Information Security Manager
Information Security Manager

Information Security Manager

Theale Full-Time 43200 - 72000 £ / year (est.) No home office possible
C

At a Glance

  • Tasks: Lead the development and improvement of our Information Security Management System.
  • Company: Join Cornerstone, the UK's top mobile and digital infrastructure provider.
  • Benefits: Enjoy a competitive salary, bonus structure, hybrid working, and 30 days holiday.
  • Why this job: Make a real impact on cybersecurity while collaborating with diverse teams.
  • Qualifications: Experience in managing ISMS and leading ISO 27001 audits is essential.
  • Other info: We value diversity and inclusion, welcoming applicants from all backgrounds.

The predicted salary is between 43200 - 72000 £ per year.

Cornerstone is the UK’s leading mobile and digital infrastructure provider, managing over 15,700 sites and holding 35% of the market. Our Mission is to be famous for excellence in delivery, embracing transformation with our people and our customers at its heart.

As Cornerstone’s Information Security Manager, you will lead the development, implementation, and continuous improvement of our Information Security Management System (ISMS), ensuring alignment with ISO 27001:2022. You will be responsible for safeguarding our digital infrastructure, managing cyber risk, and embedding a security-first culture across the organisation. This is a strategic and hands-on role, requiring collaboration across IT, legal, procurement, and operational teams. You will act as the primary point of contact for all matters related to information assurance, supplier security assurance, incident response, and regulatory compliance.

  • IT Security Operations: Collaborate closely with IT SecOps team members to ensure security controls remain effective. Where gaps are identified, implement appropriate mitigation measures and lead the response to security incidents in a timely and coordinated manner.
  • Compliance & Security: Coordinate ISO 27001 certification audits and maintain ongoing compliance on behalf of the IT & Digital function. Actively support and contribute to health and safety, environmental sustainability, business continuity, and information security initiatives, ensuring we meet our obligations to customers and regulatory standards.
  • Delivery:
    • ISMS Leadership: Own and maintain the ISMS, ensuring it meets ISO 27001:2022 requirements and supports business objectives.
    • Risk Management: Identify, evaluate, and mitigate information security risks across systems, suppliers, and processes. Maintain visibility over key cyber risks and report to senior leadership.
    • Incident Response: Lead the response to security incidents, including forensic analysis, reporting, and remediation. Coordinate with law enforcement and external partners where necessary.
    • Supplier Assurance: Conduct security reviews and audits of third-party vendors. Ensure compliance with Cornerstone’s security policies and contractual obligations.
    • Policy & Governance: Draft, review, and enforce security policies and procedures. Chair or support governance forums such as the ISMS Review and Information Security Steering Group.
    • Cyber Awareness Programme: Champion a culture of security awareness through training, phishing simulations, ensuring staff compliance with mandatory cyber training and internal communications.
    • Compliance & Certification: Ensure ongoing compliance with GDPR, ISO standards, and other regulatory frameworks. Lead surveillance audits and certification renewals.
    • Technology Oversight: Evaluate and implement security tools and technologies. Collaborate with IT Operations and infrastructure teams to embed security into system design and operations.
    • Secure Development: Ensure that security considerations are embedded throughout the project lifecycle, from initial design through to deployment and ongoing maintenance.

The successful candidate will possess substantial experience in managing and maintaining an enterprise Information Security Management System (ISMS), with a demonstrable track record of leading and supporting external ISO 27001 audits and implementing and managing robust security frameworks. They will have a comprehensive understanding of cyber threats, cloud security, particularly within Azure and Microsoft 365 environments, and key regulatory and compliance frameworks, including GDPR and ISO 27001. Experience with security and compliance tools such as ISMS Online, Qualys VMDR, and Cofense phishing simulation would be highly advantageous.

The role requires strong proficiency in vulnerability management, coordinating penetration testing, supplier security assurance, and incident response. A thorough understanding of legal and procedural obligations relating to data protection and information governance is essential. Excellent communication and stakeholder management skills are required, with the ability to articulate technical risks in a clear and business-focused manner. Analytical and problem-solving skills are critical to effectively identify vulnerabilities, assess risks, and deliver appropriate mitigation strategies in collaboration with internal and external stakeholders. Leadership and professional judgement are central to the position. The postholder will lead regular internal and customer orientated security governance meetings, oversee cross-departmental initiatives, and foster a culture of security awareness throughout Cornerstone. The role also involves close collaboration with the IT Security Operations team, contributing to continuous improvement, and supporting Cornerstone's ongoing security and compliance maturity.

Suitable candidates are likely to have prior experience in roles such as Information Security Manager, Security Lead, or Senior Security Analyst, ideally within ISO 27001-certified or similarly regulated environments.

Knowledge, Skills and Experience:

  • Proven experience managing an enterprise ISMS and leading ISO 27001 audits.
  • Strong understanding of cyber threats, cloud security (Azure, M365), and regulatory compliance.
  • Experience with supplier assurance, penetration testing, and vulnerability management.
  • Excellent stakeholder engagement and communication skills.
  • Ability to work independently and influence cross-functional teams.
  • Familiarity with Cofense phishing simulation tool, ISMS Online, Qualys VMDR.

What we offer:

  • Competitive salary and an excellent bonus structure.
  • 30 days holiday.
  • Competitive pension scheme.
  • Hybrid working.
  • Life insurance.
  • Cycle to Work.
  • Retail Discount.
  • Competitive refer a friend scheme.
  • Private Healthcare Insurance.

Our commitment to Equity, Diversity, and Inclusion (EDI) is fundamental to our success. We strive to cultivate an inclusive environment where every employee feels valued, respected, and empowered. By embracing unique perspectives and experiences, we drive innovation and drive our organisation forward, therefore, we recognise the importance of welcoming applications from candidates of all backgrounds.

We want to ensure everyone is able to present their best self throughout the recruitment process so if you require any adjustments, please let us know.

If this role is of interest to you and you would like to find out more, please do apply with an up to date version of your CV.

Operate and uphold Cornerstone’s values of Everyone Matters, Innovate to Elevate, Do the Right Thing and Customer First by being Professional, Respectful and Open.

Information Security Manager employer: Cornerstone

Cornerstone is an exceptional employer, offering a dynamic work culture that prioritises innovation and collaboration. As an Information Security Manager, you will benefit from competitive salaries, a robust bonus structure, and opportunities for professional growth within a supportive environment that values diversity and inclusion. With a commitment to employee well-being, including hybrid working options and comprehensive healthcare benefits, Cornerstone fosters a workplace where every individual can thrive and contribute to safeguarding our digital infrastructure.
C

Contact Detail:

Cornerstone Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Information Security Manager

✨Tip Number 1

Network like a pro! Reach out to folks in the industry, attend events, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

✨Tip Number 2

Prepare for interviews by researching the company and its culture. Understand their mission and values, especially how they align with your own. This will help you stand out as someone who genuinely cares about being part of their team.

✨Tip Number 3

Showcase your skills through practical examples. Be ready to discuss specific projects or challenges you've tackled in the past, especially those related to information security. This will demonstrate your hands-on experience and problem-solving abilities.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you're serious about joining Cornerstone and contributing to our mission of excellence.

We think you need these skills to ace Information Security Manager

Information Security Management System (ISMS)
ISO 27001:2022
Cyber Risk Management
Incident Response
Supplier Security Assurance
Regulatory Compliance
Vulnerability Management
Penetration Testing
Cloud Security (Azure, Microsoft 365)
GDPR Compliance
Stakeholder Engagement
Communication Skills
Analytical Skills
Problem-Solving Skills
Security Policy Development

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the Information Security Manager role. Highlight your experience with ISO 27001, cyber security, and any relevant tools you've used. We want to see how your skills align with what we're looking for!

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how you can contribute to our mission at Cornerstone. Keep it concise but impactful – we love a good story!

Showcase Your Achievements: Don’t just list your responsibilities; showcase your achievements! Use specific examples of how you've improved security measures or led successful audits. We’re all about results, so let us know how you’ve made a difference in your previous roles.

Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. It’s super easy, and you’ll be able to keep track of your application status. Plus, we love seeing applications come directly from our site!

How to prepare for a job interview at Cornerstone

✨Know Your ISO 27001 Inside Out

Make sure you’re well-versed in the ISO 27001:2022 standards. Brush up on how they apply to Cornerstone’s Information Security Management System (ISMS) and be ready to discuss your experience with audits and compliance. This shows you’re not just familiar with the framework, but that you can actively contribute to maintaining it.

✨Showcase Your Cybersecurity Knowledge

Prepare to talk about your understanding of cyber threats, especially in cloud environments like Azure and Microsoft 365. Bring examples of how you've managed vulnerabilities or responded to incidents in the past. This will demonstrate your hands-on experience and strategic thinking in safeguarding digital infrastructure.

✨Communicate Clearly and Confidently

Since this role involves a lot of stakeholder engagement, practice articulating technical risks in a way that’s easy for non-technical folks to understand. Use clear examples from your previous roles to illustrate your points. This will help you stand out as someone who can bridge the gap between IT and business needs.

✨Emphasise Your Leadership Skills

Be prepared to discuss your leadership style and how you’ve fostered a culture of security awareness in past roles. Share specific instances where you led cross-departmental initiatives or governance meetings. This will highlight your ability to influence and engage teams across the organisation.

Information Security Manager
Cornerstone
Location: Theale

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

C
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>