Business Information Security Officer
UK (Reading)
⚠️ We'll shut down after Aug 1st - try foo🦍 for all jobs in tech ⚠️
Keyloop
As the largest global automotive technology solutions provider, we understand what it takes to thrive in the modern era.
Keyloop bridges the gap between dealers, manufacturers, technology suppliers and car buyers.We empower car dealers and manufacturers to fully embrace digital transformation. How? By creating innovative technology that makes selling cars better for our customers, and buying and owning cars better for theirs. We use cutting-edge technology to link our clients’ systems, departments and sites. We provide an open technology platform that’s shaping the industry for the future. We use data to help clients become more efficient, increase profitability and give more customers an amazing experience. Want to be part of it?
Reporting to the Senior Governance, Risk & Compliance Officer, the Information Security Officer will assist in strengthening the organisation’s security posture within a large, complex, and fast-paced environment. This role supports the development and implementation of GRC policies, risk management frameworks, and control processes to ensure the confidentiality, integrity, and availability of Keyloop’s information assets. The Information Security Officer will work cross-functionally with stakeholders across diverse teams and departments to embed strong information security practices throughout the business. The role also includes identifying and tracking risks within the supply chain and supporting the organisation’s broader information security governance, risk, and compliance efforts. A critical part of this role is helping to promote a strong risk-aware culture and embedding positive security behaviours across the organisation.
Keyloop doesn’t require academic qualifications for this position. We select based on experience and potential, not credentials.We are also an equal opportunity employer committed to building a diverse and inclusive workforce. We value diversity and encourage candidates of all backgrounds to apply.
Reporting to the Senior Governance, Risk & Compliance Officer, the Information Security Officer will assist in strengthening the organisation’s security posture within a large, complex, and fast-paced environment. This role supports the development and implementation of GRC policies, risk management frameworks, and control processes to ensure the confidentiality, integrity, and availability of Keyloop’s information assets. The Information Security Officer will work cross-functionally with stakeholders across diverse teams and departments to embed strong information security practices throughout the business. The role also includes identifying and tracking risks within the supply chain and supporting the organisation’s broader information security governance, risk, and compliance efforts. A critical part of this role is helping to promote a strong risk-aware culture and embedding positive security behaviours across the organisation.
Role & Responsibility :
- The job holder will be responsible for assisting and supporting in a range of activities across the Governance, Risk and Compliance function. The job holder will be responsible for the following activities: Governance
- Support the development, maintenance, and review of Information Security policies, standards, and associated processes.
- Monitor regulatory and industry developments to ensure evolving external requirements are reflected in internal practices.
- Attend and document meetings such as the Information Security Forum, ensuring actions and decisions are appropriately recorded and tracked.
- Collate, analyse, and visualise GRC-related data to support reporting on key metrics such as risk trends, policy compliance, control effectiveness, and audit findings, enabling informed decision-making by stakeholders and leadership.
- Contribute to the ongoing risk management process by identifying, assessing, and tracking information security risks, maintaining the Risk Register, and coordinating risk treatment plans with relevant risk owners.
- Conduct third-party risk assessments and due diligence during onboarding and at scheduled intervals to ensure vendor compliance with security requirements.
- Support internal and external audits, including evidence gathering, issue tracking, and remediation of findings or control gaps.
- Perform ongoing control assurance activities to validate the effectiveness of implemented security controls and identify areas for improvement.
- Manage and respond to governance and compliance queries and tickets from business units and technical teams.
- Respond to customer security questionnaires, RFPs, compliance assessments, and related documentation requests as needed, ensuring alignment with both internal standards and customer expectations.
- Promote adoption and compliance with Information Security policies, standards, and guidelines across the organisation and support stakeholder education and awareness initiatives.
- Collaborate with key business functions including HR, Procurement, Legal, IT, and Engineering to embed GRC requirements into core business processes.
- Foster a strong security culture across the organisation, helping to embed risk-aware behaviours and make information security integral to day-to-day operations.
Risk
Compliance
Collaboration & Culture
Expereince :
- Essential
- Prior experience in cybersecurity, risk management, compliance, or governance.
- Strong understanding of regulatory requirements, security frameworks, and standards such as ISO 27001, NIST CSF, CIS, and SOC 2.
- Hands-on experience with ISO 27001 implementation and audit readiness.
- Experience supporting SOC 2 readiness and evidence collection.
- Proficient with risk assessment methodologies and control frameworks to evaluate and mitigate risks, including third-party/vendor risk assessments.
- Experience supporting internal and external audits.
- Skilled in developing and maintaining security policies, processes, and controls.
- Relevant industry certifications such as Security+, ISO 27001 Lead Implementer, CRISC, or equivalent.
- Understanding of GDPR principles and their application to information security and data protection practices.
Desirable
Skills & Abilities:
- Excellent written and verbal communication skills, with the ability to engage effectively and adapt content for both technical and non-technical audiences.
- Strong analytical and problem-solving skills, with keen attention to detail and a methodical approach.
- Proficient in producing a wide range of business-relevant documentation, including processes, procedures and reports.
- Ability to prioritise and manage multiple tasks effectively in a fast-paced, dynamic environment.
- Strong collaboration skills with experience working across diverse teams and departments to achieve shared goals and drive effective governance, risk, and compliance outcomes.
- Strong organisational skills with the ability to track issues, audits, and remediation efforts to ensure timely resolution.
- Proactive mindset with the ability to anticipate potential risks and compliance challenges before they arise.
- Proficient in collating and visualising data to communicate GRC metrics, risk trends, and compliance status.
Keyloop doesn’t require academic qualifications for this position. We select based on experience and potential, not credentials.We are also an equal opportunity employer committed to building a diverse and inclusive workforce. We value diversity and encourage candidates of all backgrounds to apply.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
0
0
0
Categories:
Compliance Jobs
Leadership Jobs
Tags: Audits BISO Compliance CRISC GDPR Governance ISO 27001 NIST Risk assessment Risk management SOC SOC 2
Perks/benefits: Career development
Region:
Europe
Country:
United Kingdom
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Systems Administrator jobsSenior Security Analyst jobsIT Security Analyst jobsSenior Information Security Analyst jobsInformation System Security Officer jobsSenior Cloud Security Engineer jobsCyber Security Specialist jobsSecurity Operations Engineer jobsSenior Product Security Engineer jobsInformation Security Manager jobsInformation System Security Officer (ISSO) jobsSenior Information Security Engineer jobsSenior Network Security Engineer jobsSenior Cyber Security Engineer jobsSecurity Specialist jobsChief Information Security Officer jobsSecurity Consultant jobsInformation Systems Security Engineer jobsSenior Software Engineer jobsNetwork Engineer jobsIT Security Engineer jobsCyber Threat Intelligence Analyst jobsSecurity Operations Analyst jobsCybersecurity Specialist jobsSoftware Engineer jobs
Security assessment jobsEDR jobsBash jobsTS/SCI jobsEncryption jobsRMF jobsSDLC jobsIDS jobsSQL jobsThreat detection jobsSplunk jobsITIL jobsMalware jobsTerraform jobsCompTIA jobsIPS jobsFinance jobsTop Secret jobsOWASP jobsForensics jobsSOC 2 jobsDocker jobsActive Directory jobsGIAC jobsClearance Required jobs
CRISC jobsDoDD 8570 jobsOSCP jobsTCP/IP jobsMITRE ATT&CK jobsIntrusion detection jobsHIPAA jobsVPN jobsCCSP jobsZero Trust jobsDNS jobsSOAR jobsUNIX jobsJavaScript jobsAnsible jobsIT infrastructure jobsIndustrial jobsNIST 800-53 jobsData Analytics jobsJira jobsKPIs jobsSANS jobsBanking jobsSOX jobsGCIH jobs