At a Glance
- Tasks: Lead security initiatives and collaborate on product development to ensure robust security practices.
- Company: Join a forward-thinking tech company focused on innovation and security.
- Benefits: Attractive salary, flexible working options, and opportunities for professional growth.
- Other info: Dynamic team environment with a focus on mentorship and career advancement.
- Why this job: Make a significant impact on product security while working with cutting-edge technologies.
- Qualifications: 15+ years in information security with expertise in secure development and GRC.
The predicted salary is between 80000 - 100000 € per year.
We are seeking an experienced professional to collaboratively lead our Governance, Risk, and Compliance (GRC) initiatives along with Secure Software Development, and serve as a security interface for customer engagements. This role requires a strategic contributor who will work closely with Information Security and other senior leadership to embed security throughout the product development lifecycle, while managing security requirements in customer contracts, RFPs, and procurement processes. The ideal candidate will bring deep expertise in application security, secure development practices, GRC, and translating complex security requirements into practical solutions that enable business growth. This role reports to the Senior Director of Information Security.
Key Responsibilities
- Strategic Product Security Leadership
- Lead out on the development and execution of a comprehensive product security strategy in partnership with the Senior Director of Information Security.
- Collaborate to establish security architecture standards and design patterns for products across cloud-based services, on-premises infrastructure, and customer-deployed solutions.
- Lead GRC initiatives in place (SOC2 and expanding), ISO27001 (Implementing), and new emerging GRC requirements.
- Partner with senior leadership and Information Security leadership to align product security initiatives with business objectives and customer requirements.
- Develop a threat model panel capable of providing security design and threat model review.
- Lead out on security design reviews and threat modeling sessions for new products, features, and architectural changes.
- Help create and sustain security champions programs to embed security expertise within development teams.
- Develop and manage vulnerability disclosure programs and third-party security assessments.
- Define and track security metrics and KPIs that demonstrate the effectiveness of the product security program, in coordination with your manager.
- Secure Development and DevSecOps
- Work with the DevOps team to build and mature a DevSecOps program that automates security testing and validation throughout CI/CD pipelines.
- Collaboratively implement secure coding standards and development frameworks across engineering teams.
- Assist in overseeing security testing programs including SAST, DAST, SCA, and penetration testing.
- Promote adoption of threat modeling practices during product design and feature planning.
- Support vulnerability management processes from identification through remediation and validation.
- Contract and RFP Security Management
- Serve as a leading and collaborative security authority in contract negotiations.
- Develop standardized security documentation and negotiate security terms in conjunction with InfoSec leadership.
- Build and maintain a library of security response templates and support pre-sales security evaluations.
- Lead out on training of security practices and responses with the Commercial organization to enhance their knowledge and ability to respond.
- Product Security Operations
- Establish secure product release processes and security validation gates in partnership with the appropriate stakeholders from each organization.
- Oversee supply chain security and implement security observability in products.
- Contribute to the development of AI/ML model security practices.
- Customer Security Engagement
- Act as a trusted advisor for strategic customers.
- Lead customer security reviews and present security roadmaps in collaboration with Product Management.
- Coordinate responses to customer security incidents and represent the company at industry forums, as directed.
- Team Development and Collaboration
- Work collaboratively with senior leadership in building and mentoring a distributed product security team.
- Assist in delivering security training tailored to technical teams.
- Help foster a security-positive culture and collaborate across engineering and product organizations.
- Security Operations and Incident Response
- Update and improve incident response playbooks specific to product vulnerabilities, in collaboration with appropriate stakeholder organizations.
- Manage incident response for product security breaches, ensuring alignment with broader InfoSec protocols.
Required Qualifications
- Experience
- 15+ years of progressive experience in information security, secure development.
- Experience supporting security for organizations with hybrid cloud/on-premises architectures.
- Proven track record implementing secure SDLC programs and DevSecOps practices in fast-paced product environments.
- Background supporting sales and customer-facing teams through security evaluations and contract negotiations.
- Experience with unified communications platforms, VoIP systems, or similar real-time communication technologies, nice to have.
- Experience contributing to AI governance policies and responsible AI frameworks.
- Background in securing multi-tenant SaaS platforms and customer-deployed enterprise software.
- Technical Expertise
- Deep understanding of application security principles, secure coding practices, and common vulnerability classes (OWASP Top 10, SANS Top 25).
- Expertise in security testing tools and methodologies (SAST, DAST, IAST, SCA, penetration testing).
- Deep understanding of cloud security architectures (AWS, Azure, GCP).
- Expertise in network security, identity and access management, and data protection.
- Knowledge of secure software development practices and DevSecOps methodologies.
- Familiarity with telecommunications security standards and unified communications protocols.
- Understanding of zero-trust architectures and modern security frameworks.
- Leadership and Communication
- Exceptional ability to communicate complex security concepts to technical and non-technical stakeholders.
- Experience presenting to executives, and external auditors.
- Proven ability to influence and drive security initiatives across diverse teams.
- Track record of building collaborative relationships with engineering and product organizations.
Preferred Qualifications
- Advanced degree in Computer Science, Information Security, or related field.
- Professional certifications such as CISSP, CISM, or CRISC.
- Experience with privacy regulations including GDPR, CCPA, and HIPAA.
- Background in telecommunications or unified communications industry.
- Experience with FedRAMP or other government compliance frameworks.
- Knowledge of container security and microservices architectures.
Senior Manager Information Security in London employer: Alianza, Inc.
Join a forward-thinking company that prioritises innovation and security, offering a collaborative work culture where your expertise in information security will be valued and nurtured. With a strong focus on employee growth, we provide ample opportunities for professional development and mentorship, ensuring you can thrive in your role as a Senior Manager of Information Security. Located in a vibrant area, our workplace fosters creativity and teamwork, making it an ideal environment for those looking to make a meaningful impact in the field of cybersecurity.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Manager Information Security in London
✨Tip Number 1
Network like a pro! Attend industry events, webinars, and meetups to connect with other professionals in the information security field. You never know who might have a lead on your dream job!
✨Tip Number 2
Show off your expertise! Create a personal blog or LinkedIn posts where you share insights on GRC initiatives, secure software development, or application security. This not only showcases your knowledge but also helps you stand out to potential employers.
✨Tip Number 3
Prepare for interviews by brushing up on your communication skills. Be ready to explain complex security concepts in simple terms, as you'll need to engage with both technical and non-technical stakeholders.
✨Tip Number 4
Don't forget to apply through our website! We love seeing candidates who are genuinely interested in joining our team. Plus, it gives you a chance to showcase your enthusiasm for the role right from the start.
We think you need these skills to ace Senior Manager Information Security in London
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in information security, GRC, and secure development practices. We want to see how your skills align with our needs, so don’t hold back on showcasing your relevant achievements!
Showcase Your Leadership Skills:As a Senior Manager, we’re looking for someone who can lead and mentor teams. Use your application to demonstrate your leadership experience and how you've successfully driven security initiatives in the past. Share specific examples that illustrate your impact!
Be Clear and Concise:When writing your application, keep it clear and to the point. We appreciate well-structured documents that are easy to read. Avoid jargon unless it’s necessary, and make sure your key points stand out. This will help us quickly see why you’re a great fit!
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, you’ll find all the details about the role and our company culture there, which can help you tailor your application even further!
How to prepare for a job interview at Alianza, Inc.
✨Know Your GRC Inside Out
Make sure you’re well-versed in Governance, Risk, and Compliance (GRC) initiatives. Brush up on SOC2, ISO27001, and any emerging GRC requirements. Being able to discuss these confidently will show that you’re not just familiar with the concepts but can also lead their implementation.
✨Showcase Your Secure Development Knowledge
Prepare to discuss secure software development practices and how they integrate into the product lifecycle. Be ready to share examples of how you've implemented secure coding standards or DevSecOps practices in previous roles. This will demonstrate your hands-on experience and strategic thinking.
✨Communicate Like a Pro
Since this role involves liaising with both technical and non-technical stakeholders, practice explaining complex security concepts in simple terms. Think about how you would present security roadmaps or incident responses to customers and executives. Clear communication is key!
✨Prepare for Scenario-Based Questions
Expect questions that require you to think on your feet, such as how you would handle a security breach or negotiate security terms in a contract. Prepare specific scenarios from your past experiences where you successfully navigated similar challenges, showcasing your problem-solving skills.