Information Security Manager

Information Security Manager

Full-Time 60000 - 80000 £ / year (est.) Home office (partial)
Financial Times

At a Glance

  • Tasks: Lead information security governance, risk management, and compliance activities across global business areas.
  • Company: Join a leading organisation committed to security and inclusivity.
  • Benefits: Enjoy flexible working, generous leave, health coverage, and career development opportunities.
  • Other info: Work in a dynamic environment with excellent growth potential and support for your career journey.
  • Why this job: Make a real impact on global security practices while collaborating with diverse teams.
  • Qualifications: Experience in information security, risk management, and stakeholder engagement required.

The predicted salary is between 60000 - 80000 £ per year.

The Information Security Manager will be responsible for leading and coordinating information security governance, risk, and compliance activities across assigned business areas. The role will provide oversight of security controls, regulatory alignment, risk management, and stakeholder engagement, ensuring that information security practices support business strategy and global standards. The position will be based in Manila and work closely with UK and international stakeholders.

Information Security Governance & Risk Management

  • Lead the implementation and oversight of information security policies, standards, and control frameworks, with reference to recognised industry standards/frameworks (e.g., ISO 27001, NIST CSF).
  • Ensure alignment between business objectives and security, privacy, and regulatory requirements.
  • Identify, assess, and manage information security risks, providing clear reporting and escalation where required.
  • Support regional and global risk management processes, including risk register maintenance and remediation tracking.

Compliance & Control Assurance

  • Oversee control assurance activities across systems and applications, ensuring appropriate security controls are implemented and operating effectively.
  • Coordinate internal and external audit engagements, including preparation, evidence gathering, and remediation management.
  • Maintain oversight of compliance‑related system inventories and documentation.
  • Track and report on remediation activities to ensure closure within agreed timelines.

Security Oversight of Systems & Data

  • Collaborate with IT and business teams to maintain accurate data inventories and system documentation.
  • Ensure appropriate data protection, classification, and handling practices are embedded in operational processes.
  • Provide guidance on secure system design, implementation, and change management activities.

Stakeholder Engagement & Advisory

  • Act as a trusted security advisor to regional business and technology stakeholders.
  • Communicate security risks, control gaps, and compliance issues clearly to technical and non‑technical audiences.
  • Support business initiatives by providing security input during project planning and delivery.

Incident & Issue Management

  • Support investigation and management of security incidents from a governance and compliance perspective.
  • Ensure lessons learned and control improvements are captured and implemented.
  • Escalate material risks or control failures appropriately.

Continuous Improvement

  • Drive improvements in security processes, documentation, and assurance activities.
  • Monitor regulatory and threat landscape developments relevant to the organisation and region.
  • Contribute to the maturity and evolution of the information security programme.

Analytical & Reporting Capabilities

  • Experience building executive‑ready risk dashboards and metrics.
  • Ability to translate technical findings into business risk narratives.
  • Comfort working with structured reporting and KPIs/KRIs.

Standards, Frameworks & Assurance

  • Working knowledge of additional frameworks (e.g., CIS Controls, COBIT, SOC 2, PCI DSS where relevant).
  • Experience with PCI DSS compliance in media, financial, or global organisations.
  • Experience with Information Security Supply chain assurance life cycle design and implementation.
  • Familiarity with control testing methodologies and evidence‑based assurance practices.

Scope & Seniority Indicators

  • Operates with a high degree of autonomy.
  • Responsible for regional coordination (Manila/APAC time zone alignment).
  • Engages directly with senior technology and business stakeholders.
  • Accountable for risk visibility and control assurance across defined domains.

Desirable

  • Exposure to GRC platforms (e.g., Archer, ServiceNow GRC, OneTrust, MetricStream or similar).
  • Exposure to GRC Engineering tooling and practices.
  • Foundational understanding of cloud security concepts (e.g., AWS/Azure control models).
  • Understanding of data protection regulations (e.g., GDPR) and data lifecycle management.
  • Experience supporting ISO 27001 certification or surveillance audits.
  • Experience with regulatory environments relevant to media, financial, or global organisations.

Benefits

Our benefits vary depending on location, but we are committed to providing best in class perks across all our offices as well as an inclusive environment to develop your career. Examples of our benefits include generous annual leaves, flexible working (including working from home), health coverage (medical & dental), and company match and enhanced family leave packages.

EEO Statement

The FT is committed to providing an inclusive working environment for all. We are an equal opportunities employer who seeks to recruit and appoint the best talent regardless of age, gender, ethnicity, disability, sexual orientation, gender identity, socio‑economic background, religion and/or belief. We also promote flexible working and will consider specific requests around flexibility for all roles where it can be accommodated. Please let us know if you require any adjustments as part of the application process or to enable you to attend an interview. If you would like to discuss your requirements, or have any questions, please contact a member of our HR team who will be happy to help.

Information Security Manager employer: Financial Times

As an Information Security Manager at our Manila office, you will join a dynamic and inclusive work culture that prioritises employee growth and development. We offer competitive benefits such as generous annual leave, flexible working arrangements, and comprehensive health coverage, all while fostering a collaborative environment that encourages innovation and engagement with international stakeholders. Our commitment to diversity and inclusion ensures that every team member feels valued and empowered to contribute meaningfully to our global security initiatives.

Financial Times

Contact Details:

Financial Times Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Security Manager

Tip Number 1

Network like a pro! Reach out to your connections in the information security field and let them know you're on the hunt for an Information Security Manager role. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Get your LinkedIn game on point! Make sure your profile is up-to-date and highlights your experience with frameworks like ISO 27001 and NIST CSF. Join relevant groups and engage in discussions to showcase your expertise and connect with potential employers.

Tip Number 3

Prepare for interviews by brushing up on your knowledge of compliance and risk management. Be ready to discuss how you've implemented security policies and managed risks in previous roles. Practice articulating complex security concepts in a way that non-technical stakeholders can understand.

Tip Number 4

Don't forget to apply through our website! We love seeing candidates who are genuinely interested in joining our team. Tailor your application to highlight your experience with GRC platforms and cloud security concepts, and show us how you can contribute to our mission.

We think you need these skills to ace Information Security Manager

Information Security Governance
Risk Management
Compliance Assurance
ISO 27001
NIST CSF
Data Protection
Stakeholder Engagement

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in information security governance, risk management, and compliance. We want to see how your skills align with our needs, so don’t hold back on showcasing relevant achievements!

Showcase Your Knowledge:Mention any familiarity you have with industry standards like ISO 27001 or NIST CSF. We love seeing candidates who understand the frameworks we work with, so drop in some examples of how you've applied these in your previous roles.

Be Clear and Concise:When writing your application, keep it straightforward and to the point. We appreciate clarity, especially when it comes to complex topics like risk management and compliance. Use bullet points if it helps make your experience stand out!

Apply Through Our Website:We encourage you to submit your application through our website. It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it’s super easy to do!

How to prepare for a job interview at Financial Times

Know Your Frameworks

Familiarise yourself with key information security frameworks like ISO 27001 and NIST CSF. Be ready to discuss how you've applied these standards in past roles, as this will show your understanding of governance and compliance.

Showcase Your Risk Management Skills

Prepare examples of how you've identified and managed information security risks. Highlight your experience with risk registers and remediation tracking, as this is crucial for the role.

Engage Stakeholders Effectively

Think about how you can communicate complex security concepts to both technical and non-technical audiences. Prepare to share instances where you've acted as a trusted advisor to stakeholders, demonstrating your ability to bridge the gap between security and business needs.

Continuous Improvement Mindset

Be ready to discuss how you've driven improvements in security processes and documentation in previous roles. Show that you're proactive about staying updated on regulatory changes and threat landscapes, which is essential for evolving the information security programme.