Cancer Research UK (CRUK)

Information Security Consultant (Salesforce)

Company
Location
Stratford, England, United Kingdom
Posted At
7/25/2025
Advertise with us by contacting: [email protected]
Description
Robust cyber security. Long-term vision and strategy. Impacting the future.

Information Security Consultant (Salesforce)

£70,000 - £73,000 (+ Benefits)

Grade: P3MP

Contract: 12 month fixed-term contract

Hours: Full time 35 hours per week

Location: Stratford, London. Office-based with high flexibility (1-2 days per week in the office)

Visa sponsorship: You must be eligible to work in the UK to apply for this vacancy. Cancer Research UK is not able to offer visa sponsorship.

Closing date: 08 August 2025 23:55

This vacancy may close earlier if a high volume of applications is received or once a suitable candidate is found, therefore we strongly recommend that you apply early to avoid disappointment. If you require more time to apply as part of a reasonable adjustment, please contact [email protected] as soon as possible.

Recruitment process: One to two competency-based interviews

Interview date: From the week commencing 18 August 2025

How do I apply? We operate an anonymised shortlisting process in our commitment to equality, diversity, and inclusion. CVs are required for all applications; but we won’t be able to view them until we invite you for an interview. Instead, we ask you to fully complete the work history section of the online application form for us to be able to assess you quickly, fairly, and objectively.

At Cancer Research UK, we exist to beat cancer.

We are professionals with purpose, beating cancer every day. But we need to go much further and much faster. That’s why we’re looking for someone talented, someone who wants to develop their skills, someone like you.

The Information Security team are essential in safeguarding Cancer Research UK across our network of 600+ shops, 4,000 staff, and millions of supporters and volunteers. The team ensures the charity has rigorous cybersecurity protocols and protective measures, while providing expert guidance and support to staff. They partner closely with leadership, stakeholders, projects, transformation programmes, and service procurement to ensure both existing and new technologies are secure by default.

As an Information Security Consultant, you will play a vital role in delivering our vision to establish a security baseline and measurable frameworks that enable governance, management, and transformation programmes. Your purpose will be to lead the architecture, design, and execution of our security strategy for a large-scale Salesforce Nonprofit Cloud (NPC) deployment, while ensuring alignment with Cancer Research UK’s wider cyber programme and strategic objectives. This will involve collaborating closely with Technology teams and senior leadership to ensure that security is a primary consideration in all aspects of deployment and throughout the broader programme.

By the end of this contract, your legacy will be defined by the successful and secure deployment of Salesforce as part of the largest transformation programme in the history of the UK charity sector (Engage). The governance frameworks, incident response protocols, and security strategies you design and embed will lay the foundations for Cancer Research UK’s long-term resilience - safeguarding critical data and empowering our lifesaving work for years to come.

If you are a Salesforce Information Security expert who has designed and delivered security strategies and transformational initiatives, we’d love for you to join our mission.

What will I be doing?

  • Security Strategy Development: Designing and implementing a comprehensive security strategy tailored to Cancer Research UK’s Salesforce Non-Profit Cloud (NPC) deployment and operations, ensuring alignment with organisational goals and regulatory requirements.
  • Risk Assessment: Conducting thorough risk assessments to identify potential security threats and vulnerabilities within the Salesforce NPC environment.
  • Security Controls Implementation: Developing and enforcing security controls, policies, and procedures to safeguard sensitive data and ensure compliance with industry standards.
  • Incident Response: Establishing and managing incident response protocols to effectively address and mitigate security breaches or incidents.
  • User Training and Awareness: As part of a wider change and training programme, conducting security training sessions for staff and stakeholders to promote best practices and ensure a security-conscious culture.
  • Continuous Improvement: Proactively monitoring the latest security trends, threats, and technologies to continuously strengthen and future-proof Salesforce NPC’s security at every stage of deployment.
  • Collaborating closely with IT, Legal, and Compliance teams to ensure cohesive security measures across the organisation.


What skills will I need?

  • Certified Information Security professional (CISSP, CISM, and/or Salesforce Security) with significant experience in Salesforce environments.
    • Experience with Salesforce Non-Profit Cloud is desirable but not essential—we welcome applicants without this experience.
  • Led on the end-to-end architecture, design, and execution of security strategies and transformational initiatives with the ability to adapt to changing security landscapes and organisational needs.
  • Led effective incident response efforts with experience using security technologies (including encryption protocols, firewalls, intrusion detection systems, and vulnerability assessment tools) to minimise risk and ensure rapid recovery.
  • Subject matter expert in information security standards and best practices (including PCI DSS and ISO 27001) with an understanding of key UK legislation (such as the Data Protection Act 2018, GDPR, and PECR).
  • Has built credible and collaborative relationships with Technology teams and senior leaders, demonstrating excellent interpersonal and communication skills with a proven ability to work autonomously and as part of a team.
  • Solutions-driven professional with meticulous attention to detail in identifying and addressing security risks, solving complex problems, driving continuous improvements, implementing robust governance frameworks, and championing best practices.
  • Ideally, has operated within DevSecOps environments, leveraging collaboration tools (such as Jira and Confluence) to enhance team efficiency, and contributing to impact assessments to shape effective technical solutions.

Our organisation values are designed to guide all that we do.

Bold: Act with ambition, courage and determination

Credible: Act with rigour and professionalism

Human: Act to have a positive impact on people

Together: Act inclusively and collaboratively

We’re looking for people who can believe in and embody these organisation values and can use them to drive forward progress against our mission to beat cancer.

If you’re interested in applying and excited about working with us but are unsure if you have the right skills and experience we’d still love to hear from you.

What will I gain?

We create a working environment that supports your wellbeing and provide a generous benefits package, a wide range of career and personal development opportunities and high-quality tools. Our policies and processes enable you to improve your work-life balance, take positive steps in your career and achieve your personal wellbeing goals.

You can explore our benefits by visiting our careers web page.

Additional Information

For more information about working with us please visit our website or contact us at [email protected].

For more updates on our work and careers, follow us on: LinkedIn, Facebook, Instagram, X and YouTube.

Our vision is to create a charity where everyone feels like they belong, benefits from and participates in, the work we do. We actively encourage applications from people of all backgrounds and cultures, in particular those from ethnic minority backgrounds who are currently under-represented.

We want to see every candidate performing at their best throughout the job application process, interview process and whilst at work. We therefore ask you to inform us of any concerns you have or any adjustments you might need to enable this to happen. Please contact [email protected] or 020 3469 8400 as soon as possible.

Unfortunately, we are unable to recruit anyone below the age of 18, so that we can protect young people from health & safety and safeguarding risks.
Advertise with us by contacting: [email protected]
logo
Hunt UK Visa Sponsors

Copyright © 2025

About us

How does it workContact UsBlog

Stay up to date

TwitterTelegram
Information Security Consultant (Salesforce) | Cancer Research UK (CRUK) | Hunt UK Visa Sponsors