Information Security Manager
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
We’re looking for an Information Security / Governance, Risk & Compliance (GRC) Manager to lead enterprise-wide risk, governance, and assurance across a fast-growing B2B technology business.
This is a senior strategic position with responsibility spanning information security, governance, compliance, quality management, and corporate risk. You’ll define how governance is embedded throughout the organisation, ensuring risk is understood, owned, and managed effectively while supporting continued business growth.
Working closely with executive leadership, you’ll own the GRC roadmap, oversee certification programmes, strengthen security and compliance frameworks, and advise on emerging areas such as AI governance and sustainability. Key ResponsibilitiesGovernance, Assurance & Compliance
- Own major certification and assurance programmes including ISO 27001, ISO 9001, SOC 2 and other recognised frameworks.
- Lead audit planning and execution across multiple standards.
- Manage cyber insurance, regulatory compliance and third-party assurance activities.
- Ensure governance supports enterprise procurement, customer due diligence and contractual security obligations.
- Oversee wider organisational compliance initiatives including sustainability and corporate governance.
Customer Assurance & Commercial Support
- Act as the senior subject matter expert for information security, governance and compliance during enterprise sales opportunities.
- Support customer meetings, executive briefings and strategic partnerships.
- Provide governance and security guidance to Product and Engineering teams to ensure enterprise customer requirements are reflected in product development.
- Build confidence with customers through a strong, commercially focused security and compliance approach.
GRC Strategy & Leadership
- Define and continuously improve the organisation’s Governance, Risk & Compliance strategy and roadmap.
- Partner with executive leadership to establish and maintain the company’s risk appetite.
- Drive a governance-first culture where policies become part of everyday decision making rather than a compliance exercise.
AI, Privacy & Emerging Risk
- Own data protection governance across UK GDPR, EU GDPR and other applicable regulations.
- Maintain privacy frameworks including DPIAs, records of processing and international data transfer controls.
- Help shape AI governance, ensuring the responsible, secure and compliant adoption of AI technologies.
- Monitor changes in legislation, regulation and industry standards, translating them into practical business controls.
- Maintain compliance tooling, risk registers and governance reporting across the organisation.
Stakeholder Management
- Partner with Sales, Legal, Finance, HR, Engineering, Product and Operations teams.
- Work directly with auditors, regulators, insurers and enterprise customers.
- Present governance, risk and compliance updates to senior leadership and board-level stakeholders.
- Translate complex security and risk topics into clear, commercially relevant guidance.
Requirements
Successful candidates will bring strong experience across both security and governance disciplines, including: Security
- Strong understanding of cloud and SaaS security models.
- Experience managing security incidents and post-incident governance.
- Practical implementation of ISO 27001 and SOC 2 within engineering environments.
- Deep understanding of UK GDPR, EU GDPR and wider privacy regulations.
- Knowledge of AI governance, ethics and regulatory considerations.
Governance & Compliance
- Enterprise customer assurance and due diligence.
- Supplier governance and third-party risk management.
- ISO 9001 quality management systems.
- Corporate governance and organisational compliance.
- Risk management frameworks and policy development., You’ll ideally have:
- 5+ years’ experience leading Information Security, GRC, Risk or Assurance functions.
- Experience working within a SaaS, software or technology business.
- The ability to influence at executive and board level.
- Relevant certifications such as CISM, CISSP or ISO 27001 Lead Auditor/Lead Implementer (or be working towards them).
- Strong commercial awareness alongside excellent judgement.
- Outstanding communication skills with the ability to influence both technical and non-technical stakeholders.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.reed.co.ukGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What Are The Top Skills Required For Azure Developers?
IT Salaries in UK
Fully Remote Software Engineer Jobs
The 12 Best Jobs for Software Engineers