- Company Name
- Bouygues Travaux Publics
- Job Title
- Information Security Officer
- Job Description
-
**Job Title**
Information Security Officer
**Role Summary**
Act as deputy to the Information Security Manager and primary cyber‑security lead for a large national infrastructure project. Responsibilities include governance, risk management, incident response, security controls implementation, and stakeholder engagement for data protection and cyber‑security standards (ISO 27001, UK GDPR, Cyber Essentials, PAS 1192:2).
**Expectations**
- Current security clearance
- Degree in Computer Science, Cyber Security or equivalent practical experience
- In‑depth knowledge of ISO 27001 controls, UK GDPR, SANS 20, and Cyber Essentials
- Proven experience with SIEM, logging, penetration testing, and vulnerability assessment
- Strong communication, negotiation, and stakeholder management skills
- Self‑driven, prioritising tasks, and delivering risk‑based outcomes
**Key Responsibilities**
- Deputise for the Information Security Manager and serve on the Information Security & Cyber Security Steering Team.
- Act as the main point of contact for all information and cyber‑security matters within the Alliance.
- Perform Data Protection Officer duties: support Data Protection Impact Assessments and maintain GDPR compliance.
- Evaluate, enhance, and secure Alliance and Partner IT systems from a security and GDPR perspective.
- Develop and maintain the Alliance Security Posture, security principles and standards.
- Coordinate, monitor, and enforce cyber security controls across the organisation.
- Conduct and interpret penetration tests, leading remediation of findings.
- Lead vulnerability assessments and close or mitigate identified risks.
- Facilitate regular stakeholder meetings to discuss incidents, risks, and regulatory changes.
- Design and deliver cyber‑security training and awareness programmes.
- Feed risk information into the alliance risk register for proactive risk management.
**Required Skills**
- Security information and event management (SIEM)
- Log management and analysis
- Penetration testing and vulnerability identification
- Incident response and threat intelligence
- Project and programme management
- Negotiation, influence, and stakeholder communication
- Report writing and technical documentation
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Cyber Security, Information Technology, or equivalent experience.
- Relevant certifications: ISO 27001 Lead Implementer/Lead Auditor, CISSP, CISM, CEH, CompTIA Security+ (preferred).
---