Information Security Manager

LT Harper
Slough, UK
17 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Microsoft Windows Artificial Intelligence Software System Penetration Testing CompTIA Security+ Cyber Security Identity and Access Management Network Security Phishing Security Information and Event Management Software Vulnerability Management Information Security Management System

Job description

I’m supporting a growing FTSE-listed business that is looking to hire an Information Security Manager to play a central role in protecting its information assets across both business and property technology. This would suit someone who enjoys operating with breadth over depth: an all-rounder who is happy moving between governance, risk and compliance work and broader cyber security topics within a small, high-impact team.The roleReporting to the Head of Information Security, you will lead the development, implementation and management of the information security governance, risk and compliance programme, ensuring alignment with regulatory requirements and industry standards such as ISO 27001 and NIST. You will also engage credibly with the wider infosec team, challenge supplier technical proposals, and contribute to operational security activities where required.Key responsibilities include:Developing and maintaining information security policies, standards and procedures, and monitoring complianceCompleting security assessments for third party suppliers, assets and projects, and maintaining the supplier risk assessment processIdentifying and assessing information security risks, maintaining the risk register, and implementing risk mitigation strategiesEnsuring compliance with relevant laws and standards (e.g. GDPR, ISO 27001) and supporting internal and external auditsBuilding strong stakeholder relationships across the business and articulating the need for information security to technical and non-technical stakeholdersDelivering security awareness and training, including phishing tests, remediation training and course rolloutManaging the information security steering committee, including secretariat duties, minutes and actionsDeveloping a working understanding of the security technology stack (SIEM, email security, DLP, endpoint, identity, vulnerability management) sufficient to engage credibly with the teamCritically reviewing supplier technical proposals, architectures and security testing reports (e.g. SOC 2, penetration test reports)Supporting incident response and operational infosec activities as requiredMaintaining awareness of AI developments relevant to information security, supporting the AI governance framework, and identifying opportunities to leverage AI within the infosec functionWhat they are looking forRequired:Demonstrable experience in an information security role with significant GRC exposure, alongside working knowledge of broader cyber security disciplinesExperience of ISO 27001 ISMS implementation and management, and the certification processStrong Microsoft 365 skills, including familiarity with enterprise security toolingRisk management experienceExperience with third party risk management software (such as SureCloud, OneTrust or similar)Working understanding of common cyber security domains: network security, endpoint protection, identity and access management, vulnerability management and security testingPreferred:ISO 27001 or NIST framework experience, and ISO 27005 risk managementExposure to AI governance frameworks (e.g. NIST AI RMF) or developing AI use-case risk assessmentsExposure to property technologyExperience

Requirements

reviewing penetration test reports, SOC 2 reports or supplier security architecturesHands-on experience supporting incident response or security operationsDesirable accreditations: ISO 27001 Lead Auditor / Implementer, ISO 27005, CISSP, CISM or equivalent, and CompTIA Security+ or an equivalent foundational technical certification.The ideal candidate will have the technical curiosity to engage the wider infosec team on operational topics, a genuine interest in AI and its application to security, and a pragmatic mindset that recognises the balance between security and productivity.PackageSalary: £75,000Hybrid working, 4 days in the office (Central London)Full benefits packageThis would suit someone who wants to make a big impact in a small team, act as a trusted advisor across the business, and deliver real value by translating technical detail for senior, non-technical stakeholders.Please message me directly if you would like to discuss the role, or feel free to share with someone in your network.

Benefits & conditions

Information Security Manager (GRC)£75,000 Central London Hybrid, 4 days in office Permanent

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.apply4u.co.uk

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:16 min

Securing internal pod communication with network security policies

Marc Nimmerrichter · World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · World Congress 2026 Europe

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all