OB Collective
Information Security Consultant

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Job Title: Information Security & Governance Lead
OB Collective is a UK technology business working on independent verification, data integrity, and evidence for information moving between organisations and systems. We work primarily across government and regulated environments, combining software engineering, architecture, and assurance to help organisations understand and control information before it is relied upon.
We are looking for an experienced Information Security & Governance Lead to join an initial five-month technical programme focused on secure data integration across UK policing environments.
The programme will explore how authorised operational information can be exposed and exchanged consistently between organisations while source systems remain under local control. The work includes identity and access, policy enforcement, data provenance, local and national service boundaries, integration resilience, and the controls needed to move from Alpha into future operational use.
You will work alongside solution architects, software engineers, data specialists, and policing stakeholders. Your role is to make sure security and information-governance requirements are designed into the technical architecture rather than applied retrospectively.
The role is UK-based, outside IR35, and primarily remote, with occasional travel for force workshops, architecture sessions, and project reviews.
Current SC and NPPV3 are required.
Responsibilities
- Own the security and information-governance workstream across the programme.
- Develop and maintain the threat model and security architecture.
- Translate policing information-governance requirements into practical technical controls.
- Advise on authentication, authorisation, policy enforcement, and identity-context propagation.
- Define security requirements for local data integration services, APIs, and service-to-service communication.
- Support DPIA, information-governance, and data-processing assessments.
- Assess controls around OFFICIAL and OFFICIAL-SENSITIVE policing information.
- Work with technical leads on encryption, secrets, credentials, audit, logging, and evidence handling.
- Define how policy decisions and access decisions should be recorded and reconstructed.
- Assess data-retention, deletion, freshness, and local-replication implications.
- Support Security Aspects Letter interpretation and any associated security actions.
- Review risks around privileged access, malicious or malformed data, replay, source-system overload, and configuration change.
- Ensure security considerations are reflected in test scenarios and acceptance criteria.
- Define security and accreditation actions that would need to be completed during a subsequent Beta or production phase.
- Work directly with police-force security, information-assurance, and information-governance stakeholders where required.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Experience we need
- Significant experience in security architecture, information assurance, or information governance within UK government or policing.
- Current SC and NPPV3 clearance.
- Strong understanding of policing or law-enforcement data handling.
- Experience designing security controls around APIs, distributed systems, or data-integration platforms.
- Practical understanding of authentication, authorisation, role/policy-based access, and identity federation.
- Experience with threat modelling and security risk assessment.
- Experience working with UK GDPR, Data Protection Act requirements, and law-enforcement processing.
- Comfortable working with architects and engineers to turn policy requirements into implementable controls.
- Experience producing clear security or information-governance evidence for programme decision-making.
- Able to distinguish Alpha assurance from production accreditation and identify what needs to be proven at each stage.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Useful experience
- Home Office, police-force, NPCC, or wider criminal-justice programmes.
- MoPI or operational policing information management.
- Security Aspects Letters and government security classifications.
- DPIAs and policing information-governance assessments.
- Microsoft Entra ID, OAuth 2.0, OpenID Connect, or comparable identity platforms.
- NIAM or other government identity/access-management approaches.
- Federated or distributed data architectures.
- Data provenance, auditability, or evidential systems.
- Azure, Kubernetes, and API-management environments.
- NCSC guidance, secure development practices, or DevSecOps.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location