Information Security & Risk Specialist (6-month FTC)

London, United Kingdom · LondonRisk & Compliance Manager, Security Engineer, Security Professional£50kPosted Jul 14, 2026
Information Security & Risk Specialist (6-month FTC) LocationLondon (Shoreditch)Employment TypeFull timeLocation TypeHybridDepartmentProduct & TechnologySecurity & PrivacyCompensation£50K💬 Accurx is solving healthcare productivity for the NHS.For decades, the NHS has struggled with fragmented systems that make simple tasks feel impossible. At Accurx, we’re changing that by building a single, system-wide platform that helps every patient get gold-standard, efficient, and joined-up care.What started as a way for GPs to text a patient has now evolved into an all-in-one digital toolkit used by 98% of GP practices.Our platform now powers Total Triage to manage patient demand, and Self-Book, which lets patients schedule their own appointments in seconds. We’ve automated routine care with Patient Questionnaires for long-term conditions, while Accumail finally allows staff-to-staff communication to happen instantly across different care settings. We’re now pushing the boundaries of the consultation itself with Accurx Scribe, our AI-powered note-taker that drafts medical notes in real-time.We’re not just shipping features. We’re giving clinicians their time back and ensuring every patient journey is as smooth as it should be.How this role sits within the functionReports to: Senior Information Security OfficerFunction: Privacy & Information SecurityContract type: Six-month fixed-term contractThis role works day-to-day alongside the Senior Information Security Officer, who owns the GRC framework, ISO 27001 programme, CE+ and DSPT compliance, and the security risk register. It provides dedicated capacity to push forward priority workstreams - particularly risk management, CE+ audit readiness, and data strategy delivery.Challenges you’ll solve...Own the security risk register: Facilitate risk assessment sessions with technical and non-technical stakeholders across the business, keep the register current and accurate, and prepare clear risk reporting that translates technical risk into business language.Drive Cyber Essentials Plus readiness: Coordinate evidence gathering across IT, Platform and Security Engineering ahead of the CE+ deep-dive audit, reviewing controls against requirements and flagging gaps with practical remediation guidance.Deliver our data classification programme: Work with data owners to classify information assets in line with policy, and push the access control programme forward by reviewing current access patterns and identifying gaps.Keep risk treatment moving: Track risk treatment actions and follow up with owners so items progress rather than stall, managing milestones and blockers across the risk, CE+, and data workstreams.Support the wider security programme: Contribute to ISO 27001 and DSPT activities where your work intersects, including evidence collection and control documentation, and support policy and process documentation as needed.Be a translator between security and the business: Communicate security requirements clearly to engineers, and help non-technical stakeholders understand risk well enough to act on it.You should apply if...You have 3–5 years of hands-on experience in information security and risk management, ideally in health-tech or a regulated SaaS environment.You've run risk sessions, owned a risk register, and prepared risk reporting for senior stakeholdersYou've worked through a Cyber Essentials Plus audit cycle yourselfYou understand cloud infrastructure, endpoint management, identity and access controls, and network boundaries well enough to hold your own in a technical conversation - you don't need to be a developer.You have working knowledge of ISO 27001 and Cyber Essentials Plus, and know what "proportionate" looks like in a fast-moving product company.You write and communicate clearly, structuring your thinking logically so people know what's expected of them and why.You're comfortable working at pace and without extensive hand-holding, managing your own workload and flagging...

Want jobs like this matched to you?

SimpleCareer scores fresh postings against your résumé so you only see the matches that matter.

Get started free