Information Security and Compliance Manager
Role details
Job location
Tech stack
Job description
The Information Security and Compliance Manager is responsible for defining and implementing the organisation's information security strategy to protect data, systems, and intellectual property. This role ensures compliance with UK, European and North American regulations and industry standards, while embedding security into the software development lifecycle., * Develop and execute a security strategy aligned with business and product objectives.
- Advise senior leadership on emerging threats, risk posture, and security investments.
Governance & Compliance
- Establish and maintain an information security governance framework.
- Ensure compliance with UK and international standards, including:GDPRPCI DSSPCI 3DSSOC 2NIST 800-61 r3
- Oversee internal and external audits and certification processes.
- Manage and complete security assessments for 3rd parties, customers and insurance purposes.
- Work in partnership with the Legal team to define information security contractual requirements.
- Interact with customers, to demonstrate compliance with legal and contractual requirements.
Risk Management
- Audit risk assessment activity and determine mitigation strategies.
- Manage third-party and supply chain security risks.
Secure Development
- Work closely with engineering teams to:integrate security into the software development lifecycle,define secure coding standards andoversee code review processes.
Security Operations
- Lead incident response and disaster recovery planning.
- Oversee vulnerability management, penetration testing, and threat intelligence.
Policy & Awareness
- Develop and enforce security policies and standards.
- Deliver security awareness training across the organisation.
Requirements
Do you have experience in Software development?, * Degree in Computer Science, Cyber Security, or related discipline .
- 5+ years of experience in information security, including leadership roles.
- Professional certifications such as CISSP or CISM.
- Detailed understanding of GDPR.
- Strong knowledge of compliance frameworks (PCI DSS, PCI 3DS, SOC 2).
- Knowledge of the DRATA GRC platform.
- Experience in secure software development practices and cloud security.
- Strategic thinking and ability to align security with business goals.
- Excellent communication and stakeholder engagement skills.
- Strong analytical and problem-solving abilities.