At a Glance
- Tasks: Lead cybersecurity strategies, manage incidents, and oversee security operations.
- Company: Join Pret, a fun and dynamic workplace focused on growth and learning.
- Benefits: Enjoy competitive salary, 33 days holiday, private healthcare, and free lunch.
- Why this job: Make a real impact in cybersecurity while working with passionate teams.
- Qualifications: 5+ years in cybersecurity, relevant degree, and certifications like CISM or CISSP required.
- Other info: Level 3 position with clear progression opportunities and no line management responsibility.
The predicted salary is between 65000 - 75000 £ per year.
People at Pret work hard, have fun, learn a lot and really grow. Right now, we’re looking for a passionate Cyber Security Manager to join us.
Job Purpose
The Cyber Security Manager role will manage the development, implementation, oversight and enhancement of the organisation’s cybersecurity controls to protect its information systems and data. The role will ensure that both on-premise and cloud infrastructure is appropriately secured and that the cybersecurity strategy is executed and maintained, both within technology projects and other business functions. This position reports to the Global Cyber Security Officer and involves leading an outsourced team of security professionals, identifying and managing vulnerabilities and risks, executing security roadmaps and responding to cybersecurity events and incidents that could contribute to a loss of data or system availability.
Relationships
This role will work closely with technical teams, operational teams, franchise partners and other central support teams alike, requiring a blend of hands-on technical work and strategic management to improve the organisation’s cybersecurity posture. Working closely with external suppliers and vendors, the role will lead an outsourced security operations team and ensure that cybersecurity tooling is operating effectively and aligned with business objectives.
Key Duties/Responsibilities
- Strategy & Planning
- Develop and implement cybersecurity strategies aligned with organisational goals and industry standards.
- Identify and deploy cybersecurity solutions that balance cost, risk, and organisational needs.
- Create and execute security roadmaps, ensuring alignment with Agile project delivery methodologies.
- Work with the Global Information Security Officer to participate in the design and architecture of secure systems, integrating security into the development lifecycle.
- Team Management
- Lead and manage an outsourced Security Operations Centre (SOC) team and Cyber Security Analysts.
- Collaborate with internal teams and external vendors to optimise cybersecurity operations.
- Compliance & Risk Management
- Plan and conduct annual PCI DSS compliance assessments in collaboration with qualified security assessors, maintaining and communicating cybersecurity risk registers to business stakeholders.
- Perform third-party risk assessments to evaluate vendor security postures and ensure contractual cybersecurity clauses are met.
- Coordinate internal and external security audits to maintain compliance and improve security posture.
- Technical Operations
- Configure and manage cybersecurity tools such as anti-virus, EDR, email security systems, firewalls, and IAM systems.
- Review and report on the effectiveness of existing cybersecurity tools and KPIs to both technical and non-technical audiences.
- Collaborate with infrastructure teams to ensure timely patching and mitigation of critical vulnerabilities.
- Incident Response
- Manage cybersecurity incidents from detection through to recovery, providing clear instructions to relevant teams and developing/enhancing incident response playbooks.
- Participate in resolving critical technical issues to drive swift incident resolution.
- Training & Policy Development
- Provide training on cybersecurity standards and best practices to various business functions.
- Develop and update policies, standards, processes, procedures, and technical controls to enhance cybersecurity resilience.
- Develop and implement security awareness programmes, including regular phishing simulations, to promote best practices and reduce human-related security risks.
- Threat Intelligence
- Conduct threat modelling and gap analysis of cybersecurity controls and processes, documenting findings and strategic improvements.
- Continuously identify emerging security threats and develop comprehensive mitigation strategies.
- Committee Participation
- Actively participate in the Information Security and Data Protection Committee, contributing to organisational security initiatives.
Person specification
- A minimum of 5 years’ experience in a cybersecurity related role, with experience of managing cybersecurity analyst roles or similar.
- BSc or MSc degree level qualification in Cybersecurity, IT or similar.
- Cybersecurity related certifications such as CISM or CISSP.
- Experience of managing and working with an outsourced SOC, and the ability to effectively communicate with and manage organisational vendors.
- Must have hands-on experience configuring a range of cybersecurity tooling and hardening cloud environments, particularly Microsoft Azure.
- Well-versed knowledge of cybersecurity and data protection frameworks including NIST, ISO27001 and DPA.
- Experience managing PCI DSS compliance for an organisation is preferred.
- Proficient at articulating technical cybersecurity concepts and risks to the business in a simple and effective manner, whilst advocating to do the right thing.
- A demonstrable passion for cyber security, infrastructure, and technology concepts.
- Strong business acumen and commercial awareness, able to deliver Cybersecurity proposals with confidence and enthusiasm.
- Diligent with a high attention to detail.
- Self-starter who can thrive with little oversight required and a security-driven mindset.
- Strong interpersonal skills to collaborate with other business departments and find pragmatic solutions to avoid over-restrictive security.
- Excellent time-management and organisational skills to simultaneously manage a variety of tasks, prioritise accordingly and meet dynamic deadlines.
- Able to thrive in a fast paced, regulated business with ambitious growth plans.
Pret Offers
- Competitive salary and annual bonus
- 33 days holiday a year including Bank Holidays
- Private healthcare
- Life assurance
- Pret pension scheme
- Season ticket loan
- Free lunch and drinks
- 50% discount in Pret shops worldwide
- Great reward and recognition events
- Legendary parties
About Progression
Supporting our teams to grow is really important to us, which is why we have a Levelling and Progression framework designed to show how you can work your way up career levels in our Support Centre, showcasing different qualities you need to be brilliant every step of the way. This role is a Level 3 position with no line management responsibility. The salary band for the role is £65,000 - £75,000 per year.
Cyber Security Manager employer: Pret A Manger
Contact Detail:
Pret A Manger Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Cyber Security Manager
✨Tip Number 1
Network with professionals in the cybersecurity field, especially those who have experience in managing outsourced Security Operations Centres. Attend industry events or webinars to connect with potential colleagues and learn about their experiences.
✨Tip Number 2
Stay updated on the latest cybersecurity trends and threats, particularly those relevant to cloud environments like Microsoft Azure. This knowledge will not only help you in interviews but also demonstrate your passion for the field.
✨Tip Number 3
Prepare to discuss specific examples of how you've successfully implemented cybersecurity strategies or managed incidents in previous roles. Use the STAR method (Situation, Task, Action, Result) to structure your responses.
✨Tip Number 4
Familiarise yourself with the compliance frameworks mentioned in the job description, such as PCI DSS and ISO27001. Being able to speak confidently about these frameworks will show your understanding of the regulatory landscape.
We think you need these skills to ace Cyber Security Manager
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in cybersecurity management, particularly any roles where you've led teams or managed outsourced operations. Use keywords from the job description to demonstrate your fit for the role.
Craft a Compelling Cover Letter: In your cover letter, express your passion for cybersecurity and detail how your skills align with the responsibilities outlined in the job description. Mention specific experiences that showcase your ability to manage cybersecurity strategies and lead teams.
Showcase Relevant Certifications: If you hold any cybersecurity certifications such as CISM or CISSP, make sure to prominently display these in your application. This will help establish your credibility and expertise in the field.
Highlight Technical Skills: Be sure to include any hands-on experience you have with cybersecurity tools and cloud environments, especially Microsoft Azure. Detail your familiarity with frameworks like NIST and ISO27001, as this is crucial for the role.
How to prepare for a job interview at Pret A Manger
✨Show Your Passion for Cyber Security
Make sure to express your enthusiasm for cyber security during the interview. Share specific examples of projects or initiatives you've been involved in that demonstrate your commitment to the field. This will help convey your genuine interest in the role and the company.
✨Understand the Company’s Cybersecurity Needs
Research Pret's current cybersecurity posture and any recent news related to their security practices. Being knowledgeable about their specific challenges and how you can contribute to improving their security strategy will set you apart from other candidates.
✨Prepare for Technical Questions
Expect to be asked technical questions related to cybersecurity tools, frameworks, and incident response. Brush up on your knowledge of NIST, ISO27001, and PCI DSS compliance, as well as your hands-on experience with security tools, especially in cloud environments like Microsoft Azure.
✨Demonstrate Leadership and Team Management Skills
Since the role involves leading an outsourced SOC team, be prepared to discuss your leadership style and experiences managing teams. Highlight your ability to collaborate with both technical and non-technical stakeholders, showcasing your interpersonal skills and strategic thinking.