At a Glance
- Tasks: Lead information security governance, risk management, and compliance activities across global business areas.
- Company: Join a leading organisation committed to security and inclusivity.
- Benefits: Enjoy flexible working, generous leave, health coverage, and career development opportunities.
- Other info: Work autonomously with senior stakeholders in a dynamic, supportive environment.
- Why this job: Make a real impact on global security practices while collaborating with diverse teams.
- Qualifications: Experience in information security, risk management, and stakeholder engagement required.
The predicted salary is between 60000 - 80000 £ per year.
The Information Security Manager will be responsible for leading and coordinating information security governance, risk, and compliance activities across assigned business areas. The role will provide oversight of security controls, regulatory alignment, risk management, and stakeholder engagement, ensuring that information security practices support business strategy and global standards. The position will be based in Manila and work closely with UK and international stakeholders.
Information Security Governance & Risk Management
- Lead the implementation and oversight of information security policies, standards, and control frameworks, with reference to recognised industry standards/frameworks (e.g., ISO 27001, NIST CSF).
- Ensure alignment between business objectives and security, privacy, and regulatory requirements.
- Identify, assess, and manage information security risks, providing clear reporting and escalation where required.
- Support regional and global risk management processes, including risk register maintenance and remediation tracking.
Compliance & Control Assurance
- Oversee control assurance activities across systems and applications, ensuring appropriate security controls are implemented and operating effectively.
- Coordinate internal and external audit engagements, including preparation, evidence gathering, and remediation management.
- Maintain oversight of compliance-related system inventories and documentation.
- Track and report on remediation activities to ensure closure within agreed timelines.
Security Oversight of Systems & Data
- Collaborate with IT and business teams to maintain accurate data inventories and system documentation.
- Ensure appropriate data protection, classification, and handling practices are embedded in operational processes.
- Provide guidance on secure system design, implementation, and change management activities.
Stakeholder Engagement & Advisory
- Act as a trusted security advisor to regional business and technology stakeholders.
- Communicate security risks, control gaps, and compliance issues clearly to technical and non-technical audiences.
- Support business initiatives by providing security input during project planning and delivery.
Incident & Issue Management
- Support investigation and management of security incidents from a governance and compliance perspective.
- Ensure lessons learned and control improvements are captured and implemented.
- Escalate material risks or control failures appropriately.
Continuous Improvement
- Drive improvements in security processes, documentation, and assurance activities.
- Monitor regulatory and threat landscape developments relevant to the organisation and region.
- Contribute to the maturity and evolution of the information security programme.
Analytical & Reporting Capabilities
- Experience building executive-ready risk dashboards and metrics.
- Ability to translate technical findings into business risk narratives.
- Comfort working with structured reporting and KPIs/KRIs.
Standards, Frameworks & Assurance
- Working knowledge of additional frameworks (e.g., CIS Controls, COBIT, SOC 2, PCI DSS where relevant).
- Experience with PCI DSS compliance in media, financial, or global organisations.
- Experience with Information Security Supply chain assurance life cycle design and implementation.
- Familiarity with control testing methodologies and evidence-based assurance practices.
Scope & Seniority Indicators
- Operates with a high degree of autonomy.
- Responsible for regional coordination (Manila/APAC time zone alignment).
- Engages directly with senior technology and business stakeholders.
- Accountable for risk visibility and control assurance across defined domains.
Desirable
- Exposure to GRC platforms (e.g., Archer, ServiceNow GRC, OneTrust, MetricStream or similar).
- Exposure to GRC Engineering tooling and practices.
- Foundational understanding of cloud security concepts (e.g., AWS/Azure control models).
- Understanding of data protection regulations (e.g., GDPR) and data lifecycle management.
- Experience supporting ISO 27001 certification or surveillance audits.
- Experience with regulatory environments relevant to media, financial, or global organisations.
Benefits
Our benefits vary depending on location, but we are committed to providing best in class perks across all our offices as well as an inclusive environment to develop your career. Examples of our benefits include generous annual leaves, flexible working (including working from home), health coverage (medical & dental), and company match and enhanced family leave packages.
EEO Statement
The FT is committed to providing an inclusive working environment for all. We are an equal opportunities employer who seeks to recruit and appoint the best talent regardless of age, gender, ethnicity, disability, sexual orientation, gender identity, socio-economic background, religion and/or belief. We also promote flexible working and will consider specific requests around flexibility for all roles where it can be accommodated. Please let us know if you require any adjustments as part of the application process or to enable you to attend an interview. If you would like to discuss your requirements, or have any questions, please contact a member of our HR team who will be happy to help.
Security Governance & Risk Leader employer: Financial Times
As a leading employer in the information security sector, our company offers a dynamic work environment in Manila that fosters professional growth and collaboration with international stakeholders. We prioritise employee well-being through generous benefits such as flexible working arrangements, comprehensive health coverage, and a commitment to inclusivity, ensuring that every team member can thrive while contributing to meaningful security initiatives.
StudySmarter Expert Advice🤫
We think this is how you could land Security Governance & Risk Leader
✨Tip Number 1
Network like a pro! Reach out to your connections in the industry, especially those who work in security governance and risk management. A friendly chat can lead to insider info about job openings that aren't even advertised yet.
✨Tip Number 2
Prepare for interviews by brushing up on your knowledge of frameworks like ISO 27001 and NIST CSF. Be ready to discuss how you've implemented security policies in past roles, as this will show you're the right fit for the job.
✨Tip Number 3
Don’t just apply anywhere; focus on companies that align with your values and career goals. Use our website to find roles that excite you and match your skills in information security governance and risk management.
✨Tip Number 4
Follow up after interviews! A quick thank-you email can keep you top of mind and show your enthusiasm for the role. Plus, it’s a great chance to reiterate why you’re the perfect candidate for the position.
We think you need these skills to ace Security Governance & Risk Leader
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in information security governance and risk management. We want to see how your skills align with the role, so don’t hold back on showcasing relevant achievements!
Showcase Your Knowledge:Mention any familiarity you have with industry standards like ISO 27001 or NIST CSF. We love seeing candidates who understand the frameworks that guide our work, so drop in some examples of how you've applied these in past roles.
Be Clear and Concise:When writing your application, keep it straightforward. Use clear language to explain your experiences and how they relate to the job. We appreciate a well-structured application that gets straight to the point!
Apply Through Our Website:We encourage you to submit your application through our website. It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it’s super easy to do!
How to prepare for a job interview at Financial Times
✨Know Your Frameworks
Familiarise yourself with key information security frameworks like ISO 27001 and NIST CSF. Be ready to discuss how you've applied these standards in previous roles, as this will show your understanding of governance and compliance.
✨Showcase Your Risk Management Skills
Prepare examples of how you've identified, assessed, and managed information security risks. Highlight any experience with risk registers and remediation tracking, as this is crucial for the role.
✨Engage Stakeholders Effectively
Think about how you can communicate complex security concepts to both technical and non-technical audiences. Prepare to share instances where you've acted as a trusted advisor, ensuring alignment between security practices and business objectives.
✨Continuous Improvement Mindset
Be ready to discuss how you've driven improvements in security processes and documentation in past roles. Mention any experience with monitoring regulatory changes and adapting security practices accordingly, as this shows your proactive approach.