Skip to main content
AfterDuty

Information Security Specialist

Clyde & Co · Glasgow, Scotland

Type
Full-time
Posted
8 days ago

Overview

Department: Information Security Role: Information Security Specialist Key Responsibilities Training, Awareness & Human Risk The chosen candidate will be accountable for the successful delivery and continuous improvement of Clyde & Co's security awareness programme, owning the relationship with…

About this role

Department: Information Security

Role: Information Security Specialist

Key Responsibilities

Training, Awareness & Human Risk

The chosen candidate will be accountable for the successful delivery and continuous improvement of Clyde & Co's security awareness programme, owning the relationship with training providers, developing engaging content and partnering with stakeholders across the firm to drive behavioural change and strengthen the firm's security culture

  • Lead the design, implementation and continuous improvement of the firm’s security awareness and human-risk management programme ensuring all content remains relevant, engaging, and aligned with emerging cyber threats, industry best practices, and firm-specific risks. The chosen candidate will:
  • Manage enterprise phishing simulation campaigns, awareness training initiatives and behavioural change activities to improve security culture and reduce cyber risk.
  • Coordinate the delivery of annual security campaigns including Cyber Security Awareness Month (CSAM), mandatory training activities and targeted awareness initiatives.
  • Monitor emerging threats, industry practices and security awareness trends, recommending improvements to strengthen organisational resilience and human-risk management capabilities.
  • Maintain and manage initiative plans, milestones, dependencies and reporting for assigned security improvement programmes.
  • Own and maintain strong a productive relationship with external vendors to ensure the quality, effectiveness and continuous improvement of awareness and training services.
  • Monitor vendor performance against agreed service levels, success metrics, and contractual commitments, driving improvements where required.
  • Produce tailored management reports, dashboards and presentations for senior leaders, providing meaningful insights into programme performance, compliance levels, user behaviour and areas of risk.
  • Partner with senior stakeholders to increase engagement, improve training completion rates and promote a strong security culture throughout the firm.
  • Present findings, recommendations, and programme updates to management in a clear, concise and business-focused manner.

Supply Chain Risk and Supplier Assurance

Responsibilities

The chosen candidate will be responsible for maintaining effective oversight of Clyde & Co's third-party security risk exposure, providing proactive insight into emerging supply chain threats and vulnerabilities and ensuring the firm's supplier assurance processes remain current, risk-based and aligned to the firm’s IT&O Risk Management Framework. The role acts as a key advisor to the business, helping stakeholders understand and manage risks arising from the firm's external supplier ecosystem. The candidate will:

  • Maintain, execute and enhance third-party and supply chain security risk management processes including tiering of suppliers by risk, periodic and ad hoc third-party information security assessments (TPISA) and ongoing assurance activities.
  • Design and operate supplier security assessment mechanisms, including contractual security schedules, supplier risk questionnaires, attestations and contract review processes.
  • Manage information security within the supplier relationship throughout the lifecycle, ensuring that supply chain risks, control deficiencies and remediation actions are identified, tracked and addressed in a timely manner.
  • Collaborate with Information Security, IT, Procurement, Risk Management, Legal and business stakeholders to ensure security requirements are integrated into operational processes and supplier engagements.
  • Monitor, analyse, and assess emerging supply chain security threats, industry trends, regulatory developments, geopolitical risks, and third-party security incidents to identify risks that may impact Clyde & Co's supply chain.
  • Develop and maintain a comprehensive understanding of Clyde & Co's supplier estate, identifying areas of concentration risk, systemic risk, fourth-party dependencies, and critical supplier exposures.
  • Continuously evaluate and improve third-party risk management processes, methodologies, assessment frameworks, and assurance activities to ensure they remain effective, proportionate, and aligned to the firm's risk appetite and evolving threat landscape.
  • Establish and maintain meaningful assurance activities over key(critical) suppliers through the review of independent audits, certifications, penetration test summaries, security attestations, performance metrics, and other relevant evidence.

Email DLP and Information Protection

To Continuously Enhance Clyde & Co's Email DLP And Information Protection Capabilities, Ensuring The Firm's Confidential, Sensitive, And Client Information Is Protected Through Effective Preventative, Detective, And Responsive Controls While Enabling Secure Business Operations And Collaboration. The Candidate Will

  • In conjunction with the Risk department, continue the development and enhancement of email DLP capabilities and the associated rulesets to help reduce the risk of unauthorised disclosure or loss or misuse of firm and client information.
  • Work with the Risk department, IT, InfoSec and other business stakeholders to assess data protection risks and define appropriate email DLP policies, effective alerting and monitoring and control requirements.
  • Support the review, tuning and improvement of DLP alerts, policies and control effectiveness, ensuring that DLP capabilities remain proportionate, risk-based and aligned with business operations.
  • Track DLP issues, exceptions, policy impacts and improvement actions, escalating material risks or control decisions through the appropriate governance channels.

Supplier Relationship Management

  • Conduct periodic service and security review meetings with strategic suppliers to keep abreast of new developments and updates, assess performance against agreed requirements, contractual obligations and risk tolerances.

Internal Audit

  • Support the successful renewal and ongoing maintenance of Clyde & Co's Cyber Essentials, Cyber Essentials Plus, and ISO 27001 certifications by coordinating evidence collection, tracking remediation activities, engaging stakeholders and assisting with audit requirements.

Reporting, Governance and Continual Improvement

  • Facilitate/establish and report on monthly metrics and Key Performance/Risk Indicators relating to third party/supply chain risk, human-risk, training/awareness and DLP.
  • Produce management reporting, metrics and risk insights to demonstrate programme effectiveness and support governance decision-making.
  • Facilitate continual improvement by investigating and utilising latest technologies such as Artificial Intelligence/Machine Learning and other process methodologies to help transform the delivery of the services with a focus on greater efficiency and accuracy.
  • Stay abreast of technical, industry, regulatory and company changes and/or trends as they relate to cyber security, the legal industry, information management, InfoSec, technological standards/trends and IT efficiencies.

Stakeholder Engagement and Team Contribution

  • Support security-related market assessments, supplier evaluations, proof-of-value activities, and procurement processes by providing subject matter expertise, requirements gathering, user feedback, and evaluation criteria where required.
  • Contribute to the development of business cases, executive recommendations and decision-support materials for security improvement initiatives.
  • Analyse insights and trends from security awareness activities, phishing simulations, user feedback, and third-party risk assessments, translating findings into actionable recommendations to improve security controls, processes and user behaviours.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Glasgow

Why this fits a police background — match score 90/100

  • Evidence & case files
  • Investigative casework
  • Risk & threat assessment
  • Working to legislation & regulation

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • £53,850 – £56,850Estimated

    Your risk assessment and threat management experience from policing applies directly to cyber security risk management.

    Posted 18 days ago

  • Security Analyst - Risk

    student · Glasgow

    Full-time

    £38,314 – £45,176Estimated

    Your threat assessment and multi-agency coordination experience from policing directly enables this risk analysis role.

    Posted 22 days ago

  • Information Security Officer

    Police Scotland · Glasgow

    Contract

    Police Scotland is seeking an experienced Information Security professional to join our Information Security and Records Management team with a specialist focus on Data Loss Prevention (DLP).x This is an exciting opportunity for an individual with strong Information Security, Governance, Risk and…

    Posted 30 days ago

  • Full-time

    Your digital forensics and evidence-handling discipline from policing maps directly onto this insider risk investigation role.

    Posted 36 days ago