At a Glance
- Tasks: Manage and report on Information Security risks while developing policies and procedures.
- Company: Join AJ Bell, a fast-growing investment platform with a collaborative culture.
- Benefits: Enjoy 27-31 days holiday, pension schemes, bonuses, and personal development opportunities.
- Why this job: Make a real impact in protecting customers and enhancing their experience.
- Qualifications: 5+ years in Information Security, knowledge of frameworks like ISO27001, and strong communication skills.
- Other info: Hybrid working model with a focus on teamwork and career growth.
The predicted salary is between 36000 - 60000 ÂŁ per year.
We are now recruiting an Information Security GRC Manager to support the Senior Manager and Chief Information Security Officer in managing and reporting the Information Security Risks faced by Technology Services and Business teams in delivering AJ Bell’s systems and services. The Information Security GRC Manager will work with the business and the wider information security team to ensure the appropriate controls, policies and procedures are in place to protect AJ Bell in line with industry best practice and regulatory legislation. In addition, this role will support the coordination and response to activities affiliated with external/internal IT audits as well as due diligence exercises requested by our external business partners and those we perform on our suppliers.
The key responsibilities of the role are:
- Development and delivery of information security policy aligned to industry recognised frameworks (typically ISO27001/2)
- Exception to policy process management and reporting
- Management reporting on the status of Information Security and the security change programme.
- Partner with Business and Technology teams, to develop and track remediation plans for identified risks and issues.
- Supporting and developing the evaluation of the security posture for key Third Parties, to ensure that they are in line with the desired security posture required by AJ Bell.
- Undertaking risk profiling of AJ Bell’s information and technology assets
- Ensure that all duties are carried out with the aim of protecting customers and improving customer experience.
- Supporting and enabling the business to achieve its regulatory requirements, including consumer duty.
Technical skills
- Strong understanding and knowledge of Information Security risk management tools and techniques
- Experience of Information Security standards and frameworks
- Awareness and understanding of the Information Security threat landscape
- Awareness of Information Security solutions e.g. email / web gateways, SIEM, Endpoint protection etc.
- Strong understanding of IT General Controls frameworks
- Awareness of Operational Risk Management and Risk & Control Self-Assessment (RCSA) processes
Competence, knowledge and skills
- Experience working within recognised Information Security frameworks and best practices such as ISO27001, NIST etc.
- Minimum 5 years’ experience in an Information Security role gained in a financial services environment is preferred
- Self-motivated, professional, tenacious and enthusiastic
- Strong ownership of tasks, attention to detail and following through to conclusion
- Ability to challenge approach, strategy and implementation to ensure Information Security is consistently considered and improved
- Ability to work under own initiative to plan and communicate effectively with colleagues and customers
- Structured, self-starting, flexible and enjoy working in fast-paced environments
- Effective communication skills, both written and verbal
- Ability to plan, organise and follow through on assigned tasks and complete with little or no prompting from management
- Ability to learn and develop new skills and take on new challenges
- Excellent attention to detail
- Attained or working towards CISM certification
About Us
AJ Bell is one of the fastest-growing investment platform businesses in the UK offering an award-winning range of solutions that caters for everyone, from professional financial advisers to DIY investors with little to no experience. We have over 644,000 customers using our award-winning platform propositions to manage assets totalling more than £103.3 billion. Our customers trust us with their investments, and by continuously striving to make investing easier, we aim to help even more people take control of their financial futures. Having listed on the Main Market of the London Stock Exchange in December 2018, AJ Bell is now a FTSE 250 company. Headquartered in Manchester with offices in central London and Bristol, we now have over 1,500 employees and have been named one of the UK's “Best 100 Companies to Work For” for six consecutive years and in 2025 named a Great Place to Work®.
At AJ Bell you can expect a friendly working environment with a strong sense of teamwork, we have a great sense of pride in what we do, and this is reflected in our guiding principles.
What we offer:
- Starting holiday entitlement of 27, increasing up to 31 days with length of service and a holiday buy and sell scheme
- A choice of pension schemes with matched contributions up to 8%
- Discretionary bonus scheme
- Annual free share awards scheme
- Buy As You Earn (BAYE) Scheme
- Health Cash Plan – provided by Simply Health
- Discounted private healthcare scheme and dental plan
- Free gym
- Employee Assistance Programme
- Sick pay+ pledge
- Enhanced maternity, paternity, and shared parental leave
- Loans for travel season tickets
- Charitable giving opportunities through salary sacrifice
- Calendar of social events, including monthly payday drinks, annual Christmas party, summer party and much more
- Personal development programmes built around you and your career goals, including access to personal skills workshops
- Monthly leadership breakfasts and lunches
- Casual dress code
- Access to a range of benefits from our sponsorship deals
At AJ Bell, our people are the heart of our culture. We believe in building strong connections by working together. That’s why we offer a hybrid working model, where you’ll spend 3-4 days per week in the office. For new team members, the first 3 months will be spent full-time in the office to help you immerse yourself in our business and build valuable relationships with your colleagues.
AJ Bell is committed to providing an environment of mutual respect where equal employment opportunities are available to all applicants and all employees are empowered to bring their whole self to work. We do not discriminate on the basis of race, sex, gender identity, sexual orientation, age, pregnancy, religion, physical and mental disability, marital status and any other characteristics protected by the Equality Act 2010. All decisions to hire are based on qualifications, merit and business need.
If you like the sound of the above, or just want to know more about the company and the role, we’d love to speak to you.
Information Security GRC Manager in Salford employer: Aj Bell
Contact Detail:
Aj Bell Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Information Security GRC Manager in Salford
✨Tip Number 1
Network like a pro! Reach out to your connections in the industry, especially those who work at AJ Bell or similar companies. A friendly chat can sometimes lead to insider info about job openings or even a referral.
✨Tip Number 2
Prepare for the interview by researching AJ Bell’s values and recent projects. Show us that you’re not just another candidate; demonstrate how your skills align with our mission to protect customers and improve their experience.
✨Tip Number 3
Practice your responses to common interview questions, but keep it natural. We want to see your personality shine through, so don’t be afraid to share your passion for information security and how you can contribute to our team.
✨Tip Number 4
Follow up after your interview with a thank-you email. It’s a simple gesture that shows your enthusiasm for the role and keeps you fresh in our minds. Plus, it’s a great opportunity to reiterate why you’re the perfect fit for the Information Security GRC Manager position!
We think you need these skills to ace Information Security GRC Manager in Salford
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience with Information Security frameworks like ISO27001 or NIST. We want to see how your skills align with the role, so don’t hold back on showcasing your relevant achievements!
Showcase Your Experience: When detailing your work history, focus on your experience in financial services and any specific projects that demonstrate your ability to manage Information Security risks. We love seeing real-world examples of how you've tackled challenges in past roles.
Be Clear and Concise: Keep your application straightforward and to the point. Use bullet points where possible to make it easy for us to read through your qualifications and experiences. Remember, clarity is key in the world of Information Security!
Apply Through Our Website: We encourage you to submit your application directly through our website. It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it shows you’re keen to join our team at AJ Bell!
How to prepare for a job interview at Aj Bell
✨Know Your Frameworks
Make sure you’re well-versed in information security frameworks like ISO27001 and NIST. Brush up on how these frameworks apply to the role and be ready to discuss how you've implemented them in past positions.
✨Showcase Your Risk Management Skills
Prepare examples of how you've managed information security risks in previous roles. Be specific about the tools and techniques you used, and how they helped mitigate risks effectively.
✨Communicate Clearly
Effective communication is key in this role. Practice explaining complex security concepts in simple terms, as you’ll need to partner with various teams. Think about how you can convey your ideas clearly and confidently.
✨Demonstrate Your Initiative
AJ Bell values self-motivated individuals. Be ready to share instances where you took the initiative to improve security processes or policies. Highlight your ability to work independently and follow through on tasks without needing constant supervision.