Information Security Manager

Keolis Amey Docklands 2025 Limited
London, UK
about 1 month ago

Role details

Contract type
Franchise
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Software System Penetration Testing Cyber Security Information Security Management PCI Data Security Standards Systems Integration Software Vulnerability Management Information Security Management System Cyber Threat Analysis Operational Systems

Job description

We’re looking for an experienced Information Security Manager to lead our cyber security function, ensuring the organisation remains resilient against evolving threats while maintaining compliance with regulatory and franchise obligations., Reporting to the Head of IT and Information Security, you’ll be responsible for leading KAD’s Information Security function and managing our cyber security governance, risk and compliance activities.

You’ll own our Information Security Management System (ISMS), lead cyber assurance across major business and infrastructure projects, manage security incidents, oversee regulatory compliance and provide expert cyber security advice to senior leaders, clients and regulators.

Leading a small specialist team, you’ll combine strategic leadership with hands-on technical expertise to help safeguard one of London’s critical transport networks., * Lead and continually improve KAD’s Information Security Management System (ISMS)

  • Own compliance with ISO 27001, NIS Regulations, Cyber Essentials, PCI DSS and franchise cyber obligations
  • Lead cyber risk management, governance and security assurance activities
  • Manage cyber security incidents, investigations, recovery and regulatory reporting
  • Provide security assurance for new infrastructure, rolling stock and technology projects
  • Oversee vulnerability management, penetration testing and technical security controls
  • Lead internal and external audits and certification activities
  • Manage supplier cyber security assurance and third-party risk
  • Provide cyber risk reporting and advice to senior leadership, clients and regulators
  • Lead, develop and mentor the Information Security team
  • Promote a strong cyber security culture across the organisation

Requirements

  • Significant experience leading Information Security within a regulated or operationally critical environment
  • Professional certification such as CISSP, CISM or CISA
  • ISO/IEC 27001 Lead Implementer or Lead Auditor certification
  • Proven ownership of a live ISO 27001-certified Information Security Management System
  • Experience maintaining compliance with NIS Regulations, Cyber Essentials and PCI DSS
  • Strong knowledge of cyber security governance, risk management and technical security controls
  • Experience managing cyber incidents and regulatory reporting
  • Experience leading cyber security assurance for projects and system integration
  • Strong stakeholder management skills with experience working with senior leaders, clients and regulators
  • Proven experience leading and developing Information Security or GRC teams, * Rail, transport or critical infrastructure experience
  • Operational Technology (OT) security experience
  • Experience working with government regulators or Competent Authorities
  • Knowledge of UK GDPR and Data Protection
  • Experience within franchise or concession-based environments

Benefits & conditions

Pulled from the full job description

  • Free or subsidised travel
  • Employee discount
  • Employee assistance programme
  • Company pension
  • Season ticket loan, * Free travel on the TfL network for you and a nominated household member.
  • 75% discount on National Rail season tickets.
  • Interest-free season ticket loan.
  • Pension scheme with up to 10% employer contribution.
  • Access to Perkbox, Doctor Care Anywhere virtual GP, and Employee Assistance Programme.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on uk.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

3:00 min

Designing data ingestion architecture with system integration

Eldert Grootenboer +1 · WWC 2023

41 sec

Introducing the blockchain operating system as a platform layer

Andrej Šarić · WWC 2023

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

Videos

See all

Related articles

See all