Information Security Compliance Lead

608176
  • £50000 - £55000 per annum
  • England
  • Permanent

Key Responsibilities

  • Leading the annual NHS DSPT submission, including evidence collection and reporting.
  • Leading the organisation's progress towards ISO 27001 certification, including evidence gathering and audit coordination.
  • Leading evidence gathering for Cyber Essentials Plus certification.
  • Leading the organisation's alignment to the NIST Cybersecurity Framework, including ongoing maturity assessment and reporting.
  • Monitoring compliance with company metrics, policies, and standards.
  • Reviewing information security policies, standards, and procedures for currency and alignment with DSPT, Cyber Essentials Plus, ISO 27001, and NIST CSF, drafting updates for review and approval by the Head of Cyber Security, IT Risk and Compliance.
  • Arranging delivery of information security training, awareness, and communication.
  • Supporting information security risk management, including assessments and treatment plans.
  • Supporting information security incident management and reporting.
  • Supplier and project information security assurance.
  • Supporting sites and business units with their information security compliance activities.
  • Maintaining the compliance and risk register.
  • Participating in information security meetings and workshops.
  • Preparation of compliance, assurance, and risk reporting for Executive, Risk, and Audit governance forums.
  • Coordination of responses to internal and external audit findings, including tracking remediation actions through to closure.

To Be Successful In This Role, You Will Need

  • Strong knowledge of NHS DSPT, Cyber Essentials Plus, ISO 27001, and NIST CSF.
  • Previous experience in an information security compliance or assurance role within a large or regulated organisation.
  • Experience leading NHS DSPT submissions, including managing timelines and gathering evidence from stakeholders.
  • Experience leading ISO 27001 or Cyber Essentials Plus certification activity, including evidence gathering and coordination with auditors.
  • Experience leading NIST CSF maturity assessments, including evidence gathering and reporting.
  • Understanding of UK data protection obligations (Data Protection Act 2018, UK GDPR).
  • Ability to conduct compliance assessments, risk reviews, and supplier and project assurance.
  • Strong communication and influencing skills with both technical and non-technical stakeholders.
  • Ability to assess departments and system owners against framework requirements, reporting findings to enable the Head of Cyber Security, IT Risk and Compliance to hold them to account.
  • Ability to prepare audit-ready evidence and support compliance reporting.
  • Ability to identify how compliance requirements should be embedded into projects and change programmes.
  • Ability to prepare and present compliance, assurance, and risk reporting for Executive, Risk, and Audit governance forums, and coordinate responses to audit findings through to resolution.

Desirable

  • Familiarity with additional regulatory frameworks or guidance beyond the organisation's core requirements (for example ICO guidance).
  • ISO 27001 Lead Auditor or Lead Implementer qualification.

This is a remote-based role, offering flexibility while ensuring close collaboration with colleagues across services. Occasional travel may be required to support project delivery, governance forums, or training.

Amelia Maun Recruitment Consultant

Apply for this role