Information Security Specialist positions focus on delivering results in their domain. This page aggregates open Information Security Specialist roles and what employers typically expect.
Location: - UK based - Willingness & flexibility to travel to UK locations, when required to support InfoSec work. (Kidlington & Exeter) - circa varies 1-3 days per quarter - Very Occasional travel to Dublin HQ (Glasnevin) as needed to support audit work Right to Work - We are unable to offer visa sponsorship for this role. Reporting & work team - You'll report to and work closely with the Information Security Lead, as well as Cybersecurity Engineering, DevOps, IT, Data Governance, and AI Governance to embed secure-by-design practices across the organisation. About this Role - Information security underpins all of our business activities, including AI development - and compliance with Medical Device regulations - This role is ideal for a hands-on security specialist who supports the ISMS, validates controls for themselves, and drives continuous improvement with energy and pragmatism. - This role moves away from traditional GRC and leans into modernising it - moving teams towards always-on compliance and consistently demonstrating business value in the activities we run. - You'll work across the business as someone who meets challenges head-on, brings people with them, and makes security work in practice, not just on paper. What This Is Not - Not a paper-only ISMS role or tick-box compliance exercise. The clear expectation here is you take hands-on ownership of effective controls, not just documentation. - Not a technical incident response role. Security operations is handled separately. - Not a bureaucratic or gatekeeping function. Our priority goal is to enable the business, not slow it down. - Not a role for someone who prefers to escalate as a first port of call. We value/ reward people who find the answer and move things forward. - Not a 'policing' role. We focus on shared responsibility and enabling teams to move fast safely. More specifically; - This role involves protecting systems and data that directly support cancer diagnostics and drug development, security work with real-world consequence. - This is a hands-on, delivery-focused role suited to someone who thrives in a very fast-moving environment. - Success requires a pragmatic approach, strong judgement, and the ability to navigate challenges, remove obstacles, and drive progress at pace. ISMS & Certifications - We hold ISO 27001 certification across our core business units and are expanding coverage as we grow. - Support the day-to-day running of the ISO 27001 ISMS across our [Deciphex](https://www.deciphex.com/about) business units (Deciphex, Diagnexia & Patholytix) - Prepare for internal and external audits so that teams are ready, controls are functioning, and evidence is complete. Audit readiness as a steady state. - Contribute to continuous improvement initiatives. Iidentify what needs to change, make the case, and see it through. - Proactively identify and close gaps in the control framework, driving corrective actions (CAPAs) to closure - Build and maintain a reliable evidence pipeline with clear ownership and high completeness. - Assess which ISMS activities deliver measurable business value - and be willing to challenge or retire processes that aren't. Security Governance & Risk - Maintain a live, decision-oriented risk register with owners and mitigation plans. - Champion a risk-aware culture where decisions are informed by risk, not paralysed by it. - Develop and maintain policies and procedures that reflect how the business actually operates (not a unworkable bottleneck) - Support vendor and customer security due diligence in support of commercial and product needs. - Contribute to tabletop exercises (e.g. incident response, business continuity) - Maintain awareness of applicable regulatory requirements (EU AI Act, GDPR, HIPAA, MDR/IVD) and ensure the ISMS remains aligned with our other Certifications and Standards Technical Oversight - Define evidence expectations for technical controls (SIEM, EDR, MFA, RBAC, vulnerability management). - Go and check…