> Markdown version of [/jobs/ext/3524401-information-security-senior-manager](https://www.wearedevelopers.com/jobs/ext/3524401-information-security-senior-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Senior Manager - **Company:** BDO - **Location:** London, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Security Management, Information Security Management System, National Institute of Standards and Technology Cybersecurity Framework, Information Technology, CIS Benchmarks - **Published:** October 2, 2026 - **Apply:** https://bdouk.wd3.myworkdayjobs.com/BDO_Careers/job/London/Information-Security-Senior-Manager_R21060 ## About the Role * Essential professional-services experience, with a strong understanding of client confidentiality, regulatory scrutiny, contractual assurance, partnership environments and proportionate risk management. * Demonstrable experience designing, documenting and maintaining enterprise information security controls and control frameworks. * Strong knowledge of control design and operating-effectiveness assessment, including control objectives, risks, evidence requirements, test procedures, sampling, deficiency evaluation and remediation tracking. * Experience creating structured, traceable and auditable control libraries that map policies, standards, risks, obligations and assurance evidence. * Strong working knowledge of ISO 27001 and relevant control or risk frameworks such as NIST CSF, NIST 800-53, CIS Controls or COBIT. * Ability to analyse complex technical and business information, identify root causes and translate findings into prioritised, practical recommendations. * Experience reporting control effectiveness, exceptions and residual risk to senior stakeholders, governance forums, clients, auditors or regulators. * Experience leading complex cross-functional security, assurance or remediation projects through influence rather than direct managerial authority. * Knowledge of relevant UK data protection, security and professional-services obligations. * Relevant professional certification such as CISSP, CISM, CISA, CRISC or ISO 27001 Lead Implementer/Lead Auditor is desirable. You'll be able to be yourself; we'll recognise and value you for who you are and celebrate and reward your contributions to the business. We're committed to agile working, and we offer every colleague the opportunity to work in ways that suit you, your teams, and the task at hand. ## Description Reporting to CISO the Information Security Senior Manager is a subject-matter role responsible for designing and maintaining a structured, documented and evidence-based ISO27001 information security management systems and professional services aligned controls framework across the firm. The role provides strong expertise in Information security risk management to ensure controls are appropriately designed, implemented, operated and demonstrably effective., * Design, maintain and continuously improve an information security controls framework aligned with the firm's strategy, risk appetite, policies, legislation, regulatory obligations, client commitments and recognised standards. * Develop and maintain information security policies and the supporting standards, procedures and guidance that form part of the firm's Information Security Management System. * Coordinate and evidence the annual review of the Information Security Management System, identify improvements, agree proportionate actions and monitor findings through to closure. * Plan, coordinate and support internal audits of compliance with ISO 27001 and related requirements, ensuring identified exposures and non-conformities are assessed, remediated and verified. * Define clear control objectives, requirements, ownership, evidence standards, compliance approaches and effectiveness criteria, ensuring traceability from risks, policies, legislation and standards to control implementation. * Lead compliance reporting and remediation initiatives, coordinating across Information Technology, Human Resources, Risk, Legal, Data Protection, Internal Audit and business functions. * Ensure partners and employees understand their information security obligations by developing practical guidance, communications and stakeholder engagement that embed controls into day-to-day business processes. * Provide authoritative information security advice and constructive challenge to control owners and stakeholders, involving relevant specialists where required. * Produce clear, concise reporting on control coverage, maturity, exceptions, effectiveness, remediation and residual risk for senior management, governance committees, clients, auditors and assurance providers. * Lead complex cross-functional projects within the role's area of expertise, establishing plans, managing dependencies and contingencies, and delivering high-quality outcomes through influence rather than direct line-management authority. Behaviours and attitude: * Demonstrates a quality mindset, strong technical expertise and diligent professional judgement when evaluating complex information security matters. * Builds trusted relationships across functions and uses evidence, reasoned argument and diverse viewpoints to influence outcomes without relying on formal authority. * Communicates complex control issues clearly and credibly, adapting the message for technical, operational, executive, client and assurance audiences. * Provides constructive challenge, remains composed in difficult situations and makes balanced recommendations based on risk, evidence and business context. * Plans and delivers complex work with clear priorities, contingencies, measurable outcomes and high-quality outputs. * Shares expertise proactively, supports the development of colleagues and contributes to an inclusive learning culture, without direct line-management accountability. * Champions continuous improvement by testing assumptions, analysing gaps and ensuring lessons learned are incorporated into future control design and operation.