> Markdown version of [/jobs/ext/1286878-information-security-manager](https://www.wearedevelopers.com/jobs/ext/1286878-information-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Manager - **Company:** CloudMargin - **Location:** London, UK - **Experience:** Expert - **Salary:** £101,594.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software as a Service, Cloud Computing Security, Cyber Security, Document Management Systems, Open Web Application Security, Phishing, Secure Coding, Information Security Management System, Atlassian Tools - **Published:** July 16, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5802867470 ## About the Role * 5+ years' experience in Information Security, Governance, Risk Management and/or Compliance roles in a technology / financial services setting * Demonstrable experience managing an ISMS in an ISO 27001:2022 aligned environment, including external audits and auditors * Managing budgets and suppliers * Exposure to securing SaaS or cloud-hosted platforms, including secure development practices (e.g. OWASP), infrastructure security and data protection * Experience responding to client security questionnaires, RFIs and RFPs, ideally using automation or managed tooling, * Detailed knowledge of the ISO 27001:2022 standard * Understanding of application and cloud security fundamentals (e.g. OWASP Top 10, secure SDLC) and the ability to translate these for development teams * Excellent administrative skills, including document management, audit management, reporting and presenting (Jira and Confluence beneficial) * Communication skills supporting diverse audiences from external parties to internal technical stakeholders * Process improvement and automation - comfortable using tools and AI to scale security operations * Commercial awareness, Relevant professional certifications are desirable but not required (e.g. ISO 27001:2022 Lead Implementer / Lead Auditor, CISSP, CISM, CCSP or cloud security certifications) ## Description As our Information Security Manager, you'll own the information security function. You will be the first point of contact for everything from ISMS governance to platform security. You'll run and evolve an established ISO 27001:2022-aligned programme with real scope to shape it, working directly with our CTO, VP of Engineering and commercial leadership. It's a hands-on role for someone ready to step up and build their reputation as a security leader., * Own and improve the ISMS and Risk Management Framework, including governance meetings, annual audits and policy/process documentation * Lead reviews of security policies and procedures, adapting them to business needs and generating new policies where required * Deliver and promote relevant security awareness training and security programs (e.g. phishing simulations) * Own responses to client and prospect RFIs, RFPs and security questionnaires * Partner with the Technology team to strengthen our SaaS platform's security posture, including secure development practices (e.g. OWASP), infrastructure security and data protection, and help developers understand their security responsibilities * Support the CTO and VP of Engineering in defining and maintaining technical security standards * Build scalable, proactive security processes, making use of tools and AI where appropriate ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers)