Security Assurance Officer

Company: The University of Sheffield
Apply for the Security Assurance Officer
Location: Sheffield
Job Description:

The University of Sheffield is a remarkable place to work, where people from diverse backgrounds and beliefs collaborate to create a world‑class learning environment.

Benefits include competitive annual leave entitlement, a generous pension scheme, flexible working, and development support.

Overview

The Information Security team in IT Services is looking for a Security Assurance Officer in the Security Operations team to support the University’s mission to keep its assets safe and secure.

Main Duties and Responsibilities

  • Support the Information Security Team by reporting on security risk and compliance metrics and delivering improvements.
  • Lead information security projects to produce technical and cultural changes to University assets and processes.
  • Perform high‑ and low‑level information security risk assessments.
  • Develop and implement new information security processes, procedures and practices.
  • Track, monitor and improve information security controls across various faculties, departments and research groups.
  • Manage and lead assurance activities for standards such as Cyber Essentials, PCI‑DSS, NHS DSPT, ONS SRS AOC and GDPR.
  • Provide support to manage risks, feeding into departmental and corporate risk registers.
  • Respond to enquiries and give expert guidance to all University staff.
  • Recommend information security decisions to ensure the infrastructure supports security goals.
  • Promote security awareness and skills, delivering tailored training when necessary.
  • Collaborate with IT security, data protection and research data management teams.
  • Keep up to date with published standards, legislation and guidelines.
  • Perform any other duties commensurate with the post.

Person Specification

We are a diverse community that values the uniqueness of each individual. Even if your past experience does not perfectly match the role, your contribution is valuable. Please reference the application criteria in your statement.

Essential Criteria

  • Previous relevant experience in information security.
  • Solid understanding of information security principles, techniques and compliance standards.
  • Ability to work at speed, to a high standard and to meet deadlines.
  • Ability to manage multiple supplier relationships and operate in a diverse technology environment.
  • Professional, self‑confident, organised approach and commitment to professional development.
  • Excellent written and verbal communication skills.
  • Experience with ISO/IEC 27001, PCI‑DSS, GDPR/DPA 2018 compliance.

Desirable Criteria

  • Experience collaborating with others to deliver information security value.
  • Experience delivering specialist training.
  • Relevant information security qualifications (e.g., CISSP, CompTIA Sec+, ISO 27001 Lead Implementer, PCI‑DSS ISA).
  • Knowledge of information management principles and related systems.

Further Information

  • Grade: 7
  • Line manager: Security Assurance Manager
  • Direct reports: None
  • Contact: Matt Doxey, Security Assurance Manager – m.doxey@sheffield.ac.uk

Benefits

  • Minimum 41 days annual leave (pro‑rata) with option to purchase more.
  • Flexible working including hybrid options.
  • Generous pension scheme.
  • Retail and lifestyle discounts.

Equal Opportunity & EEO

We are a Disability Confident Employer. If you have a disability and meet the essential criteria, you will be invited to the next stage of the selection process.

Criminal Record

BPSS clearance will be required. You will be assessed on your criminal record as part of the recruitment process.

#J-18808-Ljbffr…

Posted: May 22nd, 2026