Point your AI agent at freehire and let it find you a job.

Get the CLI →

Reed Technology

NewBe an early applicant

Information Security Consultant

Discussion

Summary

The Information Security Consultant will own and maintain the ISO‑27001 ISMS, ensure GDPR and security governance compliance, conduct risk assessments, manage supplier security, and oversee Microsoft 365 security controls while reporting to senior stakeholders.

Salary: £50,000 - 50,000 per year

Requirements:
  • Experience in Information Security Governance, Risk and Compliance (GRC)
  • Experience in Information Security Assurance and risk management
  • Experience with ISO 27001 and Information Security Management Systems (ISMS)
  • Knowledge of GDPR and data protection requirements
  • Experience with security audits, compliance reviews and assurance activities
  • Experience with supplier or third-party security assessments
  • Experience with security incident management and response processes
  • Experience with Microsoft security technologies such as Defender, Sentinel, Entra ID or similar platforms
  • Ability to build strong relationships with stakeholders at all levels
  • Desirable: Cyber Essentials or Cyber Essentials Plus
  • Desirable: Experience with the NIST Cyber Security Framework
  • Desirable: Experience within infrastructure, utilities, energy, defence, engineering, financial services or other regulated sectors
  • Desirable: Professional certifications such as CISSP, CISM, ISO 27001 Lead Auditor/Implementer, Security or equivalent
Responsibilities:
  • Own and maintain the Information Security Management System (ISMS)
  • Ensure compliance with ISO 27001, GDPR and wider security governance requirements
  • Develop and maintain security policies, standards and procedures
  • Conduct security risk assessments and support internal and external audits
  • Manage supplier and third-party security assurance activities
  • Provide oversight of Microsoft 365 security controls, including identity and access management, MFA, endpoint protection and monitoring
  • Work closely with SOC and security service providers to support incident management and response activities
  • Produce security reports, dashboards and assurance documentation for senior stakeholders
  • Deliver security awareness initiatives across the organisation
  • Support continuous improvement of security controls, processes and governance frameworks
Technologies:
  • Incident Management
  • Support
  • Microsoft 365
  • Security
  • Office 365

More:

We are recruiting for an Information Security & Assurance Officer to join a major UK infrastructure programme based in Suffolk onsite. This is a fantastic opportunity for an information security professional who enjoys balancing security governance, compliance and assurance with oversight of operational cyber security activities. You will play a key role in maintaining our Information Security Management System, ensuring compliance with recognised security frameworks, managing risk and assurance activities, and acting as a trusted adviser to both technical and non-technical stakeholders. We offer a 15% project uplift paid monthly, a company car or car allowance, annual bonus, private medical insurance, life assurance, enhanced pension contributions, 25 days annual leave plus bank holidays, an additional holiday purchase scheme, paid professional memberships, and ongoing training and development opportunities. This is an excellent opportunity to join a high-profile programme where you will have real ownership of information security governance and assurance while contributing to the success of a nationally significant project.

last updated 36 week of 2026

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available