David Jones
Information Security Compliance Associate @Severn Trent
Signup · Get unlimited contacts
WORK HISTORY
Information Security Compliance Associate @Severn Trent
Maintain and improve the Information Security compliance framework aligned with regulations and standards (GDPR, NIS, PCI DSS).Support audits, evidence collection, and remediation of compliance gaps.Assess and report on supplier security posture and adherence to policies.Develop and update security policies, standards, and procedures.Deliver training and awareness programs to promote a strong security culture.Translate technical compliance issues into clear business-focused reporting.Collaborate with teams to enhance governance and security maturity.
EDUCATION
Coursera
Google's Cybersecurity Professional Certification
Learning People Global
CompTIA Security+
Simply Cyber Academy
GRC Masterclass, Governance, Risk and Compliance
Learning People Global
CompTIA Network+
University of Worcester
Higher National Diploma (HND), Sports Performance and Coaching
Telfore College of Arts and Technology
Uniformed Public Services
ABOUT DAVID JONES
I’m a cybersecurity professional specialising in Governance, Risk & Compliance, with hands-on experience supporting security controls, assurance activities, and regulatory alignment within critical national infrastructure.In my current role as Information Security Compliance Associate at Severn Trent, I play a crucial role in strengthening organisational security maturity through risk-based compliance, evidence-driven assurance, supply chain security assessments, and close cross-functional collaboration. My work spans policy implementation, control validation, audit readiness, and stakeholder engagement — with leading implementation toward Cyber Essentials certification and supporting alignment with emerging NIS-R requirements.I’m particularly focused on translating technical security requirements into practical, auditable outcomes — bridging the gap between engineering, operations, and governance. This includes supporting control frameworks, assessing security posture, improving documentation standards, and helping embed security-by-design across the business.My technical foundation is backed by industry certifications including CompTIA Network+ and Security+, alongside ongoing progression through CySA+ pathways via CompTIA. These studies reinforce my strengths in network security, threat awareness, incident response fundamentals, and defensive architecture.I bring a structured, analytical mindset to cybersecurity — combining compliance rigor with a genuine interest in how systems work under the hood. I’m driven by continuous improvement, practical risk reduction, and helping organisations operate securely in complex environments.I’m actively building toward a future in cyber leadership — developing both the technical depth and strategic perspective required to guide security programmes at scale. My goal is to progress into senior GRC and security leadership roles where I can shape security culture, influence organisational risk decisions, and help drive resilient, business-aligned cyber strategy. I’m keen to connect with security leaders, GRC professionals, and mentors who value continuous growth, pragmatic security, and leading from the front.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.