Information Security Officer – Chelsea FC

KEY RESPONSIBILITIES INCLUDE:

  • Lead vulnerability management and incident response across all platforms and systems.
  • Oversee and execute security projects, including policy enforcement and new initiatives.
  • Collaborate with the Technology and Infrastructure teams to ensure continuous improvement of the club’s security framework.
  • Manage relationships with external security partners and ensure timely resolution of any third-party security issues.

 

LOCATION: Stamford Bridge

CONTRACT: Permanent

MAIN RESPONSIBILITIES:

  • Identify and manage vulnerabilities within our current infrastructure.
  • Monitor network traffic and logs to ensure compliance with security policies and swiftly address any anomalies.
  • Take ownership of risk management and vulnerability assessments, offering strategic recommendations and working with internal teams to implement remediation actions.
  • Oversee phishing campaigns, investigate phishing alerts, and ensure continuous improvement of threat detection.
  • Collaborate with external security partners to manage risks, vulnerabilities, and incidents, acting as the primary liaison between these partners and the club.
  • Perform investigations of security incidents and breaches not covered by external partners, and oversee the club’s response to such threats.
  • Educate teams across the club on security best practices, and ensure they are equipped with the latest knowledge and tools to handle security incidents.
  • Lead on drafting and updating security policies, ensuring compliance with the latest industry standards.
  • Manage email security filters and respond to alerts in a timely manner.
  • Conduct regular security audits and assessments to ensure continuous improvement in the club’s security posture.
  • Assist in security-related legal and data protection matters (e.g., eDiscovery) as needed.
  • Champion the club’s efforts towards achieving CE+ certification, and drive forward other major security initiatives.

 

MEASURES OF PERFORMANCE:

  • Respond to security alerts and incidents within defined SLA terms.
  • Improve and maintain the club’s secure score, ensuring regular updates and remediation actions.
  • Successfully lead and implement vulnerability and risk management processes across all departments.
  • Ensure security awareness and compliance throughout the organisation by delivering regular training and workshops.

 

EXPERIENCE/REQUIREMENTS:

Essential:

  • Extensive experience in an information security role, including incident and service request management.
  • Experience with vulnerability management, risk assessment, and monitoring of IT systems.
  • Strong understanding of cloud security, with hands-on experience in Microsoft and Cloud environments.
  • Knowledge of security frameworks and regulations (e.g., GDPR, CE+).
  • Effective communication skills, with the ability to educate and influence a non-technical audience.

 

Desirable:

  • Professional cybersecurity certifications (e.g., CISSP, CISM).
  • Experience in Data Protection and GDPR compliance.
  • Experience with risk management in a fast-paced, highly regulated environment.
  • Microsoft Windows technical certifications.

More Information

Share this job