> Markdown version of [/jobs/ext/2247570-information-security-manager](https://www.wearedevelopers.com/jobs/ext/2247570-information-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Manager - **Company:** Stewarts - **Location:** London, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Agile Methodology, Application Firewall, Remote Backup Services, Cyber Security, Domainkeys Identified Mail, Domain-Based Message Authentication Reporting and Conformance (DMARC), Multi-Factor Authentication, Identity and Access Management, Information Security Management, Network Security, Public Key Infrastructure, PRINCE2, Remote Access Technology, Security Information and Event Management, Firewalls (Computer Science), Information Technology, Vulnerability Analysis - **Published:** August 26, 2026 - **Apply:** https://www.collegerecruiter.com/job/2815047440-information-security-manager ## About the Role * Extensive experience in information security management, ideally within professional services environments. * Proven management capabilities, including team management and effective stakeholder engagement. * Hands-on expertise in ISO 27001 implementation and certification, from development through to successful audit. * Experience of successfully completing Cyber Essentials Plus audits and a solid understanding of UK GDPR requirements. * Demonstrated ability to manage third-party security relationships. * Strategic, pragmatic, and business-aligned approach to security risk management and decision-making. * Highly desirable certifications such as CISM, CISSP, or ISO 27001 Lead Implementer. Broad Technical Proficiency Across * Endpoint Security: EDR solutions and endpoint management platforms. * Microsoft 365 / Entra ID: Identity protection, Conditional Access, MFA, and Privileged Identity Management (PIM). * Security Monitoring & Operations: SIEM platforms and SOC processes. * Network Security: Firewalls, web application firewalls, and VPN technologies. * Encryption: PKI and data encryption for both data at rest and in transit. * Email Security: Mimecast and Exchange Online, Tessian plus SPF/DKIM/DMARC configuration. * Backup and Recovery Systems: On-premise and Cloud backup solutions * Experience of project management disciplines (eg: Prince2, Agile) are desirable. * Well organised, uses initiative, prioritises appropriately, applies self, shows attention to detail, manages own workload and meets deadlines * Demonstrates excellent communication and interpersonal skills (respectful, positive, articulate, professional and sympathetic) * Delivers helpful internal services with a "can do" approach, shows commercial awareness and represents the department/firm appropriately * Shares information and ideas * Accepts and follows instructions, listens, makes notes, questions appropriately, co-operates * Shows sound judgement and decision-making skills; acts within boundaries * Shows commitment, passion and enthusiasm * Is a respectful, reliable and supportive team player * Reflects the firm's culture. ## Description Information Security Manager - Stewarts We are looking for an Information Security Manager to join our IT team in London. Job Responsibilities * Develop and deliver the firm's information security strategy and roadmap. * Provide subject matter expertise and guidance on information security to partners and staff. * Lead and mentor a small team, fostering professional growth and development. * Lead the implementation and ongoing management of ISO 27001, including policy and control implementation and stakeholder engagement. * Own the information security risk management process, including risk assessment, and risk / information asset register maintenance. * Lead the development, implementation, and review of security policies, standards, and procedures. * Ensure compliance with ISO 27001 and Cyber Essentials Plus * Oversee third-party risk management, including onboarding/offboarding and ongoing due diligence. * Coordinate and respond to client audits and assurance activities. * Maintain awareness of the current cyber-risk landscape for the firm and factor into the annual strategic cyber-plan. Security Operations * Own and manage the relationship with the firm's Managed Security Operations Centre (SOC), acting as the primary point of contact, ensuring service levels are met, and coordinating incident response. * Oversee operational security including server and endpoint protection, M365 security, identity and access management, vulnerability assessments, patching, and system hardening. * Manage security monitoring activities and support business continuity and disaster recovery initiatives. * Monitor emerging threats advising the business on risk and required actions. * Renew the firm's Cyber Essentials Plus certification on an annual basis. Security Projects * Lead the delivery of security projects, ensuring they are completed on time, within scope, and aligned with the firm's strategic objectives. * Collaborate with project managers and business stakeholders to integrate security requirements into both IT and non-IT projects ensuring Secure by Design principles are embedded from the outset. * Work with cross-functional teams to identify, assess, and mitigate security risks in business initiatives. Stakeholder Engagement & Communication * Act as the primary point of contact for information security matters across the business. * Develop and deliver security awareness training for partners and staff. * Represent the firm in external security forums and with clients as required. * Prepare quarterly info. sec. management reports for the CIO and Executive Committee. Key Skills and Experience * Extensive experience in information security management, ideally within professional services environments. * Proven management capabilities, including team management and effective stakeholder engagement. * Hands-on expertise in ISO 27001 implementation and certification, from development through to successful audit. * Experience of successfully completing Cyber Essentials Plus audits and a solid understanding of UK GDPR requirements. * Demonstrated ability to manage third-party security relationships. * Strategic, pragmatic, and business-aligned approach to security risk management and decision-making. * Highly desirable certifications such as CISM, CISSP, or ISO 27001 Lead Implementer. Broad Technical Proficiency Across * Endpoint Security: EDR solutions and endpoint management platforms. * Microsoft 365 / Entra ID: Identity protection, Conditional Access, MFA, and Privileged Identity Management (PIM). * Security Monitoring & Operations: SIEM platforms and SOC processes. * Network Security: Firewalls, web application firewalls, and VPN technologies. * Encryption: PKI and data encryption for both data at rest and in transit. * Email Security: Mimecast and Exchange Online, Tessian plus SPF/DKIM/DMARC configuration. * Backup and Recovery Systems: On-premise and Cloud backup solutions * Experience of project management disciplines (eg: Prince2, Agile) are desirable. * Well organised, uses initiative, prioritises appropriately, applies self, shows attention to detail, manages own workload and meets deadlines * Demonstrates excellent communication and interpersonal skills (respectful, positive, articulate, professional and sympathetic) * Delivers helpful internal services with a "can do" approach, shows commercial awareness and represents the department/firm appropriately * Shares information and ideas * Accepts and follows instructions, listens, makes notes, questions appropriately, co-operates * Shows sound judgement and decision-making skills; acts within boundaries * Shows commitment, passion and enthusiasm * Is a respectful, reliable and supportive team player * Reflects the firm's culture. Seniority level * Mid-Senior level Employment type * Full-time Job function * Legal and Information Technology * Law Practice Location: London, England, United Kingdom ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Small, Secure, Interconnected: The next Internet Protocol](https://www.wearedevelopers.com/videos/100062-small-secure-interconnected-the-next-internet-protocol) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [UK Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/326-uk-business-culture-and-etiquette) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)