> Markdown version of [/jobs/ext/3032493-senior-information-security-manager](https://www.wearedevelopers.com/jobs/ext/3032493-senior-information-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information Security Manager - **Company:** Careers and Enterprise Company - **Location:** London, UK (Remote available) - **Experience:** Expert - **Salary:** £60,000.0 - £65,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Security Management, Microsoft Office, Information Technology - **Published:** September 23, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5893861293 ## About the Role You may already be leading information security governance in a smaller organisation, or you may have built strong experience as a key member of a larger information security or governance team. We are looking for someone with at least three years' experience, ideally five, working in an ISO 27001-certified environment. A CISSP or similar professional or academic qualification is preferred, and an understanding of quality management, or a willingness to develop it, would be an advantage. * A minimum of 3 years of work experience in an information security governance role within an ISO 27001 certified environment * ISO 27001 Lead Implementer or Lead Auditor certification * CISSP, or a degree or equivalent level 6 or above qualification with an information security focus, or computer science or similar including relevant security modules Skills and core competencies: * Good knowledge of current information security threats and best practices for information security management and governance * Delivery focused with excellent organisational skills and attention to detail * Capable of building and maintaining strong working relationships across teams and working through ambiguity * Motivated to find practical solutions, yet willing to escalate significant risk * Confident user of Microsoft tools and comfortable developing skills for use of new technologies Please note that a basic DBS check is required for this role before any offer of employment can be confirmed. ## Description Working Arrangements: This role can be home-based, with occasional attendance at the London office required, or performed on a hybrid basis (depending on your location). This is a permanent position (37.5 hours per week) although we are open to excellent applicants seeking part-time work (i.e. 4 days a week, 0.80 FTE), The Careers & Enterprise Company, a non-profit organisation with a social purpose, is looking for a knowledgeable and committed Senior Information Security Manager to join its small Compliance Team. Reporting to the Head of Compliance (CEC's Data Protection Officer), you will lead CEC's ISO 27001-certified information security management system, strengthen processes, and help shape policy. In this role, you will play a key part in ensuring information risk is managed effectively, overseeing security governance and standards, conducting audits and monitoring, and ensuring policies and processes continue to improve. Your work will be essential in providing assurance that the young people's data entrusted to CEC is secure. You may already be leading information security governance in a smaller organisation, or you may have built strong experience as a key member of a larger information security or governance team. We are seeking a candidate with broad experience across information security and governance, including most of the following: identifying and assessing information risk, managing controls, carrying out internal and third-party audits, improving processes, developing training and guidance for staff, managing and reviewing incidents, and contributing to policy development. Because CEC works with children's data and provides digital tools for careers education, we are especially interested in candidates who are motivated by social purpose who understand the importance of security governance in this context. An appreciation of data protection, tech ethics, and safeguarding will be important in helping you thrive here. Technical skills and experience matter, but so do your values. We are passionate about helping young people take their best next step, and keeping their information safe is fundamental to that mission. This is a fast-moving environment, so you will need to be comfortable working through ambiguity, building strong partnerships across teams, finding practical solutions, and confidently raising significant risks when needed. The key responsibilities of this role are to oversee information security standards by managing and continually improving CEC's ISO 27001-certified Information Security Management System, leading business continuity management for information and technology risks, and supporting the organisation's development of a proportionate quality management approach, including work towards ISO 9001 certification. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [UK Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/326-uk-business-culture-and-etiquette) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)