At a Glance
- Tasks: Lead security initiatives and ensure compliance with the UK Telecommunications (Security) Act.
- Company: Join a dynamic team at iD Mobile, part of Currys, focused on innovation and security.
- Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
- Why this job: Make a real impact on telecommunications security and shape the future of iD Mobile.
- Qualifications: Extensive experience in telecoms and cyber security, with knowledge of TSA compliance.
- Other info: Collaborative environment with strong leadership support and career advancement opportunities.
The predicted salary is between 54000 - 84000 £ per year.
We are looking to recruit a senior Information Security manager to act as the key interface between iD Mobile, Commercial, IT operations, and Currys information security & risk teams. The role is crucial to ensuring the security and resilience of iD Mobile's systems, applications, and data and will also lead iD Mobile's response to the UK Telecommunications (Security) Act (TSA). Knowledge and prior application of the TSA is essential, and a core responsibility will be delivering measurable improvements to iD Mobile's risk posture against the TSA Security Measures across architecture, delivery, operations, supplier management, and contractual frameworks.
Alongside regulatory experience, the successful candidate will be highly attuned to developments in telecommunications security to ensure iD is always ahead of the game. The role must also have proficiency across a broad range of Information Security domains and act as the 'go-to' security leader for all iD Mobile matters. This will include triaging security incidents, interpreting technical vulnerability data and prioritising remediation, assuring security-by-design, and ensuring TSA compliance & risk reduction are built into decision making across the business.
Formative understanding and acquisition of accurate inventories of all iD Mobile systems, architecture, people and processes will be paramount, aided by strong stakeholder management skills to influence steering groups and governance forums. There will also be opportunity to work with senior Currys Infosec colleagues in making operational improvements to security methodologies and drive future security strategy across iD Mobile and the wider Group.
Responsibilities- TSA Compliance & Governance: Lead the development and continuous improvement of the TSA compliance and control framework to improve iD Mobile's risk posture.
- Embed TSA requirements & design checkpoints into Architecture Board, Portfolio governance, project teams and change processes.
- Provide structured TSA reporting, compliance insights, and risk updates to senior leadership and the Board.
- Deliver TSA-aligned supplier audits and contract uplifts to reduce supply-chain risk exposure.
- Establish a TSA Steering Forum with defined RACI, KPIs, and governance cadence.
- Maintain an in-depth understanding of all iD systems, processes and people through hands-on operations.
- Act as the Information Security & TSA SME within governance forums.
- Produce monthly iD Mobile Cyber dashboards, reporting on iD project delivery & assurance, incidents and alerts.
- Regularly review IT asset inventories for accuracy and completeness in line with TSA compliance.
- Compile a register of iD Mobile third party suppliers, their criticality level and associated risks and any regulatory frameworks (such as TSA) required of them.
- Maintain an audit-ready evidence repository.
- Provide security advisory input to Change Approval Board.
- Collaborate with technical leads, business analysts and project managers on a wide range of technology projects, including software development, package implementations and infrastructure upgrades/changes.
- Act as a Data Governance champion within iD Mobile ensuring data is classified and processed in an authorised manner.
- Provide second-line challenge for iD Mobile security incidents, crisis management and resilience planning.
- Lead post-incident lessons learned reviews and enact improvements in incident playbooks and operational processes to reduce risk.
- Liaise with Security Operations to identify trending threat patterns, security tool uptime and SLAs.
- Design and schedule an annual programme of penetration testing / red teaming (TBEST aligned) for relevant iD Mobile environments.
- Review penetration test, vulnerability scans and exposure management tool output and determine appropriate risk scores and remedial activities.
- Assist Capex delivery within iD Mobile through provision of non-functional security requirements, RFP scoring, architectural review and presentation to the Data & Security Approval Board.
- Regularly review the iD Mobile risk register, drive risk closure and management, monitor for ongoing non-compliance, escalating where necessary.
- Lead the response to regulatory and business-to-business audits and security reviews of iD Mobile operations.
- Extensive experience in telecoms, cyber security, operational risk, or regulatory compliance.
- Deep knowledge of the UK Telecommunications (Security) Act and Ofcom Security Measures.
- Strong track record influencing senior governance forums and decision-making bodies.
- Hands-on experience with supplier assurance, third-party risk management, and security audits.
- Ability to drive improvements that strengthen organisational risk posture.
- Certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Auditor.
- Knowledge of MNO/MVNO network environments and telecom operational processes.
- Experience in second-line assurance or internal audit functions.
Senior Information Security Manager in City of Westminster employer: Currys PLC
Contact Detail:
Currys PLC Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Information Security Manager in City of Westminster
✨Tip Number 1
Network like a pro! Attend industry events, webinars, and meetups to connect with professionals in the telecoms and cybersecurity space. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your expertise! Create a personal blog or LinkedIn posts discussing the UK Telecommunications (Security) Act and its implications. This not only showcases your knowledge but also positions you as a thought leader in the field.
✨Tip Number 3
Prepare for interviews by brushing up on your TSA compliance knowledge and be ready to discuss how you've improved risk postures in previous roles. Use real examples to demonstrate your hands-on experience and problem-solving skills.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, we love seeing candidates who are proactive about their job search!
We think you need these skills to ace Senior Information Security Manager in City of Westminster
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Senior Information Security Manager role. Highlight your experience with the UK Telecommunications (Security) Act and any relevant certifications. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're the perfect fit for this role. Share specific examples of how you've influenced governance forums or improved risk postures in previous roles. We love a good story!
Showcase Your Stakeholder Management Skills: Since this role involves a lot of collaboration, make sure to highlight your stakeholder management skills. Talk about how you've successfully influenced decision-making bodies in the past. We need someone who can navigate complex relationships!
Apply Through Our Website: We encourage you to apply through our website for a smoother application process. It helps us keep track of your application and ensures you don’t miss out on any important updates. We can't wait to hear from you!
How to prepare for a job interview at Currys PLC
✨Know Your TSA Inside Out
Make sure you have a solid understanding of the UK Telecommunications (Security) Act and its implications. Brush up on how it affects risk management and compliance, as you'll need to demonstrate your knowledge during the interview.
✨Showcase Your Stakeholder Management Skills
Prepare examples that highlight your ability to influence and manage stakeholders effectively. Think about times when you've successfully navigated governance forums or led discussions with senior leadership.
✨Be Ready to Discuss Security Incidents
Expect questions about how you've handled security incidents in the past. Be prepared to share specific examples, including your approach to triaging incidents and implementing lessons learned to improve processes.
✨Demonstrate Your Technical Proficiency
Familiarise yourself with the technical aspects of information security relevant to telecommunications. Be ready to discuss your experience with vulnerability assessments, penetration testing, and security tooling, as these will be key topics in the interview.