Information Security Manager

Information Security Manager

West Bromwich Full-Time 48000 - 72000 £ / year (est.) No home office possible
A

At a Glance

  • Tasks: Lead ARAG UK's security strategy and manage the information security team.
  • Company: ARAG Legal Services UK is a dynamic player in the insurance sector, focused on digital services.
  • Benefits: Enjoy 27 days holiday, private medical insurance, and exclusive discounts across retail partners.
  • Why this job: Join a passionate team, take ownership of your work, and make a real impact on security.
  • Qualifications: Strong understanding of information security frameworks and experience with security technologies required.
  • Other info: Open to candidates with transferable skills, regardless of meeting all criteria.

The predicted salary is between 48000 - 72000 £ per year.

We’re excited to announce an opportunity for an Information Security Manager to join our dynamic Digital Services team at ARAG UK. As a member of the Digital Services team, this role will be at the forefront of ARAG UK’s security strategy, ensuring the confidentiality, integrity and availability of ARAG’s information and information systems.

The successful candidate will hold accountability for ensuring our ISO27001 accreditation is adhered to and successfully renewed, as well as assessing the information risk and facilitating remediation of identified vulnerabilities within the company’s network, systems and applications. In addition, you will lead on the strategy, road mapping and planning of security in the organisation as well as the management of the information security team.

This is an excellent opportunity to report on findings and apply recommendations for corrective & preventative action, whilst identifying opportunities to reduce security risks. Key responsibilities will also include documenting remediation options regarding acceptance or mitigation of risk scenarios, as well as facilitating and monitoring performance of risk remediation tasks, changes related to risk mitigation & reporting on findings.

This role will help the company understand security threats and help create strategies to protect ARAG’s assets and interests for multiple ARAG entities. This is a strategic and hands-on work role, where you will manage a small team, whilst also supporting the Security & Governance Manager driving the IT Security strategy, leading projects, coordinating the team’s work and mentoring, coaching & developing them.

There will also be a responsibility to work with others in Digital Services and the wider organisation to ensure appropriate leadership and accountability in the security space. The role-holder will engage with our parent company, ensuring our ISMS aligns with their prescribed standards and frameworks, as well as discussing, analysing, planning and executing any required changes and improvements in our Information Security Systems.

We are keen to hear from candidates that possess a high level of technical, organisational and communication skills to fulfil this role. You will also be accountable for contributing to audit responses, specifically in the InfoSec area, and establishing improvements in the response process and standardisation.

About You: We are keen to hear from candidates with a good understanding of information security frameworks, standards and security best practice (ISO27001, NIST CSF, Cyber Essentials, OWASP). You’ll have demonstrable knowledge and adherence to data protection legislation and regulatory requirements (e.g. GDPR, FCA SYSC, PCI DSS), as well as extensive experience and understanding of security analysis tools, defensive technologies and other security technologies (e.g. SIEM, VAS, IDS/IPS, Firewalls, IAM, NAC, patch management, anti-malware).

In addition, the ideal candidate will have:

  • Solid understanding of security incident management and incident response processes and activities.
  • Strong working knowledge of authentication technologies (e.g. two-factor, multifactor).
  • Good knowledge of Zero trust principles (e.g. limiting access to confidential information, limiting remote access to applications, differentiating between corporate and personal devices, trusted endpoints).
  • Knowledge of endpoint security solutions (e.g. HIDS, anti-malware, file integrity, DLP).
  • AWS and cloud platforms (e.g. SaaS, IaaS, PaaS).
  • System administration, supporting multiple platforms and applications.
  • Skilled in conducting vulnerability scans and identifying vulnerabilities in systems.
  • Good awareness of the current Threat Landscape.
  • Good understanding of modern malware: execution methods, persistence, detection, delivery mechanisms and entry points.
  • Experience delivering presentations and supporting messaging to leadership teams.
  • At a minimum, intermediate level of expertise in IT risk management or a related discipline – for example, security, privacy, business continuity management or compliance.

As a team, we are passionate and enthusiastic about what we do. Our people are encouraged to think independently and to take ownership of their work. In return for your commitment, we will offer you generous remuneration and an attractive benefits package which includes:

  • 27 days holiday with the option to buy up to a further 5 days
  • Company pension scheme with the option to increase contributions
  • Group Income Protection for all employees
  • Group Legal Protection for all employees
  • European Motor Assistance and Home Emergency Assistance
  • Private Medical Insurance
  • Salary sacrifice benefits including Cycle scheme
  • Access to our employee discounts hub offering exclusive discounts across thousands of retail partners, including discounted gym memberships at over 3,000 gyms across the UK
  • The option to join our Sports and Social club which organises discounted events such as theatre visits, wine tasting and shopping trips

If you think you would be a good match for this role and can demonstrate some transferable experience please apply, regardless of whether you meet all the criteria listed above.

Information Security Manager employer: ARAG Legal Services UK

ARAG Legal Services UK is an exceptional employer that fosters a dynamic and inclusive work culture, encouraging employees to think independently and take ownership of their roles. With a strong focus on employee growth, the company offers generous benefits including 27 days of holiday, private medical insurance, and access to exclusive discounts, all while being located in the vibrant city of Bristol, which enhances both professional and personal life experiences.
A

Contact Detail:

ARAG Legal Services UK Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Information Security Manager

✨Tip Number 1

Familiarise yourself with the specific information security frameworks mentioned in the job description, such as ISO27001 and NIST CSF. Being able to discuss these frameworks in detail during your conversations will demonstrate your expertise and alignment with ARAG's needs.

✨Tip Number 2

Network with current or former employees of ARAG Legal Services UK on platforms like LinkedIn. Engaging with them can provide you with insider knowledge about the company culture and expectations, which can be invaluable during interviews.

✨Tip Number 3

Prepare to discuss your experience with incident management and response processes. Given the role's focus on security incident management, having concrete examples ready will help you stand out as a candidate who can handle real-world challenges.

✨Tip Number 4

Showcase your leadership skills by preparing examples of how you've successfully managed teams or projects in the past. This role involves leading a small team, so demonstrating your ability to mentor and develop others will be crucial.

We think you need these skills to ace Information Security Manager

ISO27001 Accreditation Management
Information Risk Assessment
Vulnerability Remediation
Security Strategy Development
Team Leadership and Management
Incident Management and Response
Data Protection Legislation Knowledge (e.g. GDPR)
Security Analysis Tools Proficiency
Defensive Technologies Expertise
Authentication Technologies Knowledge
Zero Trust Principles Understanding
Endpoint Security Solutions Knowledge
Cloud Platforms Familiarity (e.g. AWS)
System Administration Skills
Vulnerability Scanning and Analysis
Threat Landscape Awareness
Modern Malware Understanding
Presentation Skills for Leadership Teams
IT Risk Management Expertise

Some tips for your application 🫡

Tailor Your CV: Make sure your CV highlights relevant experience in information security management, particularly with frameworks like ISO27001 and NIST CSF. Use specific examples that demonstrate your skills in risk assessment and incident response.

Craft a Compelling Cover Letter: In your cover letter, express your enthusiasm for the role and the company. Discuss how your background aligns with ARAG's security strategy and mention any specific projects or achievements that showcase your expertise in managing information security.

Highlight Technical Skills: Clearly outline your technical skills related to security technologies such as SIEM, firewalls, and vulnerability scanning tools. Mention your familiarity with data protection legislation like GDPR and how you have applied this knowledge in previous roles.

Showcase Leadership Experience: Since the role involves managing a small team, emphasise any leadership or mentoring experience you have. Provide examples of how you've successfully led projects or initiatives in the past, particularly in the context of information security.

How to prepare for a job interview at ARAG Legal Services UK

✨Understand the Security Frameworks

Make sure you have a solid grasp of information security frameworks like ISO27001, NIST CSF, and Cyber Essentials. Be prepared to discuss how these frameworks apply to the role and how you've implemented them in past experiences.

✨Showcase Your Technical Skills

Highlight your experience with security analysis tools and technologies such as SIEM, firewalls, and anti-malware solutions. Be ready to provide examples of how you've used these tools to identify and mitigate vulnerabilities.

✨Demonstrate Leadership Experience

Since this role involves managing a small team, be prepared to discuss your leadership style and any relevant experiences. Share examples of how you've mentored or developed team members in previous roles.

✨Prepare for Scenario-Based Questions

Expect questions that assess your problem-solving skills in real-world scenarios. Think about past incidents you've managed and how you approached risk assessment and remediation. Use the STAR method (Situation, Task, Action, Result) to structure your responses.

Information Security Manager
ARAG Legal Services UK
A
  • Information Security Manager

    West Bromwich
    Full-Time
    48000 - 72000 £ / year (est.)

    Application deadline: 2027-06-20

  • A

    ARAG Legal Services UK

Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>