> Markdown version of [/jobs/ext/2816266-senior-information-security-manager](https://www.wearedevelopers.com/jobs/ext/2816266-senior-information-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information Security Manager - **Company:** Nscale Ltd. - **Location:** London, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Access Control List, Artificial Intelligence, Cloud Computing Security, Computer Clusters, Cyber Security, Data Centers, Intrusion Detection and Prevention, Phishing, Security Information and Event Management, Software Vulnerability Management, Information Security Management System, HybridCloud, Kubernetes, Network Server - **Published:** September 10, 2026 - **Apply:** https://www.collegerecruiter.com/job/2840575918-senior-information-security-manager ## About the Role * 5+ years in information or physical security management within a data centre, cloud, or MSP environment. * Deep familiarity with ISO 27001, SOC 2, NIST CSF, and Cyber Essentials Plus frameworks. * Experience leading or supporting audits and external assessments. * Strong understanding of incident response, vulnerability management, and access control processes. * Excellent documentation, communication, and stakeholder management skills. * Hands-on with GRC tooling. * Experience with GPU/HPC or cloud infrastructure security. * Familiarity with ISO 22237 (data-centre design & operations). * Knowledge of Kubernetes, container security, and hybrid cloud architectures. * Familiarity with Darktrace, Tenable, Checkpoint Harmony, and Exabeam SIEM. * Security certifications (CISSP, CISM, ISO 27001 LA/LI, CompTIA Sec+, or similar). ## Description We are seeking a Senior Information Security Manager to work closely with the Head of Information Security in building and managing Nscale's end-to-end security framework cross physical, technical, and organisational domains. You'll be hands-on, execution-focused, and comfortable working in a complex environment that spans hyperscale GPU clusters, critical infrastructure, and compliance programmes (SOC 2 Type II, ISO 27001/17/18, Cyber Essentials Plus, ISO 22301, and ISO 22337). This role will directly support ongoing certification, audit readiness, and incident response initiatives, while driving operational maturity across all Nscale sites and systems. This role requires UK government security clearance up to DV., * Support ongoing delivery of ISO 27001, ISO 27017/27018, SOC 2 Type II, Cyber Essentials Plus, and ISO 22301 frameworks. * Maintain the Information Security Management System (ISMS), risk register, and control evidence for internal and external audits. * Support third-party risk management (TPRM) ensuring supplier compliance and onboarding reviews. * Develop and track KPIs/KRIs for security operations and compliance health. Operational Security * Oversee vulnerability management, EDR posture, and security incident workflows in partnership with or MSSPs. * Support incident detection, triage, investigation, and root-cause analysis. * Own operational runbooks for containment, eradication, and recovery procedures. * Review access control lists, privileged-user logs, and infrastructure security baselines. * Maintain asset inventory, patch cadence, and configuration compliance (servers, workstations, and Kubernetes workloads). Physical & Data Centre Security * Support the physical security programme at all Nscale data centres, ensuring alignment with ISO 27001 Annex A.11 and ISO 22237. * Maintain visitor management and access audit trails, assisting with incident reviews and compliance documentation. Awareness & Culture * Support security awareness and phishing simulation programmes. * Develop clear communications and training materials to reinforce security accountability across teams. Continuous Improvement * Contribute to architecture reviews, change-control boards, and project assessments. * Identify and implement automation opportunities to reduce manual compliance and reporting overhead. * Track and report on control effectiveness, audit findings, and remediation progress to senior leadership. ## Related Videos - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Kubernetes Security - Challenge and Opportunity](https://www.wearedevelopers.com/videos/412-kubernetes-security-challenge-and-opportunity) - [Instant KAI Sandboxes with vCluster: Multi-Tenant, Multi-Scheduler GPU Sharing](https://www.wearedevelopers.com/videos/100333-instant-kai-sandboxes-with-vcluster-multi-tenant-multi-scheduler-gpu-sharing) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Learning Kubernetes made easy with KubeCampus](https://www.wearedevelopers.com/magazine/348-learning-kubernetes-made-easy-with-kubecampus) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)