We work with some of the UKβs biggest companies and government departments to provide a pragmatic approach to technology, delivering bespoke software solutions and expert advice.Β
An Information Security Engineer works as part of the IT Department and focuses on introducing and improving the processes, tools, and policies necessary to prevent, detect, document, and counter threats to Scott Logic. The role carries defined responsibilities within the Service Management System (SMS) under ISO/IEC 20000-1:2018 and contributes directly to the Information Security Management System (ISMS) under ISO/IEC 27001:2022.
Impact of this Role:
Prevents information security threats to Scott Logic and ensures the secure, compliant delivery of IT services to all staff across three companies.
Scope of this Role:
Supporting the internal IT function across Scott Logic Ltd., Marra Ltd., and Logical Holdings Ltd., with occasional support to client projects as required.
Key Responsibilities:
Service Management (SMS):
β’ Deliver IT services within the SMS scope in accordance with ISO/IEC 20000-1:2018.
β’ Execute SMS processes including incident management, service request management, problem management, change management, release and deployment management, and configuration management.
β’ Maintain accurate configuration and asset records.
β’ Triage, prioritise, and handle security events and service tickets to agreed SLAs.
β’ Keep customers and stakeholders updated with accurate and timely ticket updates.
Govern and Protect:
β’ Monitor and respond to security events across Scott Logic.
β’ Understand regulatory obligations to protect confidential data and maintain appropriate controls.
β’ Maintain and communicate minimum security configuration standards for managed operating systems.
β’ Analyse and determine root causes of security incidents and breaches.
β’ Assist with information security training and awareness.
β’ Support risk-based threat and vulnerability assessment processes.
β’ Follow data governance policies and processes.
β’ Manage access control policies and processes, including entitlement reviews.
Provide Support:
β’ Respond to security incidents effectively, maintaining clear communication with key stakeholders throughout resolution.
β’ Build and maintain a knowledge base to improve resolution times.
β’ Maintain effective working relationships with internal teams and third parties to resolve, minimise, and avoid issues.
Lead and Coordinate:
β’ Champion information security policy, standards, and awareness throughout Scott Logic.
β’ Drive improvements to the IT team's ways of working and evolve information security processes to deliver better outcomes.
Continual Improvement:
β’ Actively contribute to the continual improvement of the SMS and the services it governs, in line with SMS Clause 10: Continual Improvement.
β’ Identify and recommend process and procedural improvements.
β’ Participate in management reviews and retrospectives.
Educational Qualifications β Essential:
β’ A relevant technical or information security qualification is essential (e.g. CompTIA Security+, SC-900, or equivalent).
Experience, Knowledge & Expertise -Essential:
β’ Commercial experience in an information security role.
β’ Risk management experience, including performing assessments and designing controls.
β’ Experience with the Data Protection Act and UK GDPR.
β’ Experience designing and implementing information security controls in cloud environments.
β’ Experience with Microsoft Defender and Sentinel.
Experience, Knowledge & Expertise β Desirable:
β’ Good understanding of cybersecurity standards and frameworks such as ISO/IEC 27001:2022, CIS, OWASP, and NIST.
β’ Good understanding of ISO/IEC 20000-1:2018 (SMS).
β’ Good understanding of ISO 9001:2015 (QMS).
β’ Good understanding of ITIL principles.
Role Specific Skills and Competencies (Technical and People Skills):
β’ Excellent communication skills; able to remain calm under pressure and manage difficult situations with stakeholders.
β’ Flexibility and ability to adapt to changing environments and new challenges.
β’ Detail-oriented with a systematic approach to identifying risks and devising mitigations.
β’ An inquisitive approach to investigating root causes of security incidents.
β’ Drive for personal growth and ongoing professional development.
In return youβll receive:
β’ 25 daysβ annual leave, rising to 30 days with each year of service.
β’ Generous family leave policies.
β’ Access to an employer pension scheme, private medical services and Group Life Assurance.
β’ A range of optional benefits such as discounted gym membership and a cycle to-work scheme.
β’ A meaningful approach to evaluating your performance and providing feedback on your progress
At Scott Logic, we value the flexibility of remote working alongside the value gained from spending time with our colleagues and clients. In our offices youβll find employee led clubs and events, as well as free games, books, and refreshments. We have shared values that govern our behaviour toward others and the environment.Β
We are proud to be a B Corp, a global movement of businesses driving for a more inclusive, equitable, and regenerative economy. We believe diversity drives innovation, and embrace a culture where everyone can contribute, irrespective of race, religion, colour, national origin, gender, sexual orientation, age, marital status or disability.