At a Glance
- Tasks: Lead security governance, compliance, and risk management for a global retail organisation.
- Company: Join a dynamic global retail company based near Manchester, embracing innovation and security.
- Benefits: Enjoy a hybrid work model with flexible hours and competitive perks.
- Why this job: Make a real impact on global security while collaborating with diverse teams.
- Qualifications: 5+ years in cybersecurity or IT governance; knowledge of ISO 27001 and NIST required.
- Other info: This is a permanent role with opportunities for professional growth and development.
The predicted salary is between 48000 - 72000 £ per year.
We are seeking a Senior Information Security Manager for a global retail organisation based near Manchester or East Midlands (hybrid position) on a permanent basis. This is a hands-on security management role responsible for overseeing governance, risk, compliance, and security operations across global regions. The role focuses on embedding robust security frameworks, maintaining compliance, and supporting effective operational security across the business.
Key Responsibilities
- Security Governance & Compliance
- Develop and implement information security policies, standards, and procedures across global operations.
- Ensure compliance with recognised frameworks such as ISO 27001, NIST, and others as required.
- Lead annual security audits and maintain continuous compliance across regional entities.
- Enterprise Risk Management & Supply Chain Security
- Maintain and improve the global information security risk management framework.
- Conduct regular security risk assessments and support mitigation planning.
- Manage supply chain security, including vendor risk assessments and responses to customer due diligence.
- Incident Response Policy & Preparedness
- Develop and maintain cybersecurity incident response policies and playbooks.
- Work with regional IT teams to ensure incident response processes are well understood and consistently applied.
- Promote awareness and preparedness through guidance and documentation.
- Security Operations & Third-Party Oversight
- Collaborate with the Security Operations Centre (SOC) to enhance operational security practices.
- Manage relationships with third-party security providers, ensuring coverage of regional threats and vulnerabilities.
- Oversee third-party risk management, including onboarding and ongoing assessments.
- Stakeholder Engagement & Support
- Build strong relationships with internal stakeholders across global IT and business functions.
- Align security practices with operational needs and provide support to regional teams as required.
Experience & Qualifications
- 5+ years of experience in cybersecurity, IT governance, or risk management roles.
- Solid understanding of compliance standards such as ISO 27001, NIST, and related frameworks.
- Proven experience in developing and maintaining security policies, audit readiness, and risk frameworks.
- Familiarity with global operational environments and cross-regional collaboration.
- Experience of managing within less regulated industries and small cyber functions.
- Strong communication and documentation skills to support policy rollout and stakeholder engagement.
Please contact me for details and a further discussion.
Information Security Manager (Perm - Hybrid) (Manchester) employer: CODA Technology Services
Contact Detail:
CODA Technology Services Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Information Security Manager (Perm - Hybrid) (Manchester)
✨Tip Number 1
Familiarise yourself with the specific compliance frameworks mentioned in the job description, such as ISO 27001 and NIST. Being able to discuss these frameworks in detail during your interview will demonstrate your expertise and readiness for the role.
✨Tip Number 2
Network with professionals in the cybersecurity field, especially those who have experience in retail or global operations. Engaging with them can provide insights into industry-specific challenges and best practices that you can bring up in your discussions with us.
✨Tip Number 3
Prepare to showcase your experience in incident response and risk management. Think of specific examples where you've successfully implemented security policies or managed incidents, as these will be crucial talking points during your interview.
✨Tip Number 4
Research our company culture and values at StudySmarter. Understanding how we align security practices with operational needs will help you articulate how you can contribute to our team and support regional stakeholders effectively.
We think you need these skills to ace Information Security Manager (Perm - Hybrid) (Manchester)
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in cybersecurity, IT governance, and risk management. Emphasise your familiarity with compliance standards like ISO 27001 and NIST, as well as any hands-on experience you have in developing security policies.
Craft a Compelling Cover Letter: In your cover letter, explain why you're the perfect fit for the Information Security Manager role. Discuss your experience with security governance, incident response, and stakeholder engagement, and how these align with the company's needs.
Showcase Your Achievements: When detailing your past roles, focus on specific achievements that demonstrate your ability to manage security operations and compliance effectively. Use metrics where possible to quantify your impact, such as successful audits or improved risk management processes.
Proofread and Edit: Before submitting your application, take the time to proofread your documents. Check for spelling and grammatical errors, and ensure that your writing is clear and professional. A polished application reflects your attention to detail, which is crucial in security management.
How to prepare for a job interview at CODA Technology Services
✨Know Your Frameworks
Familiarise yourself with compliance standards like ISO 27001 and NIST. Be prepared to discuss how you've implemented these frameworks in previous roles, as this will demonstrate your expertise and understanding of security governance.
✨Showcase Your Incident Response Skills
Prepare examples of how you've developed or maintained incident response policies. Highlight any specific incidents you've managed and the outcomes, as this will show your hands-on experience in security operations.
✨Emphasise Stakeholder Engagement
Think about how you've built relationships with internal stakeholders in past roles. Be ready to share strategies you've used to align security practices with operational needs, as this is crucial for the role.
✨Demonstrate Risk Management Experience
Be prepared to discuss your experience with risk assessments and mitigation planning. Provide concrete examples of how you've improved risk management frameworks, especially in a global context, to showcase your capability in this area.