Information Security Manager

Hays plc
Salisbury, UK
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
£60,000.0 - £65,000.0
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Cyber Security Data Governance Microsoft Office Network Architecture Systems Development Life Cycle Phishing Mod Security Software Vulnerability Management

Job description

I am looking for an Information Security Manager to join a great defence organisation based in Wiltshire. You’ll be walking into a strong position, being that there’s already a good setup in place with ongoing upgrades and transformation across the business, especially within IT. The role responsibilities:

  • Own and manage the Information Security requirements and compliance obligations.
  • Develop, maintain and deliver the Information Security strategy, plans, policies, processes and best practices.
  • Act as subject-matter expert for all Information Security matters, engaging with internal and external stakeholders (including SIRO, MoD security representatives and accreditors).
  • Ensure compliance with Security Operating Procedures (SyOps) across all environments, escalating non-compliance where appropriate.
  • Manage and maintain appropriate Information Security controls and tooling.
  • Define Information Security awareness and training requirements, working with Learning & Development to ensure suitable content and completion.
  • Line manage and develop the IT Security Officer, providing guidance, coaching and performance support.

Requirements

  • Strong demonstrable experience of IT and cyber governance, compliance, risk, and security within enterprise IT environments.
  • Strong, in-depth understanding of information and cyber security.
  • Proven experience defining and delivering Information Security best practice.
  • Experience leading Information Security initiatives, including awareness programmes, training and phishing simulations.
  • Good technical understanding of information security, including network architecture, SDLC, penetration testing, DLP tools, patching and vulnerability management.
  • Working knowledge of National Cyber Security Centre (NCSC) guidance and best practice.
  • Understanding of data governance, cyber security and data protection principles.
  • Experience working with security audits and assurance activities.
  • Strong Microsoft Office skills.
  • Full UK driving licence

Desirable:

  • At least one of the following, ideally 2 - CISM / CISA / CIPT / ISO27001 Lead Auditor
  • Experience working in a MoD restricted environment and knowledge of MoD security standards.
  • Familiarity with the NIST/ CSM V4 framework.

Benefits & conditions

  • Salary of between £60k-£65k
  • 25 days annual leave + bank holidays - additional gained with service
  • Hybrid working 2 days just outside of Salisbury per week, ideally
  • Up to 8% employer pension contribution
  • And more!

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on careerjet.co.uk

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · WWC Europe 2026

Videos

See all

Related articles

See all