> Markdown version of [/jobs/ext/3277542-information-security-manager](https://www.wearedevelopers.com/jobs/ext/3277542-information-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Manager - **Company:** Context Recruitment Limited - **Location:** Birmingham, UK - **Salary:** £156,000.0 - £169,000.0 - **Contract:** Temporary contract - **Skills:** Microsoft Windows, Software System Penetration Testing, Microsoft Azure, Cyber Security, Databases, Information Security Management, PCI Data Security Standards, Information Technology Security Auditing, Software Vulnerability Management, Multitopology Routing Configuration, Cyber Threat Analysis, Information Technology, SolarWinds (Software), Patch Management, Servicenow - **Published:** September 9, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5876096447 ## About the Role * Previous experience working in a Cyber Security Manager, Information Security Manager, Cyber Risk Manager, Cyber Threat Manager, IT Security Manager or similar role * Strong experience spanning both information security strategy/framework management and oversight of technical security controls * Experience setting up, running and/or managing SOC services, including third-party SOC providers * Strong cyber incident management experience, including coordinating technical response and remediation * Extensive knowledge of security standards and frameworks including ISO 27001 and NIST * Experience assessing an organisation against security standards, identifying gaps and delivering remediation plans * Extensive experience with GDPR, data protection and relevant security legislation/regulatory frameworks * Knowledge of security assessment methodologies including threat modelling, controls assessments and risk assessments * Experience across vulnerability management, penetration testing, threat intelligence, incident playbooks and patch management * Solid understanding of IT infrastructure fundamentals including networks, operating systems, databases, Azure and Microsoft 365 * Experience with Rapid7, Sophos MTR, SolarWinds and ServiceNow would be highly advantageous * Exposure to PCI DSS and NIS would also be beneficial * Excellent stakeholder management and reporting skills * Relevant security qualifications such as CISSP, CRISC, CISM or Security+ are highly desirable The successful candidate will need to be comfortable working across both the strategic and operational sides of information security, with the ability to engage senior stakeholders while maintaining sufficient technical depth to oversee security controls, incidents and third-party security services. ## Description IT Information Security Manager sought by a well-known, public-facing organisation operating across a complex and critical transport environment, providing services to hundreds of thousands of customers. As part of a Critical National Infrastructure environment, the IT Information Security Manager will play a crucial role in the day-to-day management of the technical cyber security landscape, SOC services and wider information security management. Reporting to the Head of IT and managing an IT Security Operations Engineer, this is a hands-on leadership role with responsibility for ensuring appropriate cyber security controls are in place, managing security risk and incidents, and maintaining ongoing compliance with relevant regulatory frameworks and industry standards. Key Responsibilities * Work with the Head of IT to create, maintain and deliver a robust Cyber Security Roadmap to minimise organisational risk * Develop and maintain the Information Security Strategy, security policies and procedures * Provide day-to-day oversight of the technical cyber security environment and associated security controls * Manage the organisation's third-party SOC service, ensuring effective monitoring, escalation and response * Take ownership of cyber security incidents, coordinating prompt technical response, remediation and mitigation * Embed Security by Design principles across technology projects and initiatives * Drive a strong culture of IT and cyber security awareness and responsibility across the organisation * Conduct ongoing security threat, risk, capability and maturity assessments * Manage vulnerability management, penetration testing schedules, remediation activities and threat intelligence * Maintain and develop incident management processes and security playbooks * Conduct and respond to security audits and support ongoing regulatory and standards compliance * Support the implementation and ongoing management of ISO 27001, including gap analysis and remediation * Oversee areas including patch management, PCI DSS, NIS, GDPR and data protection * Engage and manage specialist third-party security providers across areas such as penetration testing, forensic analysis and security auditing * Provide clear security reporting to senior stakeholders ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) ## Related Articles - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)