Buckinghamshire New University
Information Security Officer

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Full Time (37 hours per week) - Permanent - High Wycombe Campus / Hybrid working
Salary - £38,784 - £43,482
We’re not trying to fit in with the higher education status quo. We’re challenging it. We’re doing things differently - because our students, our staff, and our world need us to.
So this is an exciting moment to join us. We’re boldly reimagining what a university can be: a place rooted in social mobility, a community where difference is celebrated, and an institution that empowers people to become more than they thought possible.
Buckinghamshire New University is seeking a proactive and ambitious Information Security Officer to help shape and strengthen our information security and compliance programme. Working within the Information Assurance team, you will play a key role in protecting the University's information assets, managing security risks, and embedding a strong security culture across the organisation.
You will lead the continual improvement of our Information Security Management System (ISMS), support the management of security incidents, drive compliance activities, and develop information security policies, standards and controls. You will also contribute to strategic projects, maintain oversight of information security risks and assets, and provide expert advice to colleagues to ensure security is embedded in decision-making and service delivery.
This is an opportunity to make a meaningful impact in a university committed to transforming lives through education. We welcome applications from all backgrounds and are committed to an inclusive and supportive workplace.
What We Offer
- A generous holiday entitlement (35/30 days per annum, plus bank holidays & closure days)
- Hybrid working (dependent on business needs)
- Training & development support opportunities
- Contributory pension scheme
- Free gym membership for our on-site gym
- A range of staff discounts with major retailers.
Please click here to see our wide range of benefits available for employees.
Please click here for our behavioural based interview question bank.
Please click here to view our employee handbook.
If you have the qualities and attributes representative of the University’s values and ambition, we would be delighted to hear from you.
For further information about this role please contact jenny.horwood@bnu.ac.uk
All applications are to be made in full and online
We are committed to promoting an inclusive and diverse workplace and aim to continue building an environment where everyone thrives and can be themselves.
Please let us know if you require any adjustments or support during the recruitment process. We are happy to discuss any reasonable adjustments that would enable you to perform to the best of your abilities in your role. Please reach out to people@bnu.ac.uk if you have any specific needs or if you would like more information on how we can support you
We ensure that our interview/shortlisting Chairs complete the relevant e-learning and/or inclusive recruitment training.
If you’re considering using AI to support your application, we encourage you to question the value it adds. The use of AI tools sometimes erodes authenticity and prevents us from being able to assess the real you. We strongly recommend you prepare your application using your own skills and knowledge and that AI is only used for the purpose of review.
Closing Date: Friday 02 October 2026
Interview Date: Monday 12 October 2026
If you are invited to interview for this role, you will need to provide evidence of your eligibility to work in the UK and if on a visa, current visa and status. Sponsorship is dependent on the salary level of the position.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
BNU is a Disability Confident employer and as such you will be given the opportunity to declare a disability as part of the application process.
Job Title: Information Security Officer
Faculty/Directorate: CIO Group
Grade: G
Location: High Wycombe
Hours: 37
Responsible to: Head of Information Assurance
Responsible for: Information Assurance and Security Analyst
Job Purpose
To maintain a good understanding of cyber security technologies, IT security operations and cyber security controls to improve the University's cyber security posture and drive key information security initiatives.
To have a broad understanding of information security and cyber security frameworks, standards and policies to help build and deliver the University’s information and cyber security strategies.
Undertake a range of audit and assurance activities including technology management; policy development and documentation; testing, monitoring and management of security controls; risk evaluation of threat information; consultative engagements; project-work; and reporting.
Main Duties & Responsibilities Of The Role
- Provide governance and assurance to the wider CIO Group and University by supporting the Head of Information Assurance in developing, delivering and auditing against the information governance framework.
- Work closely with the Infrastructure and Operations Teams to review the existing global architecture (including infrastructure and cloud services), identify design gaps, and recommend enhancements to cyber security controls and implement any agreed improvements so that the University’s data and information systems are secured.
- Serve as an internal information and cyber security subject matter expert and lead operational security activities including security monitoring, threat detection, security event management, endpoint security, identity security and oversight of managed security service providers.
- Develop, validate, maintain and regularly test all information security, cyber security, disaster recovery and business continuity plans, process and procedures.
- In collaboration with the CIO assist with the design and development of the cyber security strategy and recommendations for new cybersecurity systems.
- Work with the wider CIO Group to execute regular vulnerability assessments and coordinate external penetration testing to identify data protection, cyber security and other compliance risks and present recommendations for mitigating the risks in the immediate term and provide guidance on plans to manage the risk long term.
- Maintain the University's information security risk register, ensuring risks are assessed, tracked, reviewed and reported to appropriate governance forums. Assist departments with risk assessments and developing appropriate management and mitigation strategies to avoid reputational and financial damage to the University.
- Lead all investigations related to security incidents, including analysis of impact, resolution, cause, prevention and subsequent remediation as required by the University’s Incident Response procedures. This includes ensuring there is adequate out of hours and emergency incident response cover.
- Develop and monitor security KPIs to assess the effectiveness of controls and present regular security reporting, risk assessments and assurance updates to leadership, governance committees and external auditors.
- Take advice from our third-party security partners and maintain a high level of knowledge about information, cyber security and privacy regulations, new security risks and protocols, and new security technology solutions.
- Assist in the development, review, and consultation of information and cyber security policies, standards, and guidelines in line with industry best practices and the University's needs, ensuring that compliance is enforced through the satisfactory completion of regular internal and external audits.
- Support the development and maintenance of the University’s ISMS, ensuring compliance with legislation e.g. Data Protection Act 2018 and UK GDPR; standards, such as ISO 27001, ISO 22301 and PCI-DSS; and frameworks including Cyber Essentials.
- Help create a positive security culture across the University through engagement activities, awareness campaigns, training and leadership engagement by promoting the University’s information and cyber security policies and procedures to all staff and serving as the primary point of contact for associated issues across the institution.
- Deliver the University's information security awareness programme to promote awareness of the processes, policies and technical solutions in place to protect the confidentiality, integrity and availability of data by maintaining training materials, promoting participation, and monitoring its effectiveness.
- Perform line management responsibilities including recruitment and selection, performance management, professional development, motivation, health and safety, and wellbeing.
- Comply with relevant legislative and other requirements (e.g., the Data Protection Act 2018 and UK GDPR; Health and Safety; UKVI; and Equality and Diversity) in all working practices
- Perform such other duties temporarily or on a continuing basis, as may reasonably be required.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
PERSON SPECIFICATION
A = Application | T = Test | I = Interview
Education, Qualifications & Training
Means of Testing
- Professionally qualified with a relevant degree/postgraduate qualification or relevant vocational, strategic management and leadership experience | A
- Relevant information security qualification (or working towards) such as CISSP or CISM, or Security+ | A
Knowledge & Experience
- Knowledge of regulatory and statutory compliance requirements e.g. Data Protection Act 2018, UK GDPR, PCI-DSS | A/I
- Experience with security certifications and audits e.g. ISO 27001 and Cyber Essentials or similar information security standards | A/I
- Previous experience in a role that includes an element of detecting and responding to security incidents and the collection and use of threat intelligence ideally within exposure to Higher Education or Public Sector environments | A/I
- Demonstrable knowledge and experience of information risk management and information assurance | A
- Experience writing formal reports including audit and compliance review findings on data and information systems | A/I
- Good underlying knowledge of Microsoft security tools and platforms as evidenced by technical or professional qualifications and work experience | A/I
Skills
- Powers of influence and negotiation to secure the prioritisation of resources and workload from other areas of the University | I
- Ability to plan, prioritise and organise own work and resources and leading / guiding others, whilst anticipating problems and planning workable solutions | I
- Communication, persuasion and presentation skills to motivate an organisation to change its culture and to lead people change projects | I
- Ability to explain complex technical information to non-technical audiences and convey complex information in clear ways to a range of audiences | I
Special Requirements
- As cyber threats occur at any time, this
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills