IT Security Lead
Listed on 2026-01-13
-
IT/Tech
Cybersecurity, Information Security, IT Consultant
Location: Greater London
IT Security Lead – 6 Month Contract
Location:
Mayfair – Hybrid
Type:
Permanent
Unity Advisory is a challenger advisory firm focused on AI-enabled, client-centric solutions. We operate a lean, conflict-free model that embeds AI across all work streams and prioritises agility and outcome‑based commercial models. Our culture is collaborative, flat‑structured, and free of traditional partner P&L silos.
Role SummaryThe Security Lead will strengthen Unity Advisory’s security posture by bridging technical, governance, and operational domains. Acting as the primary liaison with our Managed SOC provider, the lead will drive Cyber Essentials certification and ISO 27001 alignment, embed sustainable security practices, and build organisational readiness for formal audit and certification.
Responsibilities- Develop and roll out a security governance framework aligned with ISO 27001 controls and Cyber Essentials requirements.
- Conduct gap analyses and implement corrective action plans to achieve compliance milestones.
- Draft and maintain security policies, standards, and procedures.
- Act as the central point of contact with the Managed Security Operations Centre (SOC), ensuring effective triage, response, and reporting of security incidents.
- Oversee configuration and optimisation of SIEM/SOAR tools to ensure actionable alerting.
- Run periodic tabletop exercises and incident simulations to validate response capability.
- Ensure vulnerability management activities are carried out in conjunction with the wider team and managed services function.
- Coordinate the technical and procedural controls required to meet Cyber Essentials Plus certification.
- Liaise with external assessors, IT operations, and third‑party providers to ensure readiness for audit.
- Build an Information Security Management System (ISMS) tailored to Unity Advisory’s business model.
- Map existing processes and documentation to ISO 27001 Annex A controls.
- Prepare the organisation for internal and external audits, including documentation, risk treatment plans, and asset registers.
- Conduct and maintain an enterprise‑wide information security risk register.
- Support Data Protection Impact Assessments (DPIAs) and privacy alignment activities in collaboration with the CPO.
- Support contractual security clauses and third‑party vendor due diligence.
- Deliver a targeted security awareness programme, including phishing simulations, staff training, and policy communications.
- Foster a culture of shared security responsibility across departments.
- Strong knowledge of information security frameworks including ISO 27001, Cyber Essentials, NIST CSF, and CIS Controls.
- Experience liaising with SOCs, managing SIEM/SOAR tools, and handling incident response workflows.
- Proven experience leading security maturity assessments and implementing ISO 27001‑aligned controls.
- Understanding of risk‑based security management, policy design, and compliance reporting.
- Excellent communication and stakeholder management skills – able to engage both technical and non‑technical audiences.
- Experience in cloud and SaaS security, ideally within Microsoft 365 and Azure environments.
- Familiarity with third‑party risk management and contract security provisions.
- Desirable: experience with ISO 42001 (AI Management) or emerging AI governance frameworks.
- Security certifications preferred (e.g., CISSP, CISM, ISO 27001 Lead Implementer, CompTIA Security+).
We offer a truly hybrid and flexible working environment and the opportunity to be at the forefront of AI‑driven advisory services. You’ll be part of a highly collaborative, flat‑structured culture, empowered to shape the way we scale our business and support our clients.
Additional InformationUnity Advisory is committed to an inclusive and accessible recruitment process. In line with the Equality Act 2010, we will accommodate any suitable candidate requiring assistance to attend or conduct an interview. If you need adjustments or support, please let us know when scheduling your interview or in your application cover letter. We are dedicated to ensuring everyone has an equal opportunity to succeed.
PLEASE NOTE:
We do not accept unsolicited CVs from third‑party agencies.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: