About the role
The role involves managing operational security, including access control reviews, security requests, and incident monitoring. Additionally, the engineer will drive ISO 27001 compliance, coordinate penetration tests, and support secure development practices.
What they look for
Requirements
Candidates should have at least 2 years of experience in a security, infrastructure, or IT role with a working knowledge of ISO 27001. Strong organizational skills, clear written communication, and a pragmatic approach to security are essential.
Benefits
Full description
About us
ORdigiNAL is a technology company operating worldwide, with our strongest presence across Europe. We deliver technology through an established partner network alongside our own applications, sold into markets where security isn't a checkbox; it's a condition of sale. Our SecOps function sits at the heart of that, and this role sits at the heart of SecOps.
The role
You'll join our SecOps function, reporting directly to the Global Technology & Services Director. The role is deliberately broad: at its day-to-day level you'll own operational security - handling security requests, access control reviews, and keeping our security posture tidy and evidenced. At its highest level you'll drive the certifications that let us sell our applications across Europe: ISO 27001 and the audits, evidence and assessments that surround it.
You'll have real ownership from day one, direct support from the director you report to, and the chance to shape our security programme as the business and product line grow.
What you'll do
Day to day
- Own the security request queue: access requests, permission changes, joiner/mover/leaver reviews, security questions from around the business
- Run periodic access control reviews across our systems and keep the evidence audit-ready
- Monitor, triage and escalate security events and keep our incident readiness current
- Carry out vendor risk assessments for new tools and suppliers
Compliance and certification
- Drive ISO 27001 evidence collection and keep our ISMS living, not shelfware, including extending its scope to cover our software development
- Support DPIAs and data protection reviews alongside the business
- Coordinate CREST-accredited penetration tests (annually and per major release) and track remediation through to closure
- Help us attain and maintain the market schemes our customers require — Cyber Essentials Plus, NHS DSPT and DTAC in the UK, NEN 7510 in the Netherlands, and equivalents as we grow
Product security
- Work with our engineering function on secure development practices for our applications
- Contribute to the security cases our customers ask for during procurement
What we're looking for
- 2+ years in a security, infrastructure or IT role with meaningful security responsibility
- Working knowledge of ISO 27001 (helping run an ISMS, gathering evidence, or being on the receiving end of an audit all count)
- Comfortable owning a queue: organised, responsive, and able to keep many small things moving without dropping them
- Clear writing: much of this role is producing evidence, assessments and documentation that auditors and customers will read
- Pragmatism: security that is proportionate and enables the business, evidenced without becoming bureaucracy
Nice to have
- Experience in a regulated sector (e.g. DSPT, DTAC, NEN 7510, HDS, BSI C5, SOC 2)
- Exposure to DPIAs or GDPR work
- Familiarity with cloud security (Microsoft 365 / Azure) and identity management
- A security certification (Security+, ISO 27001 internal auditor, or similar) — or the appetite to work towards one
What we offer
- £33,000 salary (or local equivalent) plus employer pension
- Remote working from the UK or mainland Europe, with occasional travel to our Netherlands office for team days and audits
- Netherlands-based? Even better, you're welcome to work from our office
- A genuinely broad role with direct access to senior leadership and a clear growth path as our security programme and product line grow
- An annual training budget to support role-relevant development and certifications
- A role where security visibly matters to the business and its route to market