Information Security Manager
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+3 more
Job description
Hello, We are Recognise Bank; a modern business bank built to support the UK’s SMEs with tailored lending and savings solutions. Founded in 2017 by experienced business owners, we set out to challenge traditional banking by offering more flexibility, understanding, and practical support to help businesses thrive. Since receiving our banking licence in 2021, we’ve built a loyal customer base and a strong, diverse team that puts people first. Our vision is building stronger futures with bespoke financial solutions. We understand that no two financial needs are the same, which is why we work closely with UK SMEs and individuals to unlock potential others often overlook. Through smart, flexible lending and savings products, we’re here to build and grow stronger futures for lasting success. Our values shape how we work and grow together: Can do, will do: We take ownership, solve problems, and adapt as our customers’ needs evolve. Be brilliant: We show up with curiosity and energy, always striving for better. Do the right thing: We act with integrity, responsibility, and care in everything we do. Make a difference: We focus on impact, helping our customers, colleagues, and communities succeed. About the role The Information Security Manager owns and runs Recognise Bank’s 1st line technical security operation: the SIEM, EDR, vulnerability management, identity security and incident response. The role sits alongside the Information Security Officer, who owns 2nd line governance, risk and compliance, so that the bank has hands-on technical control and independent oversight working side by side. Key Responsibilities
- Own and run the SIEM, EDR and vulnerability management estate, driving detection, triage and remediation against agreed SLAs
- Manage identity, DLP and cloud security controls across Microsoft Entra ID, Purview, AWS and Azure, keeping the estate compliant and hardened
- Lead technical response, containment and recovery for security incidents, escalating material incidents to the Head of Technology and the Information Security Officer
- Investigate and resolve insider security events, escalating outcomes to the Information Security Officer for risk assessment and governance
- Manage the MSSP and MSP relationships on day-to-day technical security matters, escalating where needed
- Coordinate execution of the penetration testing programme, manage suppliers and drive remediation to closure
- Drive threat hunting and detection engineering to improve the bank’s proactive security posture beyond reactive alert response
- Own the Information Security roadmap and delivery of security improvements, partnering with the Information Security Officer on review, challenge and governance of the Information Security strategy and risk appetite prior to committee and Board submission
- Produce technical security metrics and reporting that support board, committee and regulatory requirements, partnering with the Information Security Officer to evidence audit and risk assurance
Corporate Responsibilities
-
Read and follow all relevant company policies and procedures
-
Adhere to all risk-related responsibilities applicable to your role, as set out in the Risk Management Policy
- Abide by all compliance and financial crime related policies, procedures and reporting obligations applicable to your role
- A Material Risk Taker for the bank you will need to act in accordance with regulatory expectations of a Certified individual
Requirements
- Relevant industry certification (e.g. CompTIA Security+, Microsoft SC-200) or equivalent demonstrable hands-on experience
- Proven hands-on experience in a SOC analyst, security engineer or technical security role, in either a senior or lead position and within financial services or another regulated sector; experience running vulnerability management programmes and handling technical incident response end to end
- Strong working knowledge of a SIEM platform; practical EDR/XDR experience; Microsoft 365 and Entra ID security controls (Conditional Access, PIM, Defender suite); scripting or automation (PowerShell or Python); network security fundamentals; cloud security in AWS and Azure
Desirable:
- CISSP, CISM, GIAC (GCIH, GCIA or GSEC), CREST, Tenable / Sentinel One / Google SecOps vendor accreditations
- Experience in a regulated UK financial services environment; MSSP / supplier management experience
- Google SecOps (Chronicle), Microsoft Defender suite depth, beyond the baseline EntraID knowledge, AWS security tooling such as Guard Duty, Cloud Security etc
About the company
£90,000 - £100,000 a year Why Join? At Recognise Bank, we’re building more than a bank - we’re creating a culture where people feel empowered to make a difference , supported to be brilliant with a can do will do attitude, and trusted to do the right thing . We believe that when our people thrive, so do our customers. That’s why we invest in an environment that reflects our values and supports your growth, flexibility, and wellbeing. Here’s what you can look forward to: Competitive Time Off - Generous annual leave plus bank holidays to rest, recharge, and enjoy life outside of work. Work From Anywhere - Up to 6 weeks per year to work remotely from anywhere in the world.* Learning & Development - Tailored training and support to grow your skills and achieve your professional goals. Hybrid Working - To support your work-life balance, we offer a hybrid working model with 3 days in the office and 2 days remote.** Private Medical
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.adzuna.co.ukGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
IT Salaries in UK
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Data Engineer Salary UK