We are currently recruiting for an experienced Information Security Coordinator to join our Compliance Team.
The Information Security Coordinator will assist in driving the continual improvement, testing, implementation and monitoring of security measures within an established ISO 27001 ISMS. The role focuses on security risk management, governance, compliance and incident response planning, ensuring Eploy maintains a strong security posture.
This position is not a technical IT role but requires an understanding of technical security controls across networks, endpoints, cloud and applications.
Key Responsibilities:
Information Security
- As part of the ISMS Team, ensure alignment with ISO 27001, Cyber Essentials, and other industry standards such as NIST and NCSC.
- Help conduct risk assessments, define controls, and monitor performance against security KPIs.
- Help maintain the Eploy Trust Centre.
- Draft, update, and implement security policies, procedures, and work instructions.
- Help support security governance, assurance activities, internal audits, and security testing.
- Deliver security awareness training and develop educational content.
- Assist in third-party security assurance processes.
- Coordinate vulnerability and penetration testing, risk analyses, and security assessments.
- Conduct security audits to evaluate operational security.
- As part of the Infosec Team respond to security incidents, perform post-incident analysis, and identify root causes.
- Research and recommend security upgrades to enhance protection.
- Act as a point of contact for security-related inquiries from third parties, prospects, and customers.
- Work with sales, compliance, and technical teams to address customer security concerns.
- Help conduct vendor security assessments to ensure third-party compliance with security requirements.
Data Protection
- Assist team members with GDPR compliance obligations.
- Support the DPO in monitoring compliance with GDPR and data protection policies.
- Raise awareness of data protection issues and deliver training.
- Assist in conducting and monitoring Data Protection Impact Assessments (DPIAs).