At a Glance
- Tasks: Lead cybersecurity efforts, manage risks, and enhance security awareness across the business.
- Company: Join a mission-driven company focused on simplifying financial decision-making for everyone.
- Benefits: Enjoy hybrid working, generous holidays, private healthcare, and personal development opportunities.
- Why this job: Be part of a creative, inclusive culture that values your unique skills and ideas.
- Qualifications: Prior experience in security roles and knowledge of risk management frameworks are preferred.
- Other info: We celebrate diversity and encourage you to bring your authentic self to work.
The predicted salary is between 48000 - 72000 £ per year.
Our purpose is to make great financial decision making a breeze for everyone, and that purpose drives us every day.
It’s why we’re on a mission to create an automated quoting engine, with the simplest of experiences, wrapped in a brand everyone loves!
We change lives by making it simple to switch and save money and that’s why good things happen when you meerkat.
We’d love you to be part of our journey.
The role is responsible for completing line 1 risk and control management covering aspects of the cybersecurity framework. The role will check technical data provided by the analysts and ensure it is accurate. Manage InfoSec 3rd party due diligence and report the risk from non-conforming vendors to the risk owners. Responsible for enhancing security awareness across the business and aligning it with new threats. Operate within the NIST framework and ensure standards remain aligned to InfoSec standards, with metrics reported regularly. The InfoSec Manager will serve as the point of escalation for analysts, providing reliable security advice and guidance to the business.
Everyone is welcome.
We have a culture of creativity. We approach our work passionately, improve constantly, and celebrate our wins at every turn. We are an inclusive workplace where employees are encouraged to bring their authentic selves. Everyone is welcome. Be you.
We’re interested in candidates with a range of skills, experiences, and ideas. You don’t need to tick all the boxes, but we’d love to hear what makes you great for this role.
Some of the great things you’ll do:
• Manage third-party due diligence reviews and identify security risks.
• Lead a team of analysts answering security queries from the business.
• Manage external third-party security requests.
• Deliver security awareness programs and campaigns.
• Oversee data management for monthly and quarterly MI reporting of NIST controls.
• Conduct initial cyber risk assessments and advise on risk mitigation.
• Manage data from security tools to assess threats and escalate issues as needed.
• Continuously report on cyber risks and control effectiveness.
What we’d like to see from you:
• Prior experience in a security role.
• Experience with third-party security due diligence.
• Knowledge of Risk Management Frameworks.
• Experience managing cyber metrics and interpreting raw data.
• Understanding of the NIST framework is preferred.
There’s something for everyone.
We’re a place of opportunity. You’ll have the tools and autonomy to develop your career, supported by a talented team.
Our benefits include a competitive salary, hybrid working, generous holiday allowance, private healthcare, an electric car scheme, paid development, wellbeing days, and CSR days. We’ve got you covered!
#LI-HL1
#J-18808-Ljbffr
Information Security Manager (FTC) employer: Compare the Market
Contact Detail:
Compare the Market Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Information Security Manager (FTC)
✨Tip Number 1
Familiarise yourself with the NIST framework and its application in cybersecurity. Understanding how it aligns with risk management will not only help you in interviews but also demonstrate your commitment to the role.
✨Tip Number 2
Network with professionals in the cybersecurity field, especially those who have experience in third-party due diligence. Engaging in discussions can provide insights into best practices and current trends that may come up during your interview.
✨Tip Number 3
Prepare to discuss specific examples of how you've managed security risks in previous roles. Highlighting your hands-on experience with cyber metrics and data interpretation will set you apart from other candidates.
✨Tip Number 4
Showcase your ability to enhance security awareness within an organisation. Think of creative ways you've previously engaged teams in security practices, as this aligns well with the responsibilities of the role.
We think you need these skills to ace Information Security Manager (FTC)
Some tips for your application 🫡
Understand the Role: Read the job description thoroughly to grasp the responsibilities and requirements of the Information Security Manager position. Highlight key skills such as risk management, cybersecurity frameworks, and team leadership in your application.
Tailor Your CV: Customise your CV to reflect your relevant experience in security roles, particularly focusing on third-party due diligence and risk management frameworks. Use specific examples that demonstrate your expertise in managing cyber metrics and interpreting data.
Craft a Compelling Cover Letter: Write a cover letter that showcases your passion for cybersecurity and your alignment with the company's mission. Mention how your skills can contribute to enhancing security awareness and managing risks effectively within the organisation.
Highlight Your Soft Skills: In addition to technical skills, emphasise your soft skills such as communication, teamwork, and problem-solving. These are crucial for leading a team of analysts and providing guidance across the business.
How to prepare for a job interview at Compare the Market
✨Understand the NIST Framework
Make sure you have a solid grasp of the NIST framework, as it’s crucial for the role. Be prepared to discuss how you've applied its principles in your previous positions and how you would implement them in this new role.
✨Showcase Your Risk Management Experience
Highlight your experience with risk management frameworks and third-party security due diligence. Be ready to provide specific examples of how you've identified and mitigated risks in past roles.
✨Prepare for Technical Questions
Expect technical questions related to cybersecurity and data management. Brush up on your knowledge of security tools and metrics, and be prepared to explain how you’ve used data to assess threats and report on control effectiveness.
✨Demonstrate Your Leadership Skills
As the role involves leading a team of analysts, be prepared to discuss your leadership style and experiences. Share examples of how you've successfully guided teams through challenges and fostered a culture of security awareness.