Information Security Manager

BMW
UK
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Information Leak Prevention Identity and Access Management Information Security Management System IT General Controls (ITGC) Software Security Information Technology

Job description

Responsible to drive the maturity of existing security controls across multiple teams and in collaboration with others across business.

  • Responsible to drive the maturity of existing security controls across multiple teams and in collaboration with others across business.
  • Provide specialist advice and guidance to the business on information security issues.
  • Analyse metrics, implement assurance reviews, and closely monitor the businesses information risk exposure.
  • Advice and balance security risks against the other needs of the business and support IT colleagues in the removal and management of information security risks.
  • Recommend appropriate technical designs and support the appraisal of technical solutions ensuring alignment to the principles of ‘security by design’.
  • Identifying, developing, implementing and maintaining processes to reduce risks across the organisation through awareness training and communications campaigns.
  • Engage all areas of the business to ensure an end-to-end Information Security strategy.
  • Advise on and, where required, manage the transformation and improvement of BMW Financial Services UK and BMW Financial Services Ireland Information Security programmes.

Requirements

  • Bachelor’s Degree in Information Technology, Business Administration, Engineering or related field or suitable relevant experience.
  • Hands-on experience of information security functions in a fast-paced global organisation, mitigating critical security risks and implementation of security technologies, education and policies.
  • The role holder will have demonstrable project management experience preferably in an international environment.
  • Proven stakeholder Management skills and an ability to influence individuals and teams in areas where knowledge and understanding may be minimal.
  • Familiarity with Information Security industry standards/best practices and relevant regulations such as ISO27000, NIST and PCI.
  • Demonstrated expertise in Information Security and Third-Party Risk.
  • A broad understanding of the terminology, core principles, IT controls and best practices across key risk domains, including risk assessment methodology, identity and access management, network and infrastructure security, application security, data loss prevention, and incident management.
  • Information security industry certification (e.g. CISSP or CISM) is desirable.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on totaljobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:17 min

Governing enterprise IT as a global automotive CIO

Katrin Lehmann Katrin Lehmann +1 · Coffee With Developers

42 sec

Energy forecasts and resource demands of information technology

Marjolein Pordon · LIVE

1:30 min

The universal and shared team responsibility of software security

Julia Wilson Julia Wilson +1 · WWC 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

3:21 min

Introduction to automotive security and digital forensics

Martin Schmiedecker · LIVE

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

Videos

See all

Related articles

See all