Information Security Manager in England

Information Security Manager in England

England Full-Time 53893 - 53893 £ / year (est.) No working from home possible
Bluelight Commercial

At a Glance

  • Tasks: Lead the development of a robust security framework and ensure compliance with national standards.
  • Company: Join BlueLight Commercial, a trusted partner in delivering commercial excellence to policing.
  • Benefits: Enjoy a competitive salary, generous leave, and support for your professional development.
  • Other info: Remote working available, fostering an inclusive and diverse workplace culture.
  • Why this job: Make a real impact on information security in a collaborative and evolving environment.
  • Qualifications: Degree or equivalent experience with relevant security certifications required.

The predicted salary is between 53893 - 53893 £ per year.

Reporting to: Senior Information Risk Owner (SIRO)

Dept/Pillar: Revenue & Transformation

Hours: 37 (full-time)

Grade/Salary: From £53,893 (dependent on experience)

Contract Type: Fixed Term Contract until 31 March 2028

Vetting Level: NPPV 3 & SC

Responsible for overseeing the Information Security approach for BlueLight Commercial (BLC), providing assurance that BLC IT systems, processes and procedures are operating within risk tolerance. Co‑ordinating and delivering non‑technical controls such as policy, process, and training, as well as collaborating with IT partner cyber resources on delivery of the technical controls. The Information Security Manager leads the development and delivery of a robust security framework across BLC. The role ensures alignment with UK policing, fire and public sector standards while operating in a commercial environment. This role also involves working with others to ensure information security is embedded into new projects and supporting the organisation’s response to any information security incidents. This role will have ownership of the SyAP (Security Assurance for Policing) framework for the organisation and will oversee delivery of the associated action plan, reporting to relevant governance and assurance boards such as BLC Audit & Risk and Finance & Commercial Committee. Remote working nationally within UK.

BlueLight Commercial is a company set up by the Home Office to deliver commercial excellence into policing with the ambition to be the trusted commercial partner of blue light organisations, delivering value through collaboration, commercial expertise and innovation.

You will operate across technology, data and operational teams, working closely with senior stakeholders, external partners and policing bodies such as Police Digital Service (PDS). You will play a key role in building a strong security culture across a collaborative, agile and evolving organisation.

Responsibilities and accountabilities:

  • To provide subject matter expertise and advice to the respective SIRO’s and other key stakeholders on Information Security related matters.
  • Lead the activity associated with the security framework, ensuring BLC achieve and maintain the agreed minimum national standard.
  • Ensure information security policies, processes and guidance are in place, fit for purpose, up to date, available, and used, to inform and where necessary enforce security behaviour across the respective organisations.
  • Collaborate with colleagues to develop and deliver ongoing training and awareness activity across a range of expertise and responsibility but with initial focus on highest risk areas.
  • Ensure BLC has an effective response to cyber incidents, alerts, and threats, to include defined roles and responsibilities, and escalation routes, as well as regular exercising and continuous improvement.
  • Oversee a risk‑based approach to auditing, including scoping and commissioning on behalf of the respective organisations, and supporting partner agency requirements. This will include physical as well as technical and procedural audits.
  • Ensure resultant findings and recommendations are recorded and assessed and activity is prioritised.
  • Liaise with stakeholders across the landscape to embed information security into change activity at the outset, supporting Secure By Design and Data Protection by Design principles, and ensure completion of any associated risk review, escalation and acceptance processes and documentation.
  • Work with colleagues to ensure supplier security assessment and continuous improvement is embedded in all finance and commercial processes.
  • Other responsibilities include supporting the remote workforce for all IT and equipment, HR support, finance, governance assurance, information management and data protection protocols.

Qualifications & Accreditations:

  • Degree or equivalent experience
  • CISSP, CISM or ISO 27001 certification

Experience & Knowledge:

  • Experience in security leadership
  • ISO 27001 implementation
  • Risk and compliance ideally within public sector or policing environments

Skills:

  • Strong cyber security knowledge
  • Stakeholder engagement
  • Risk translation
  • Analytical thinking
  • Communication

Personal Qualities:

  • Resilient
  • Collaborative
  • Professional
  • Adaptive
  • Committed to continuous improvement

Equality, Diversity and Inclusion:

We foster a work environment that is inclusive as well as diverse, where our people can be themselves. We value every idea and perspective towards helping us to evolve and innovate.

What We Offer – Total Rewards Package:

  • Starting salary £53,893 p.a. (dependent on experience)
  • Quality equipment for successful remote working: laptop, mobile phone, monitor, chair & desk and a Welcome ‘kit box’
  • 12% employer pension contribution
  • Support for your development for your role and future career development (a framework to achieve this)
  • Pension salary sacrifice scheme
  • Life insurance 4 x salary
  • 28 days annual leave (rising on service) plus paid bank holiday leave
  • Birthday Leave (1 x extra day per year to be used in birthday month)
  • Occupational sick pay
  • Wellness – free vouchers for eye test and flu jab
  • Employee Assistance Programme for health and wellbeing
  • 1 x annual professional subscription
  • Learning Management System – access to free training & e‑learning (more than 80,000 learning resources)

The legal bit:

The successful applicant will be subject to pre‑employment checks including medical screening and vetting (carried out externally NPPV3). Due to the nature of our business this is important. As standard you will need to satisfy: Employment eligibility check (right to work in the UK); Residency qualification (meaning you must have a 5 year ‘checkable history’ in the UK, ideally you have been and you are a resident in England or Wales for the last 5 years); Employment references (last 3 years or educational / personal reference where applicable).

NPPV3: This level of vetting grants the applicant to have unsupervised, unrestricted access to police premises and systems and could include those working in areas where the police roles have been identified as designated posts. NPPV3 allows access to classified police material or information up to SECRET and occasional access to TOP SECRET. Clearance at SC level, sits alongside NPPV3 allows applicants access to a higher level of secure information and systems.

Information Security Manager in England employer: Bluelight Commercial

BlueLight Commercial is an exceptional employer, offering a collaborative and inclusive work culture that prioritises employee growth and development. With a strong commitment to innovation in the public sector, employees benefit from a comprehensive rewards package, including generous pension contributions, wellness support, and extensive training resources, all while working remotely across the UK. Join us in making a meaningful impact within policing and public safety, where your expertise in information security will be valued and nurtured.

Bluelight Commercial

Contact Details:

Bluelight Commercial Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Security Manager in England

Tip Number 1

Network like a pro! Reach out to folks in the industry, attend events, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Prepare for interviews by researching the company and its culture. Understand their approach to information security and be ready to discuss how your experience aligns with their needs. Show them you're not just a fit on paper but also in spirit!

Tip Number 3

Practice makes perfect! Conduct mock interviews with friends or use online platforms to refine your answers. Focus on articulating your experience with security frameworks and stakeholder engagement clearly and confidently.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who are proactive about their job search!

We think you need these skills to ace Information Security Manager in England

Information Security Management
Cyber Security Knowledge
Stakeholder Engagement
Risk Translation
Analytical Thinking
Communication Skills
ISO 27001 Implementation

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in information security, especially in relation to the responsibilities mentioned in the job description. We want to see how your skills align with our needs!

Showcase Your Expertise:Don’t hold back on showcasing your qualifications like CISSP or ISO 27001 certification. We’re looking for someone with strong cyber security knowledge, so let us know how you’ve applied this in previous roles.

Be Clear and Concise:When writing your application, keep it clear and to the point. Use bullet points where possible to make it easy for us to read through your achievements and experiences. We appreciate a well-structured application!

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you don’t miss out on any important updates regarding your application status.

How to prepare for a job interview at Bluelight Commercial

Know Your Security Frameworks

Make sure you’re well-versed in security frameworks like ISO 27001 and the SyAP. Brush up on how these frameworks apply to the public sector and be ready to discuss your experience with implementing them.

Showcase Your Stakeholder Engagement Skills

Prepare examples of how you've successfully engaged with stakeholders in previous roles. Highlight your ability to communicate complex security concepts in a way that resonates with non-technical audiences.

Demonstrate Your Risk Management Expertise

Be ready to talk about your approach to risk management. Discuss specific instances where you’ve identified, assessed, and mitigated risks, especially in a public sector or policing context.

Emphasise Continuous Improvement

Share your commitment to continuous improvement in information security practices. Talk about any training initiatives you’ve led or participated in, and how you’ve fostered a culture of security awareness within teams.