> Markdown version of [/jobs/ext/1461902-information-security-manager-risk-management](https://www.wearedevelopers.com/jobs/ext/1461902-information-security-manager-risk-management). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Manager - Risk Management - **Company:** Babcock International - **Location:** Portsmouth, UK - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Information Systems Security Architecture Professional - **Published:** July 28, 2026 - **Apply:** https://jobs.babcockinternational.com/talentcommunity/apply/1419774133/?locale=en_GB ## About the Role * Significant experience in Information Security, Cyber Security, Risk Management or Governance roles. * Experience operating enterprise risk management processes. * Strong understanding of cyber risk assessment methodologies, information security governance, security controls and assurance practices. * Experience developing risk treatment and remediation plans within complex organisations. * Ability to communicate technical security issues in clear business risk language and present findings to senior stakeholders., * Relevant professional experience demonstrating expertise in information security, cyber security or risk management. Advantageous: * Certified Information Systems Security Professional (CISSP). * Certified Information Security Manager (CISM). * Certified in Risk and Information Systems Control (CRISC). * Equivalent information security, governance or risk management qualifications. Security Clearance The successful candidate must be able to achieve and maintain Standard (BPSS) and Security Check (SC) security clearance for this role. ## Description As Information Security Manager - Risk Management, you'll play a critical role in strengthening cyber resilience across a global organisation that supports defence, aerospace and engineering programmes of national importance. This is an exciting opportunity to lead the development and continuous improvement of information and cyber security risk management practices, helping to protect critical services, infrastructure and sensitive information. Working across the business, you'll collaborate with senior leaders, project teams and technical specialists to ensure cyber and information security risks are effectively identified, assessed and managed. Your expertise will influence strategic decision-making, support regulatory compliance, and contribute to the delivery of Babcock's wider cyber security strategy. Day-to-day you'll be responsible for: * Leading the identification, assessment and management of cyber and information security risks across the organisation. * Developing and continuously improving the cyber security risk management framework, policies and governance processes. * Partnering with business leaders, project teams and technical specialists to ensure effective risk treatment and informed decision-making. * Presenting risk insights, recommendations and assurance reporting to senior stakeholders. * Supporting security assurance activities and ensuring alignment with regulatory, contractual and business requirements This role is full time, 37.5 hours per week and can be based at any of our main UK locations. Hybrid working arrangements are available. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Make it simple, using generative AI to accelerate learning](https://www.wearedevelopers.com/videos/969-make-it-simple-using-generative-ai-to-accelerate-learning) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Don’t shoot yourself in the foot.](https://www.wearedevelopers.com/videos/580-don-t-shoot-yourself-in-the-foot) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [UK Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/326-uk-business-culture-and-etiquette) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Guide for Expats Living in the UK](https://www.wearedevelopers.com/magazine/355-guide-for-expats-living-in-the-uk)