Information Security & Governance Lead - £80k

Incite InsightLondon, EnglandOn-siteFull-timeSenior, 5–8 yearsListed 4 hours ago

Apply now

About this role

Salary: £80,000 per annum
Location: London
Reports to: Head of IT Services

The opportunity

An opportunity to work in the Insurance sector working for a Blue Chip employer as an Information Security & Governance Lead .

You will establish and maintain the organisation’s information security framework, technology governance and cyber risk management capabilities. Working closely with colleagues and external service providers, you will ensure security controls are effective, risks are managed and regulatory requirements are supported.
This is a practical individual contributor role with no direct reports. It suits someone who combines strong security and governance knowledge with the ability to turn requirements into workable controls, clear guidance and reliable evidence.

Key responsibilities

- Develop, maintain and improve the information security framework, policies, standards and procedures.
- Ensure security controls are implemented and evidenced across technology services and suppliers.
- Own the technology risk register, facilitate risk assessments and track risk treatment plans.
- Oversee vulnerability management, coordinate penetration testing and monitor remediation.
- Support security incident management and post-incident reviews.
- Coordinate responses to audits, assurance reviews and regulatory requests.
- Support compliance with FCA requirements, UK GDPR, ICO expectations and internal governance standards.
- Conduct supplier security due diligence and ongoing assurance reviews.
- Support procurement and contract reviews from a security and governance perspective.
- Contribute to operational resilience and control testing.
- Develop security awareness activities and advise project and operational teams.
- Ensure information is handled, stored and retained securely, with customer outcomes and Consumer Duty considerations reflected in decisions.

About you

You will bring:

- Proven experience in information security, cyber security, technology risk or governance.
- Strong knowledge of ISO 27001, NIST, CIS Controls and Cyber Essentials.
- Experience of risk management, audit support and regulatory compliance.
- An understanding of cloud security, identity management and third-party risk.
- Experience supporting vulnerability management, penetration testing and incident response.
- The ability to influence colleagues and suppliers and communicate security requirements clearly.
- A practical approach to balancing security, commercial and operational needs.

Financial services experience is important, with insurance or insurance broker experience particularly relevant. CISSP, CISM or an equivalent qualification would be desirable.
Apply

Please submit your CV, highlighting your relevant information security, governance and regulated-sector experience.