Information Security Officer
Aareon
Job Description
Aareon Aareon is Europe's established provider of SaaS solutions for the real estate industry and a pioneer of the sector's digital future. With its software solutions, Aareon connects people, processes, and properties-bringing the industry closer together. With the Aareon Property Management System, based on intelligent software solutions, the company enables the efficient management and maintenance of residential and commercial properties and creates digital experiences for all stakeholders.
As a reliable and innovative partner, Aareon is committed to progress, positive change, and sustainable living and working spaces for everyone. We value a working environment in which diversity and flexibility are appreciated, cooperation in partnership and mutual support in the team are a matter of course and learning is perceived as an opportunity. Become part of our international team!
Become part of #OneAareon! We are looking forward to meeting YOU! Salary: £70,000-£80,000 per year (depending on experience) Work Location: Hybrid London or Manchester Hours per week: 37.5 Contract Type: Permanent, full-time About the Role Aareon UK builds software that housing providers and property professionals rely on every day.
As our product set grows, security and data protection matter more than ever. We're hiring a UK Security Officer to take ownership of security across the UK business. This is a senior role covering security across applications, platforms, infrastructure, and engineering.
You'll also act as the UK Information Security Officer, helping protect customer data, maintain compliance, and keep security practical in day-to-day delivery. You’ll be the main UK contact for the Group Security Operations Centre in Germany, making sure group direction works in practice for the UK business. You’ll own the UK security programme, build on what is already in place, and help bring more consistency across our UK brands.
Team & Scope This is initially an individual contributor role with strong matrix influence across teams. It works alongside CloudOps, IT, Legal, Compliance and Engineering. What You'll Be Responsible For Developing and running the UK security strategy – Set and deliver a clear UK security strategy that aligns with group direction while working for the UK business.
Turn group guidance into practical local plans, set priorities, and help leadership make sensible investment decisions. Bring more consistency across our UK brands. Shape and manage the UK security budget, ensuring investment focuses on the right risks, controls, and priorities.
Governance, risk and compliance – Own and improve our UK security governance. That includes the ISMS, policies, risk management, and the controls needed to meet our obligations. Keep ISO 27001, ISO 9001, Cyber Essentials, GDPR, and relevant customer or sector requirements up to date.
Support audits, due diligence, customer assurance activity, and third‑party risk management, coordinating evidence and assurance readiness. Security operations, vulnerability management and incident support – Oversee day‑to‑day security operations for the UK, working closely with CloudOps and the Group SOC. Coordinate security incidents, ensuring the right people are involved and follow‑up actions are completed.
Own penetration testing and vulnerability management, helping teams make risk‑based decisions about remediation, sequencing, and technical debt. Security in engineering and platform delivery – Work with engineering, architecture, product, platform, and DevOps teams to embed security into design, build, and run processes. Include secure coding, design reviews, threat modelling, DevSecOps practices, and cloud security.
Policy, awareness and cross‑functional working – Update security and quality policies and standards to be practical and usable. Support security awareness through clear guidance, communication, and training. Coordinate with engineering, product, IT, data, legal, compliance, HR, and operations to keep security visible and aligned.
Resilience, disaster recovery and business continuity – Strengthen disaster recovery strategy and business continuity planning across the UK estate. Ensure recovery expectations are clear, plans are practical, risks are understood, and resilience is tested proportionately. Customer assurance and commercial security support – Support customer and commercial security activity, including security questionnaires, due diligence responses, and clear explanations of our controls and approach.
Aid sales, account teams, and leadership in responding consistently to customer security queries. Reporting and Group alignment – Track useful security metrics and report to UK leadership and the Group CISO/SOC. Use dashboards to show risk, progress, and areas needing attention.
Act as the main UK link into the Group SOC. AI security – Keep the business informed of AI‑related security risks, covering staff use of AI tools, AI in products, agentic workflows, and the evolving risks from new models and external tooling. About You You are an experienced security leader who combines sound judgement with practical delivery.
You can work comfortably with senior stakeholders while also digging into detail when needed. You explain security clearly, make risk visible, and help teams take sensible action. Your collaboration, pragmatism and credibility help you push, guide and negotiate trade‑offs without losing sight of the bigger picture.
You are comfortable operating across a complex organisation and working with different teams, brands, and levels of technical maturity. You will be a great fit if you: can work well with both technical teams and senior business stakeholders are practical and delivery‑minded, not theoretical are comfortable owning security outcomes while working through others can influence without creating unnecessary friction care about building a strong security culture, not just implementing controls stay current on emerging technology and risk, including AI Skills & Experience Essential Strong experience in a senior cyber or information security role in a technology‑led business A solid grasp of security governance, risk management, and control frameworks Good working knowledge of ISO 27001, ISO 9001, Cyber Essentials, GDPR, and similar standards Broad technical understanding across cloud, infrastructure, application security, and secure delivery Experience of incident response, vulnerability management, and penetration testing follow‑up Ability to communicate clearly with both technical and non‑technical audiences Comfortable setting priorities, balancing risk, and working in a fast‑moving environment Desirable Relevant certifications such as CISSP, CISM, or CISA Experience in SaaS, proptech, housing, or another data-sensitive software environment Experience working with group functions, auditors, regulators, or external security partners Experience working across multiple brands, business units, or countries Familiarity with AI security issues across internal use, product use, and evolving external tooling #J-18808-Ljbffr