & Authorisation
Incident Response & Security Operations Support
Disaster Recovery & Business Continuity
Internal Audit & Governance
Age At least 30 years Experience in Information Security, GRC, risk management, or compliance roles.Hands-on experience with Drata or an equivalent GRC/compliance automation platform (Vanta, Secureframe, Sprinto) — including control monitoring, evidence management, and remediation of failing tests.Working knowledge of ISO/IEC 27001 audits — direct experience of implementation, internal audit, or certification/surveillance audits, including evidence preparation and liaising with external auditors.Strong knowledge of security risk assessment, vulnerability management, and security operations.Experience conducting or coordinating penetration testing and reviewing scan results.Familiarity with incident response processes and access management.Professional Certifications (Preferred)ISO 27001 Lead Implementer (highly desirable) — for candidates with a Lead Auditor qualification, this is valued only for audit liaison and evidence preparation, given this role's operational (non-auditing) function.CISM, CISSP, CRISC, or equivalent security management/risk certification.UK GDPR/Data Protection certification, such as CIPP/E or CIPM (privacy program/operational focus). Full DPO-level qualifications are not required, as the DPO function is independent of this role.CEH, Security+, or similar technical security certification (advantageous, not essential, given this role coordinates rather than performs penetration testing).ITIL Foundation (added benefit).Key Skills & CompetenciesStrong understanding of security governance, standards, frameworks, and controls.Ability to interpret and evaluate control evidence and risk documentation.Excellent communication skills with the ability to work across technical and non-technical teams, including external consultants and auditors.Strong analytical and problem-solving capabilities.Attention to detail and strong documentation skills.Ability to work independently and manage workloads in a dynamic environment.
https://bdjobs.com/h/details/1535140
Category:IT & Telecommunication
Published:18 Sep 2026
Deadline:18 Oct 2026
Category:Sales & Marketing
Published:07 Sep 2026
Deadline:22 Sep 2026