Information Security & Risk Specialist (12-month FTC)
Accurx
<h2><strong>💬 Accurx is solving healthcare productivity for the NHS.</strong></h2><p style="min-height:1.5em">For decades, the NHS has struggled with fragmented systems that make simple tasks feel impossible. At Accurx, we’re changing that by building a single, system-wide platform that helps every patient get gold-standard, efficient, and joined-up care.</p><p style="min-height:1.5em">What started as a way for GPs to text a patient has now evolved into an all-in-one digital toolkit used by 98% of GP practices.</p><p style="min-height:1.5em">Our platform now powers <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.accurx.com/primary-care"><strong>Total Triage</strong></a> to manage patient demand, and <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.accurx.com/booking"><strong>Self-Book</strong>,</a><strong> </strong>which lets patients schedule their own appointments in seconds. We’ve automated routine care with <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.accurx.com/questionnaires"><strong>Patient Questionnaires</strong></a> for long-term conditions, while <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.accurx.com/accumail"><strong>Accumail</strong></a> finally allows staff-to-staff communication to happen instantly across different care settings. We’re now pushing the boundaries of the consultation itself with <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.accurx.com/scribe"><strong>Accurx Scribe</strong></a>, our AI-powered note-taker that drafts medical notes in real-time.</p><p style="min-height:1.5em">We’re not just shipping features. We’re giving clinicians their time back and ensuring every patient journey is as smooth as it should be.</p><h2><br /><strong>How this role sits within the function</strong></h2><ul style="min-height:1.5em"><li><p style="min-height:1.5em"><strong>Reports to:</strong> Senior Information Security Officer</p></li><li><p style="min-height:1.5em"><strong>Function:</strong> Privacy & Information Security</p></li><li><p style="min-height:1.5em"><strong>Contract type:</strong> Twelve-month fixed-term contract</p></li></ul><p style="min-height:1.5em">This role works day-to-day alongside the Senior Information Security Officer, who owns the GRC framework, ISO 27001 programme, CE+ and DSPT compliance, and the security risk register. It provides dedicated capacity to push forward priority workstreams - particularly risk management, CE+ audit readiness, and data strategy delivery.</p><p style="min-height:1.5em"></p><h2><strong>Challenges you’ll solve...</strong></h2><ul style="min-height:1.5em"><li><p style="min-height:1.5em"><strong>Own the security risk register:</strong> Facilitate risk assessment sessions with technical and non-technical stakeholders across the business, keep the register current and accurate, and prepare clear risk reporting that translates technical risk into business language.</p></li><li><p style="min-height:1.5em"><strong>Drive Cyber Essentials Plus readiness:</strong> Coordinate evidence gathering across IT, Platform and Security Engineering ahead of the CE+ deep-dive audit, reviewing controls against requirements and flagging gaps with practical remediation guidance.</p></li><li><p style="min-height:1.5em"><strong>Deliver our data classification programme:</strong> Work with data owners to classify information assets in line with policy, and push the access control programme forward by reviewing current access patterns and identifying gaps.</p></li><li><p style="min-height:1.5em"><strong>Keep risk treatment moving:</strong> Track risk treatment actions and follow up with owners so items progress rather than stall, managing milestones and blockers across the risk, CE+, and data workstreams.</p></li><li><p style="min-height:1.5em"><strong>Support the wider security programme:</strong> Contribute to ISO 27001 and DSPT activities where your work intersects, including evidence collection and control documentation, and support policy and process documentation as needed.</p></li><li><p style="min-height:1.5em"><strong>Be a translator between security and the business:</strong> Communicate security requirements clearly to engineers, and help non-technical stakeholders understand risk well enough to act on it.</p></li></ul><p style="min-height:1.5em"></p><h2><strong>You should apply if...</strong></h2><ul style="min-height:1.5em"><li><p style="min-height:1.5em">You have 3–5 years of hands-on experience in information security and risk management, ideally in health-tech or a regulated SaaS environment.</p></li><li><p style="min-height:1.5em">You've run risk sessions, owned a risk register, and prepared risk reporting for senior stakeholders</p></li><li><p style="min-height:1.5em">You've worked through a Cyber Essentials Plus audit cycle yourself</p></li><li><p style="min-height:1.5em">You understand cloud infrastructure, endpoint management, identity and access controls, and network boundaries well enough to hold your own in a technical conversation - you don't need to be a developer.</p></li><li><p style="min-height:1.5em">You have working knowledge of ISO 27001 and Cyber Essentials Plus, and know what "proportionate" looks like in a fast-moving product company.</p></li><li><p style="min-height:1.5em">You write and communicate clearly, structuring your thinking logically so people know what's expected of them and why.</p></li><li><p style="min-height:1.5em">You're comfortable working at pace and without extensive hand-holding, managing your own workload and flagging blockers early.</p></li><li><p style="min-height:1.5em">You care about what Accurx does, and understand that the data we protect belongs to patients and clinicians who trust us with it.</p></li></ul><p style="min-height:1.5em"></p><h2><strong>What’s in it for me?</strong></h2><p style="min-height:1.5em">You'll be joining an established but fast-growing Tech for Good movement, led by our <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.notion.so/accurx/How-we-work-Accurx-Principles-211640edee304821b4480d3f9c30e051">Principles</a> and our <a target="_blank" rel="noopener noreferrer nofollow" href="https://accurx.notion.site/Mission-and-Vision-fe9b12ff78bd4a7996682fc5c09c2d8e">mission</a> to solve healthcare productivity. </p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">£50k salary</p></li><li><p style="min-height:1.5em"><a target="_blank" rel="noopener noreferrer nofollow" href="https://accurx.notion.site/Perks-Benefits-f1e9148b71be486791aa2c503e5d775a?pvs=74"><u>Benefits to suit you: </u></a>adjust your healthcare cover, your pension or life insurance, whatever stage you’re at in life</p></li><li><p style="min-height:1.5em">Flexible working: We are an office-first culture and ask that you’re in our (dog-friendly) Shoreditch office 3 days a week, with core hours of 10 am - 4 pm</p></li><li><p style="min-height:1.5em">Time off: You’ll get 28 days of holiday (plus bank holidays) and up to 4 weeks to work from anywhere per year</p></li><li><p style="min-height:1.5em">We have our very own Chef! Free healthy breakfasts, snacks and lunches will be provided, with the occasional sweet treat!</p></li></ul><hr><p>Compensation: £50K</p><ul><li> • £50K</li></ul><p>Find more <a href="https://www.arbeitnow.co.uk/english-speaking-jobs">English Speaking Jobs in United Kingdom</a> on Arbeitnow</a>