Information Security Manager
Kier Group plc.
Charing Cross, United Kingdom
4 days ago
Role details
Contract type
Permanent contract Employment type
Full-time (> 32 hours) Working hours
Regular working hours Languages
English Compensation
£ 96KJob location
Charing Cross, United Kingdom
Tech stack
Cloud Computing Security
CompTIA Security+
Computer Security
Identity and Access Management
Information Management
Network Segmentation
Open Web Application Security
Systems Development Life Cycle
Devsecops
Job description
Location: Flexible, hybrid working. Can be based out of our Rushden or London office. Travel to both is required as well as to various UK wide Transportation sites and offices for audits
Hours: 37.5 hours per week - some flexibility on hours available if desired, just let us know when you speak to us
What will you be responsible for?
As anInformation Security Manager, your day-to-day responsibilities will include, but not be limited to:
- Working with Kier's strategic partners to ensure overall Information Security governance is understood and being adhered to by all partners.
- Providing consultative advice and coaching to security customers within the Kier Transportation environment, and wider business as required.
- Creating status reports and briefings on security matters for staff and senior management.
- Supporting bids by providing security review and assurance around Bid security requirements.
- Ensuring upward balanced and expert reporting to guide stakeholders in how to manage Kier IT Security risks.
- Ensuring that Transportation adhere to Kier policies and authorised procedures.
- Devising and delivery of Security Education training aligned to specific contractual requirements.
Requirements
- Security expertise backed by certifications such as CompTIA Security+, ISO 27001 Lead Implementor/Auditor, CISM, or CISSP - or equivalent hands-on experience.
- Strong technical knowledge in cloud security, IAM, network segmentation, OWASP, and DevSecOps.
- Proven ability in risk management, applying frameworks like ISO 27001 and NIST to deliver proportionate controls.
- Experience in secure-by-design principles and validating large-scale, high-risk services.
- Familiarity with key standards such as List-X (FSC), ISO 27001, Cyber Essentials, and Cyber Essentials Plus.
- Awareness of how emerging technologies impact security requirements and architecture.
- Understanding of information management, SDLC, IT service management, Enterprise Architecture, and ITIL frameworks.
About the company
Making Kier a diverse and inclusive place to work is a huge priority for us. We're proud of the steps we've taken so far, but we know we must always do more. Our employees are key in shaping Kier's diversity and inclusion initiatives and our people have made a huge impact on how we work, by using their experiences to shape our policies. You can see our D&I action plan here.
As a Disability Confident employer, we will ensure that a fair and proportionate number of disabled applicants that meet the minimum criteria for this role will be offered an interview.