Information Security & Risk Specialist (12-month FTC)

Posted 19 Days Ago
Be an Early Applicant
Shoreditch, Somerset, England, GBR
Hybrid
50K-50K Annually
Mid level
Healthtech • Software
The Role
Manage and maintain the security risk register, lead risk assessment sessions, drive Cyber Essentials Plus audit readiness, deliver data classification and access control workstreams, track risk treatment actions, and support ISO 27001/DSPT evidence collection and security policy documentation.
Summary Generated by Built In
💬 Accurx is solving healthcare productivity for the NHS.

For decades, the NHS has struggled with fragmented systems that make simple tasks feel impossible. At Accurx, we’re changing that by building a single, system-wide platform that helps every patient get gold-standard, efficient, and joined-up care.

What started as a way for GPs to text a patient has now evolved into an all-in-one digital toolkit used by 98% of GP practices.

Our platform now powers Total Triage to manage patient demand, and Self-Book, which lets patients schedule their own appointments in seconds. We’ve automated routine care with Patient Questionnaires for long-term conditions, while Accumail finally allows staff-to-staff communication to happen instantly across different care settings. We’re now pushing the boundaries of the consultation itself with Accurx Scribe, our AI-powered note-taker that drafts medical notes in real-time.

We’re not just shipping features. We’re giving clinicians their time back and ensuring every patient journey is as smooth as it should be.


How this role sits within the function
  • Reports to: Senior Information Security Officer

  • Function: Privacy & Information Security

  • Contract type: Twelve-month fixed-term contract

This role works day-to-day alongside the Senior Information Security Officer, who owns the GRC framework, ISO 27001 programme, CE+ and DSPT compliance, and the security risk register. It provides dedicated capacity to push forward priority workstreams - particularly risk management, CE+ audit readiness, and data strategy delivery.

Challenges you’ll solve...
  • Own the security risk register: Facilitate risk assessment sessions with technical and non-technical stakeholders across the business, keep the register current and accurate, and prepare clear risk reporting that translates technical risk into business language.

  • Drive Cyber Essentials Plus readiness: Coordinate evidence gathering across IT, Platform and Security Engineering ahead of the CE+ deep-dive audit, reviewing controls against requirements and flagging gaps with practical remediation guidance.

  • Deliver our data classification programme: Work with data owners to classify information assets in line with policy, and push the access control programme forward by reviewing current access patterns and identifying gaps.

  • Keep risk treatment moving: Track risk treatment actions and follow up with owners so items progress rather than stall, managing milestones and blockers across the risk, CE+, and data workstreams.

  • Support the wider security programme: Contribute to ISO 27001 and DSPT activities where your work intersects, including evidence collection and control documentation, and support policy and process documentation as needed.

  • Be a translator between security and the business: Communicate security requirements clearly to engineers, and help non-technical stakeholders understand risk well enough to act on it.

You should apply if...
  • You have 3–5 years of hands-on experience in information security and risk management, ideally in health-tech or a regulated SaaS environment.

  • You've run risk sessions, owned a risk register, and prepared risk reporting for senior stakeholders

  • You've worked through a Cyber Essentials Plus audit cycle yourself

  • You understand cloud infrastructure, endpoint management, identity and access controls, and network boundaries well enough to hold your own in a technical conversation - you don't need to be a developer.

  • You have working knowledge of ISO 27001 and Cyber Essentials Plus, and know what "proportionate" looks like in a fast-moving product company.

  • You write and communicate clearly, structuring your thinking logically so people know what's expected of them and why.

  • You're comfortable working at pace and without extensive hand-holding, managing your own workload and flagging blockers early.

  • You care about what Accurx does, and understand that the data we protect belongs to patients and clinicians who trust us with it.

What’s in it for me?

You'll be joining an established but fast-growing Tech for Good movement, led by our Principles and our mission to solve healthcare productivity.

  • £50k salary

  • Benefits to suit you: adjust your healthcare cover, your pension or life insurance, whatever stage you’re at in life

  • Flexible working: We are an office-first culture and ask that you’re in our (dog-friendly) Shoreditch office 3 days a week, with core hours of 10 am - 4 pm

  • Time off: You’ll get 28 days of holiday (plus bank holidays) and up to 4 weeks to work from anywhere per year

  • We have our very own Chef! Free healthy breakfasts, snacks and lunches will be provided, with the occasional sweet treat!

Skills Required

  • 3-5 years hands-on experience in information security and risk management
  • Experience in health-tech or regulated SaaS environments
  • Experience running risk sessions, owning a risk register, and preparing risk reporting for senior stakeholders
  • Experience completing a Cyber Essentials Plus audit cycle
  • Working knowledge of ISO 27001 and Cyber Essentials Plus
  • Understanding of cloud infrastructure, endpoint management, identity and access controls, and network boundaries
  • Experience contributing to ISO 27001 and DSPT activities, including evidence collection and control documentation
  • Ability to coordinate evidence gathering across IT, Platform and Security Engineering
  • Strong written and verbal communication; able to translate security requirements to technical and non-technical stakeholders
  • Ability to work at pace, manage own workload, and escalate blockers early
  • Alignment with Accurx mission and care for patient/clinician data protection
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: London
254 Employees
Year Founded: 2016

What We Do

Accurx is where conversations happen with and about patients. Through one, easy-to-use platform, we help everyone involved in a patient’s care to communicate and collaborate. Whether you’re a patient or a healthcare professional, Accurx lets you connect seamlessly with the people you need to. We believe that healthcare runs on conversations - conversations in GP practices, on hospital wards, over the phone, text, video, email and from a patient’s home. That’s why we’re working toward a health system where everyone involved in patient care can communicate for the good of patients and healthcare staff. Every interaction on Accurx helps to build a better-connected healthcare system, where easy communication changes and saves lives every day.

Similar Jobs

Block Logo Block

Business Development Manager

Blockchain • eCommerce • Fintech • Payments • Software • Financial Services • Cryptocurrency
In-Office
London, Greater London, England, GBR
12000 Employees

Expedia Group Logo Expedia Group

Principal Product Manager

AdTech • eCommerce • Information Technology • Software • Travel • Generative AI
Hybrid
London, Greater London, England, GBR
16000 Employees

Cash App Logo Cash App

Business Development Manager

Blockchain • Fintech • Mobile • Payments • Software • Financial Services
Hybrid
London, Greater London, England, GBR
3500 Employees

Samsara Logo Samsara

Security Engineer

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
UK
4000 Employees
139K-174K Annually

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account