Information Security Risk & Assurance Specialist

Three
Reading, Berkshire

Our people make us who we are. We’re a diverse and inclusive bunch, and it’s important you can feel you belong here. We value everybody for who they are and what they bring to the table, supporting one another as we continue to deliver for our customers.

LI-KS1

  • Create & Maintain an information security management system (ISMS) capable of demonstrating compliance against internal security requirements and external commitments including certification and regulatory requirements.
  • Provide subject matter expertise in the application of established standards including NIST, PCI-DSS, GDPR, COBIT, ISO 27001 and Cyber Essential compliance to any new or existing programme of work.
  • Prepare and support internal and / or external compliance audit activities.
  • Manage remediation of any audit (internal & External) non-conformities.
  • Ensuring security policy (on a risk-based approach) is produced, signed off from relevant stakeholders, published and communicated. Also ensure that the policy is being managed in-life and updated through yearly or ad-hoc reviews.
  • Relevant security standards documentation is being produced in consultation with Technical teams.
  • Lead on providing information on requests from Three UK Customers (B2B) on Three UK’s security practices.
  • Provide support in proactive and effective oversight (and where appropriate challenge) of the technology and security risk management frameworks, methodologies, processes, assurance, remediation and reporting activities across the company.
  • Assist with the design, build and implementation of a Technology and Security Risk framework through working in conjunction with technology, security and Enterprise Risk and compliance teams.
  • Support Technology and Security teams in Undertaking risk assessments and identifying emerging risks through continuous assessment of the inherent and residual risk exposure. Provide robust challenge to the operational teams as they identify, assess, manage and report their technology risks (including Information Security and Cyber Risk) through various tools and activities (including risk and control assessments, key indicators, issue and incident management, and control assurance).
  • Manage and continually improve Three’s Security Exception process.
  • Work effectively with Enterprise risk and compliance function to escalate any enterprise level Technology and Security risks.
  • Operate GRC tool for Risk Management to record, track and monitor risks and controls.
  • Support ongoing education and awareness activities around agreed Security policies, Risk management frameworks and governance across the company.
  • Working with Stakeholders and Partners to ensure that Three delivers and remains compliant against key
    security and privacy standards and certifications
  • Maintains up-to-date knowledge of the legal & regulatory requirements that can impact Technology and
    Operations and its Partners.
  • Uses comprehensive knowledge of legal and regulatory obligations and industry best practice and frameworks
    (e.g NIST, COBIT, ISO27001, PAS 555) to ensure technology standards compliance is achieved.
  • Schedules risk and compliance audits, review the outcomes audit process; Directs compliance issues to
    appropriate resources for investigation and resolution.

Our people make us who we are. We’re a diverse and inclusive bunch, and it’s important you can feel you belong here. We value everybody for who they are and what they bring to the table, supporting one another as we continue to deliver for our customers.

LI-KS1

  • One of the Risk or security certifications (CISSP, CRISC, CISM)
  • Good knowledge and practical experience of NIST, PCI-DSS, GDPR, COBIT, ISO 27001 or Cyber Essentials.
  • Previous experience in similar role. Ability to work in dynamic and changing environment.
  • Excellent team player who can influence, help and support others.
  • Working with Stakeholders and Partners to ensure that Three delivers and remains compliant against key
    security and privacy standards and certifications
  • Maintains up-to-date knowledge of the legal & regulatory requirements that can impact Technology and
    Operations and its Partners.
  • Uses comprehensive knowledge of legal and regulatory obligations and industry best practice and frameworks
    (e.g NIST, COBIT, ISO27001, PAS 555) to ensure technology standards compliance is achieved.
  • Schedules risk and compliance audits, review the outcomes audit process; Directs compliance issues to
    appropriate resources for investigation and resolution.
Posted 2025-04-05

Recommended Jobs

Business Support Assistant - Post Room Operative - CAMPUS...

Savills Management Resources
Reading, Berkshire

Purpose of the Role The Post Room Operative’s main role is to take responsibility for effective running of the post room/loading bay at Campus Reading International. The role holder will ensure al…

View Details
Posted 2026-04-08

Mobile Air Conditioning Installer

Tech-People
Reading, Berkshire

Mobile Air Conditioning Installation Engineer M4 Corridor & London Up to £55,000 + Door-to-Door + Overtime + Package Want to work on high-end commercial installs with a company that actually …

View Details
Posted 2026-04-01

Wet Room Fitter

ITS Property Maintenance
Reading, Berkshire

SW-007-WetRoom-246 Wet Room Fitter | (Cap & Cove / Hot Weld Specialist) £25 - £28 per hour Working for a Maintenance Contractor Based in the Reading area Long term temp to perm Overview * W…

View Details
Posted 2026-04-09

Mixed Tax Manager - Newbury

Clark Wood
Reading, Berkshire

Mixed Tax Manager - Newbury Clark Wood have been instructed on an exceptionally rare opportunity, which offers the chance for an experienced Tax Manager to join one of the region's accountancy & t…

View Details
Posted 2025-08-24

Electrician

Daniel Owen Ltd
Reading, Berkshire

Job Title: Electrician - EICRs Location: Reading Salary: £38,700 - £42,000 (OTE - £60,000 - £70,000) w/ Van and Fuel Card Job Type: Permanent Daniel Owen are currently seeking qualified electricia…

View Details
Posted 2026-03-04

Employer Tax Manager - Location Flexible - 100% WFH

Clark Wood
Reading, Berkshire

Employer Tax Manager - Location Flexible - 100% WFH This Employer Tax Manager role offers genuine scope for career development and progression as part of this international advisory boutique who s…

View Details
Posted 2025-12-09

Transfer Pricing Lead

Hays Accountancy and Finance
Reading, Berkshire

Your new company My client is seeking an experienced and strategic Transfer Pricing Senior Manager to lead global transfer pricing operations, ensure compliance with international regulations, and…

View Details
Posted 2026-04-02

Year 2 Teacher - Outstanding School in Reading

Marchant Recruitment
Reading, Berkshire

Are you an enthusiastic and dedicated Year 2 teacher with a passion for helping children thrive during their Key Stage 1 journey? Do you want to make a meaningful impact in a supportive and creative …

View Details
Posted 2025-10-10

Field Service Engineer

LINK CONSULTANTS
Reading, Berkshire

Company: LINK CONSULTANTS Job Type: Permanent, Full Time Salary: £40000 - £50000/annum

View Details
Posted 2026-04-09

Facility Specialist

AWE
Reading, Berkshire

If you’d like to be considered for this opportunity we encourage you to apply promptly to avoid disappointment as if applications are high the role will close before the closing date given. Faci…

View Details
Posted 2026-03-25