DTG GLOBAL

Associate Business Information Security Officer

London
August 7, 2026
Application ends: September 11, 2026
Apply Now

Apply for this job

Upload CV (txt, doc, docx, xlsx, xls, pdf)
Deadline date:
September 11, 2026
£50000 - £60000 / year

Job Description

We are working with a large UK professional services firm who are building out their Business Information Security Officer function. 

The firm is expanding the scope of its ISMS and driving ISO 27001 certification across more of the business, and you would be working on that alongside the senior BISO.

It is a business facing role rather than a technical one. You would be the first point of contact for teams with security questions, running the operational side of the ISMS, and helping turn control and risk data into something senior stakeholders can actually act on.

The work

  • Supporting ISMS scope expansion and ISO 27001 certification, including gap analysis and evidence gathering
  • Risk register upkeep, control testing, action tracking and chasing remediation to closure
  • Client and supplier security assurance, including security questionnaires and due diligence responses
  • Governance papers and reporting for security forums and business leadership
  • Cyber Essentials Plus and related certification workstreams
  • Security awareness and engagement across the aligned business unit

What they are looking for

Two to five years in information security, cyber GRC or a related control environment. Working knowledge of ISO 27001 and how an ISMS runs day to day. 

Beyond that it is about how you handle people. You need to be comfortable in front of senior stakeholders and able to translate security requirements into language a partner or an engagement lead will act on.

Professional services or another regulated, client facing background is useful. So is Cyber Essentials Plus exposure, or a certification held or in progress such as CISM, ISO 27001 Lead Implementer or Auditor.