At a Glance
- Tasks: Lead our Information Security and Data Protection initiatives while collaborating with diverse teams.
- Company: Join the Focusrite Group, a leader in music technology with a commitment to innovation.
- Benefits: Enjoy flexible working, private healthcare, and exciting company events.
- Other info: Embrace a culture of diversity and inclusion while advancing your career.
- Why this job: Make a real impact on security and privacy in a dynamic tech environment.
- Qualifications: Experience in Information Security and Data Protection, with a passion for learning.
The predicted salary is between 60000 - 85000 £ per year.
We’re looking for an Information Security Compliance Specialist to take ownership of our Information Security, Data Protection, and AI Governance programmes across the Focusrite Group. You will be the operational owner of our Information Security and Data Protection (ISDP) framework informed by ISO 27001 (ISMS), ISO 27701 (PIMS), Cyber Essentials and NIST CSF keeping us aligned to those standards and ready for certification and audit.
Working alongside development, IT, and business teams, you will advise on security and privacy requirements for new and changing systems, ensuring appropriate controls are designed in, evidenced, and verified after implementation. You will also own the Group’s response to emerging risks in AI, translating evolving regulation (EU AI Act, UK AI principles, ICO guidance) into practical governance.
About You
Several years’ experience in Information Security and Data Protection, with a good understanding of IT systems, web operations, cloud platforms, and secure coding practices (including OWASP). Comfortable engaging at all levels of the organisation and externally, with the gravitas to influence security and privacy outcomes and reduce the impact of change. The position requires providing support and advice to all parts of the Group on Information Security and Data Protection.
Responsibilities
- Own the Information Security and Data Protection Framework and its documentation, and advise IT, development, and business teams on security requirements.
- Run the Business Approved Tools process (including assessment of AI tools, vendors, and use cases), own designated Information Security tools, and conduct supplier audit assessments.
- Own certification readiness for Cyber Essentials and lead new certification efforts as the business requires.
- Monitor cyber threats and translate them for the business, own the incident management process (including phishing response and simulation exercises), and manage vulnerability scans and penetration testing (including external Red/Purple/Blue Team engagements).
- Conduct risk assessments across products, systems, and processes; own the Information Security and Data Protection risk register, contributing to the Group Risk Management process; and maintain and test the Business Continuity Plan (BCP).
- Own the AI Governance framework, AI system inventory, and alignment with ISO 42001, NIST AI RMF, and the EU AI Act where appropriate.
Data Protection Compliance
- Handle Data Subject Rights requests (Subject Access, erasure, rectification, restriction, objection, portability, and rights relating to automated decision‑making) and run Data Protection Impact Assessments (DPIAs).
- Maintain the Records of Processing Activities (RoPA) under Article 30 for controller and processor activities, the lawful basis register, consent records, and Legitimate Interest Assessments (LIAs).
- Operate Privacy Notices and Cookie Tools (OneTrust), and advise on PECR and e‑privacy compliance including direct marketing and electronic communications.
- Help product managers and developers embed Privacy by Design, and design and deliver Data Protection training and awareness across the Group.
- Own the retention schedule and deletion/anonymisation processes, and own personal data breach handling (including detection triage, 72‑hour ICO/EU supervisory authority notification, data subject notification where required, and the breach register).
- Manage processor and sub‑processor governance (Article 28 due diligence, Data Processing Agreements, processor register) and international data transfers (SCCs, the UK IDTA/Addendum, and Transfer Risk Assessments).
Change Management
- Review and provide security and data protection sign‑off on changes to systems, products, and processes.
- Participate in the Change Advisory Board (CAB) and ensure security and privacy risks are assessed before changes are approved.
- Own change management procedures relating to Information Security and Data Protection, ensuring evidence is captured for audit.
- Ensure security and privacy requirements are embedded in the SDLC and release processes, working with development and operational teams.
- Track and report on the security impact of significant business, technology, and organisational change initiatives.
Compliance and Audits
- Generate monthly compliance and activity reports and other reports as required by senior management.
- Review Financial System compliance activities; perform internal Information Security audits; perform internal Data Protection audits.
- Be the key contact for any IT / Data Protection related audits by external bodies, ensuring requested data is supplied, complete, and accurate; take ownership of any related audit issues; generate audit support documents.
You will be expected to keep up to date with developments in the security, privacy, and AI regulatory landscape, translating these into practical actions for the Group. We understand that not all candidates will have in depth experience of all these elements, so we welcome applications from candidates who meet most of the criteria and have a desire to learn the rest.
Benefits
Flexible/hybrid working, company pension, life insurance, private healthcare, Health Cash Plan, enhanced Maternity and Paternity pay, employee purchase scheme, group bonus scheme, company music events, off‑site company parties and free lunch in the canteen. Company training sessions and personal development are encouraged.
Equal Opportunity Statement
As an equal opportunity employer, the Focusrite Group is committed to Diversity and Inclusion. The group mission is to cultivate an equitable culture, internally and externally, where all people feel they are welcome, safe and positively represented.
Information Security & Data Protection Manager in High Wycombe employer: ADAM Audio GmbH
At Focusrite Group, we pride ourselves on being an exceptional employer, offering a dynamic work culture that champions flexibility and personal development. With a strong commitment to diversity and inclusion, our employees enjoy comprehensive benefits including private healthcare, enhanced parental leave, and opportunities for continuous training, all while working in a collaborative environment that values innovation and security in the rapidly evolving landscape of information technology.
StudySmarter Expert Advice🤫
We think this is how you could land Information Security & Data Protection Manager in High Wycombe
✨Tip Number 1
Network like a pro! Reach out to folks in the industry on LinkedIn or at events. A friendly chat can open doors that a CV just can't.
✨Tip Number 2
Prepare for interviews by researching the company and its culture. Tailor your answers to show how you fit into their world, especially around security and data protection.
✨Tip Number 3
Show off your skills! Bring examples of past projects or challenges you've tackled in information security. Real-life stories make you memorable.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who take that extra step!
We think you need these skills to ace Information Security & Data Protection Manager in High Wycombe
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Information Security & Data Protection Manager role. Highlight relevant experience and skills that align with the job description, especially around ISO standards and data protection compliance.
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how your background makes you a great fit for our team. Don’t forget to mention any ongoing training or certifications!
Showcase Your Achievements:When detailing your experience, focus on specific achievements rather than just duties. Use metrics where possible to demonstrate your impact in previous roles, especially in areas like risk management and compliance.
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands and shows us you’re serious about joining our team!
How to prepare for a job interview at ADAM Audio GmbH
✨Know Your Standards
Familiarise yourself with ISO 27001, ISO 27701, Cyber Essentials, and NIST CSF. Be ready to discuss how these frameworks apply to the role and share examples of how you've implemented or adhered to these standards in your previous positions.
✨Showcase Your Technical Savvy
Brush up on your knowledge of IT systems, web operations, and secure coding practices like OWASP. Be prepared to explain how you would advise teams on security requirements for new systems and how you’ve handled similar situations in the past.
✨Demonstrate Your Communication Skills
This role requires engaging with various levels of the organisation. Practice articulating complex security concepts in simple terms. Think of examples where you've influenced security outcomes or educated others about data protection.
✨Stay Updated on Regulations
Keep abreast of the latest developments in AI regulations and data protection laws. Be ready to discuss how you would translate these into practical governance for the company, showing your proactive approach to emerging risks.