Business Information Security Officer & Cybersecurity Programme Lead
Summary
As Business Information Security Officer & Cybersecurity Programme Lead at Gist, you own and strengthen the company's cybersecurity posture: leading the security transformation roadmap, managing the risk register, audits and executive reporting, and coordinating between business teams, M&S Information Security, auditors and suppliers. Core focus: security governance, risk management and programme
At Gist, we're proud to be part of the M&S Group, the logistics engine behind M&S Food.
From our distribution centres to our transport operations and support functions, we connect people, technology and expertise to ensure the right products reach the right stores at the right time.
As we continue to invest in our people, technology and network, there's never been a more exciting time to join Gist and help shape the future of food logistics.
The Opportunity
We are looking for an experienced Business Information Security Officer (BISO) & Cybersecurity Programme Lead to join Gist and play a pivotal role in strengthening and transforming our cybersecurity capability.
This is a high impact role at the intersection of business, technology, risk and security. You will be responsible for ensuring Gist maintains a fit-for-purpose cybersecurity posture, while leading the delivery of our cybersecurity transformation roadmap and establishing the operating model needed to sustain long-term security maturity.
You will work closely with business leaders, technology teams, M&S Information Security, auditors, suppliers and strategic partners providing pragmatic security leadership, challenging where necessary and ensuring cyber risk is understood, managed and reported effectively.
What you'll be doing
Reporting to the Head of Technology Operations & Security, you will lead our cybersecurity roadmap, strengthen our security operating model and provide pragmatic leadership that protects the business while enabling it to grow.
As the BISO, you will connect business, technology, M&S Information Security, auditors and strategic partners, ensuring cyber risk is understood, managed and embedded into decision making. You will lead security risk and assurance, own the Security risk register, oversee audits and remediation, and provide clear reporting to senior leaders.
You will drive our cybersecurity transformation programme, turning strategy into action, coordinating teams and partners, managing risks and dependencies, and building compelling business cases for security investment. As well as providing security oversight across major change and incidents, ensuring lessons learned translate into lasting improvements.
You will be a pragmatic, confident security leader with strong experience across cybersecurity governance, risk, assurance or programme delivery. You will be a strong communicator and influencer, comfortable challenging at all levels and translating complex security risks into practical business actions.
What we're looking for
We are looking for someone who combines strong cybersecurity expertise with excellent business judgement and the ability to make security practical. You will be able to demonstrate:
- Significant experience in cybersecurity governance, information security, risk management, compliance or security programme leadership.
- A proven track record of delivering security transformation and risk reduction initiatives.
- Experience developing business cases, executive reporting and investment recommendations.
- Strong stakeholder engagement, influencing and communication skills.
- Experience working with auditors, suppliers and strategic security partners.
- A strong understanding of modern security domains, including identity, network security, cloud security, endpoint protection, governance and risk management frameworks.
- The ability to apply pragmatism and commercial thinking to security challenges.
- Experience working across business, operational and technology teams, translating complex security risks into clear and practical actions.
- The confidence to challenge and influence at all levels, including senior leadership.
This isn’t simply a governance role. You will have the opportunity to shape how Gist manages cybersecurity, influence investment and transformation priorities, and build the operating model that will underpin our security capability for the long term. If you are a pragmatic cybersecurity leader who can operate strategically while getting things done, we would love to hear from you.
Role details:
Salary: Up to £85,000 per annum (DOE)
Hours: Monday to Friday, 9am to 5pm.
Location: Gist Ltd, Rosewood, Crockford Lane, Chineham Park, RG24 8UB - This is a site-based role, working from our Chineham Office 5 days a week.
What’s in it for you?
As well as a competitive salary, you'll benefit from:
- 20% M&S discount on most things from furniture, fashion and food
- 25 days’ annual leave plus bank holidays (rising with length of service)
- Discounted rates on healthcare cash plan
- Attractive annual bonus scheme, based on M&S performance and personal objectives
- Auto Enrolment Pension or competitive Defined Contribution Pension Scheme and life assurance (up to 4 times salary)
- Amazing perks and discounts via our App to major restaurants and retailers
- Access to a wide range of wellbeing support – including our Employee Assistance Programme
- A first-class welcome with a tailored induction and a wide range of training schemes to help with your learning and development
- Cycle to work scheme
Why Gist?
When you join Gist, you're joining a business that plays a critical role within the M&S Group.
You'll have the opportunity to influence meaningful change, work alongside experienced leaders and contribute to one of the UK's leading food supply chains.
Our culture is built around our values of being Progressive, Accountable, Collaborative and Ethical, creating an environment where people are trusted, supported and encouraged to grow.
Whether you're leading a site operation, delivering transformation or shaping future strategy, your work will make a real difference.
Our commitment to inclusion
At Gist, we believe our differences make us stronger.
We're committed to building an inclusive workplace where everyone feels valued, respected and able to succeed. We welcome applications from people of all backgrounds, experiences and perspectives.
If you require any reasonable adjustments at any stage of our recruitment process, please let us know. We'll work with you to ensure you have the support you need.