Information Security & ISMS Specialist
Information Security & ISMS Specialist
The Role
We're looking for a hands-on Information Security & ISMS Specialist to help drive and mature our security, compliance, and risk management practices.
Working closely with the Information Security Lead and cross-functional teams including Engineering, DevOps, IT, Data Governance, and AI Governance, you'll play a key role in maintaining and improving our ISO 27001-certified Information Security Management System (ISMS).
This is not a traditional tick-box GRC role. We're looking for someone who takes ownership, validates controls firsthand, drives continuous improvement, and helps embed security into the day-to-day operation of the business.
This is a fully remote within the UK or Ireland. Applicants must already have the right to work in the UK or Ireland. Visa sponsorship is not available.
Key Responsibilities
- Support the ongoing management and improvement of the ISO 27001 ISMS.
- Prepare for and support internal, external, customer, and certification audits.
- Maintain security policies, procedures, risk registers, and control frameworks.
- Identify control gaps and drive corrective actions through to completion.
- Conduct vendor and customer security assessments and due diligence activities.
- Ensure evidence is gathered, maintained, and audit-ready.
- Verify security controls independently, including MFA, RBAC, EDR, SIEM, and vulnerability management controls.
- Support business continuity, resilience, and tabletop exercises.
- Deliver engaging security awareness initiatives and promote a strong security culture.
- Work with stakeholders across the business to implement practical, risk-based security solutions.
- Monitor relevant regulatory and compliance requirements, including ISO 27001, GDPR, AI governance, and healthcare-related standards.
Must-Have Experience
- 5+ years' experience in Information Security, ISMS, Governance, Risk & Compliance, or related security roles.
- Hands-on experience managing or supporting an ISO 27001-certified environment.
- Experience supporting both internal and external audits.
- Strong understanding of risk management and security governance.
- Excellent stakeholder management and communication skills.
- Ability to translate technical security requirements into practical business actions.
- Experience working with cloud-based environments and modern security controls.
- Comfortable operating in a fast-paced, high-growth environment with a high degree of autonomy.
Nice to Have
- CISSP or equivalent certification.
- Experience with SOC 2, CIS Controls, ISO 27701, or similar frameworks.
- Technical background with security control implementation experience.
- Experience partnering closely with engineering and product teams.
GCS is acting as an Employment Agency in relation to this vacancy.
Information Security & ISMS Specialist
Other similar jobs
Popular job searches
Your next job
starts here.
JOB SPECIALISMS
LATEST JOBS
TOP SEARCHES
LOCATIONS
- IT Support & Infrastructure
- Project Management
- Engineering
- Data
- Controls & Automation
- BI & Data Analytics
- Network security consultant
- Software Development
- DevOps
- Manufacturing & Production
- Engineering Technology
- Embedded Software
LATEST JOBS
- Information Security & ISMS Sp...
- Senior Resilience & Risk Assur...
- OSP Engineer
- Python Developer
- Senior Frontend Developer
- Web Developer
- Digital Marketing Manager
- AWS Cloud Engineer - 6M Contra...
- Contact Center Manager
- Software Tester
- Satellite Operations Engineer
- IAM Technical Lead
TOP SEARCHES
LOCATIONS
- Engineer
- Data Scientist
- Senior Data Scientist
- Head of Data Science
- Trainee Data Scientist
- Data Science Graduate
- Senior Financial Accountant
- Management Accountant
- Cost Accountant
- Civil Engineer
- Senior Civil Engineer
- Civil Design Engineer