Information Security Specialist
About this role
Location:
- Living & working full time in either Ireland or UK only
- Remote by default.
Travel:
- Roughly 1-3 days per quarter to UK sites (Kidlington and Exeter), Ireland and occasionally to North America.
- This is required to support good information security posture and culture
Right to Work
- We are unable to offer UK or Irish visa sponsorship for this role.
Reporting & work team
- You'll report to and work closely with the Information Security Lead, as well as Cybersecurity Engineering, DevOps, IT, Data Governance, and AI Governance to embed secure-by-design practices across the organisation.
Why this role exists
- Through the work that we do, the team at Deciphex helps pharma to accelerate the process of essential drug development and helps cancer patients get a timely and accurate diagnosis. We hold ISO 27001 across our core business units and we are expanding coverage as we grow.
- The systems and data we protect directly support cancer diagnostics and drug development, so this is security work with real consequence.
- Information security underpins all of our business activities, including AI development and compliance with Medical Device regulations
If you’ve ever been the person who found the problem, could not get anyone to fix it, and eventually fixed it yourself, this role is written for you.
About this Role
- This role moves away from traditional GRC and leans into modernising it. We're moving teams towards always-on compliance and consistently demonstrating business value in the activities we run.
- What we do not need is another layer of documentation. What we do need is someone who builds the controls, checks them personally, and can show the difference they made.
- You'll work across the business as someone who meets challenges head-on, brings people with them, and makes security work in practice, not just on paper.
What this is not
- Not a paper-only ISMS role. You’re a doer, you take hands-on ownership of controls that work, not documentation that describes controls that might.
- Not an on-call security operations role. Day to day logging, monitoring and live incident handling sit with our cyber security team. You own the incident management process and the tooling around it.
- Not a gatekeeping or policing function. The goal is to enable the business to move fast safely not punish them.
- Not a role where escalation is the first move. We reward people who find the answer and act themselves to fix it.
- Not a role with six layers of management above you. If you need extensive direction to make progress, you will find this frustrating.
What success looks like in your first year
- Evidence for the majority of controls is collected automatically, not requested by email.
- Incident management has been rebuilt, tested through a tabletop, and is actually used.
- Controls you have signed off have been verified by you, with a record of how.
- Audits hold no surprises for anyone, and stay low friction.
- Security reviews unblock commercial deals rather than delay them.
- Risks are visible, owned and reducing, with numbers to show it.
- Teams bring security in early because it helps them, not because policy says so.
What you will own
ISMS and certifications
- Day to day running of the ISO 27001 ISMS across Deciphex, Diagnexia and Patholytix.
- Audit readiness as a steady state - Internal and external audits, certification bodies and customers.
- Finding and closing gaps in the control framework, and driving corrective actions to closure.
- A reliable evidence pipeline with clear ownership and high completeness.
- Judging which ISMS activities deliver measurable value, and retiring the ones that do not.
Governance and risk
- A live, decision-oriented risk register with named owners and mitigation plans that actually move.
- Policies and procedures that reflect how the business really operates. (not large unwieldy policy for policy sake)
- Vendor and customer security due diligence in support of commercial and product needs.
- Tabletop exercises for incident response and business continuity.
- Keeping the ISMS aligned to the EU AI Act, GDPR, HIPAA and MDR or IVD requirements.
Technical delivery and oversight
- Define what good evidence looks like for technical controls: SIEM, EDR, MFA, RBAC, vulnerability management.
- Go and check. Verify yourself rather than relying on assertions. If something looks wrong, investigate it and resolve it.
- Automate the manual parts of compliance rather than staffing them.
- Support site reliability and resilience work.
Security culture
- Awareness training that changes behaviour, not completion rates.
- Be the visible, approachable point of contact for security questions across the business.
- Translate security requirements into plain language without losing accuracy.
Skills & Qualifications
- A note on certifications: we are more interested in what you have implemented than what you have passed. A shorter list with evidence behind it beats a long one without.
What we need to see
- Around five years in information security. We will look seriously at less if your delivery evidence on your CV is strong. (Generic CV’s wont show us this)
- Hands-on implementation of security controls, with outcomes you can describe. Vulnerabilities reduced, evidence automated, hours saved, a process that scaled. Tell us what changed, not what you were responsible for.
- Practical experience with the technology behind the controls: mobile device management, identity provider tooling, vulnerability management, SIEM, and cloud environments such as AWS.
- Working ISO 27001 experience covering internal audit, management review, and external audit with both certification bodies and customers.
- A habit of validating controls yourself rather than accepting that someone says they exist.
- A track record of operating with autonomy where resources are limited and priorities shift. You find the answer and move things forward rather than escalating first.
Nice to have
- Scripting or automation against APIs, particularly for evidence collection.
- Google Workspace, GitHub or GitLab, and familiarity with how software actually ships.
- Experience in a regulated environment such as med tech, clinical or life sciences.
- Experience working alongside engineering teams.
- CISSP or equivalent.
How we will assess your Application
- We know a CV is a poor way to show delivery, so we do not rely on it alone.
- You’ll be asked three short written questions at the application stage & assesed on this + your outcomes focused CV
Soft skills (we hire for will as equally as skill)
- Comfortable working with a high degree of autonomy - you naturally lead & take ownership of priorities and make progress without the need for close supervision or extensive direction.
- This role is likely to suit someone who enjoys working in a fast-paced, growing environment where resources may be more limited and priorities can shift quickly. Those accustomed to highly structured organisations with large, specialised teams may find the pace and breadth of responsibility either challenging or highly rewarding, depending on their preferred way of working.
- Your well able to navigate ambiguity, exercise sound judgement, and build effective relationships across a matrixed, globally distributed organisation to deliver results.
What are the benefits of working with Deciphex?
🔬 Work that saves lives. Every day, your contribution moves the needle on patient outcomes that actually matter.
🚀 Join a team people leave other companies for. World-class talent, hyper-growth environment, zero mediocrity.
📈 Grow fast, on purpose. Regular feedback, clear progression, and real career momentum built in from day one.
🏡 Work from where you do your best thinking. A flexible, hybrid model that trusts you to manage your time like an adult.
✈️ Take your work global. Eligible employees can work from abroad for up to a month each year. Yes, really.
💰 Paid fairly, rewarded for performance. Competitive salary with annual increments tied to what you actually deliver.
🎄 Recharge properly. Generous annual leave plus a fully paid Christmas shutdown.
🌍 A team that spans cultures, not just time zones. Genuinely collaborative, genuinely supportive, no politics.
The above Job Description reflects the requirements of this position at the time of issue. As duties and responsibilities change and develop, this will be reviewed and may be subject to amendments.
About Us
Through the work that we do, the team at Deciphex helps pharma to accelerate the process of essential drug development and helps cancer patients get a timely and accurate diagnosis.
Founded in Dublin in 2017, Deciphex has scaled rapidly to a team of over 230 people and counting who are providing software solutions to address the pathology gap in research pathology and clinical areas. We have offices in Dublin, Exeter, Oxford, Chicago and Toronto, and are expanding our team throughout the world.
We are software developers, clinical specialists, artificial intelligence engineers, operations professionals and so much more, all working as one team to support our customers and patients.
Read more about Deciphex here and more about our incredible team on our Careers Page her
Deciphex is an equal opportunities employer and we are committed to the principle of equality. All qualified applicants will be considered for employment without regard to age, race, religious beliefs, political views, gender identity, affectional or sexual orientation, national origin, family or marital status (including pregnancy), disability, membership of the travelling community or any other classification protected by applicable law.
A copy of our Privacy Policy can be viewed here
Frequently Asked Questions
Is the salary disclosed for the Information Security Specialist position at deciphex?
Is the Information Security Specialist job at deciphex remote?
Is the Information Security Specialist role at deciphex full-time or part-time?
Which team or department does the Information Security Specialist at deciphex belong to?
How do I apply for the Information Security Specialist position at deciphex?
When was the Information Security Specialist job at deciphex posted?
You'll be redirected to deciphex's official application page on bamboohr.