Skip to main content
AfterDuty

Information Security Officer

ERGO UK Specialty Limited · London, Greater London

Type
Full-time
Posted
19 days ago

Overview

Your policing background gives you a strong foundation in incident response, investigation, and risk assessment, all of which are directly applicable to this information security role. You are used to following strict procedures, managing sensitive information, and reporting to senior stakeholders, which mirrors the governance and compliance demands of the position. While you may need to develop specific technical cyber knowledge, your experience in managing complex incidents and mitigating risks translates well into protecting information assets and supporting security frameworks.

About this role

Job Title: Information Security Officer

Department: Compliance

No Visa Sponsorship for this role

Role Purpose:*

We are looking for an Information Security Officer to support the ongoing development, implementation and maintenance of our information security strategy, policies, controls and risk management processes. The successful candidate will play a central role in protecting information assets, embedding security best practice and supporting compliance with regulatory, Group and business requirements.

Responsibility:*

  • Developing and maintaining information security policies, procedures, frameworks and controls.
  • Conducting information security risk assessments, identifying vulnerabilities and supporting proportionate mitigation plans.
  • Supporting incident response, investigation, reporting and follow-up activity for security incidents and breaches.
  • Working with IT, Legal, Compliance, Group and senior stakeholders to strengthen security governance and regulatory alignment.
  • Preparing clear reports, dashboards and updates for governance forums, senior management and executive stakeholders.
  • Delivering security awareness, training and incident response exercises to promote a strong security culture.
  • Supporting audits, third-party reviews and remediation activity linked to information security and IT risk.

What you will bring

  • You will bring strong knowledge of information security, cyber risk, governance, compliance and incident management.
  • You will be comfortable working across teams, translating technical risks into clear business recommendations, and supporting a regulated environment where integrity, diligence, customer outcomes and effective risk management are essential.

What we are looking for

  • Experience in information security, cyber security, IT risk or governance, risk and compliance.
  • Knowledge of security frameworks, policies, standards and regulatory expectations relevant to a regulated financial services or insurance environment.
  • Experience supporting risk assessments, incident response, audit activity and security reporting.
  • Strong stakeholder management, communication and advisory skills.
  • A proactive, analytical and collaborative approach, with strong attention to detail and a commitment to continuous improvement.

Key skills

  • Information security governance, risk and compliance management.
  • Cyber security risk assessment, vulnerability review and risk mitigation planning.
  • Development and maintenance of security policies, standards, procedures and controls.
  • Incident response coordination, investigation, reporting and lessons-learned activity.
  • Knowledge of regulatory requirements and security frameworks relevant to financial services or insurance.
  • Audit support, control monitoring, remediation tracking and management reporting.
  • Security awareness training, phishing simulation reporting and incident response exercises.
  • Stakeholder management, including engagement with IT, Legal, Compliance, Group teams and senior leadership.
  • Clear written and verbal communication, with the ability to translate technical risks into practical business recommendations.
  • Strong analytical thinking, attention to detail, prioritization and continuous improvement mindset.

Why ERGO?

ERGO UK Specialty is a well-established specialist insurer with a strong market reputation. We are focused on profitable, sustainable growth, operational excellence and delivering consistent value to clients and partners.

Equal opportunities

We are an equal opportunities employer and welcome applications from all suitably qualified candidates. We are committed to a fair, inclusive and accessible recruitment process.

If you’re ready to take on this role, we’d love to hear from you.*

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background — match score 75/100

  • Incident command & response
  • Investigative casework
  • Risk & threat assessment
  • Working to legislation & regulation

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Full-time

    Your investigative mindset and evidence-handling discipline from policing transfer directly to digital forensics and incident response.

    Posted Yesterday

  • Full-time

    £61,440 – £69,120Estimated

    Your risk assessment and analytical skills from policing transfer directly to cyber assurance.

    Posted 3 days ago

  • Director - Risk Management

    SHI International · London

    Full-time

    Your threat assessment and multi-agency command experience directly transfer to building enterprise risk frameworks and governance.

    Posted 3 days ago

  • GRC Manager - 6 month FTC

    Trayport · London

    Full-time

    Your experience managing risk, policy, and regulatory compliance under frameworks like PACE transfers directly to GRC.

    Posted 3 days ago