Information Security & Data Protection Manager

Information Security & Data Protection Manager

Full-Time 60000 - 85000 £ / year (est.) Home office (partial)
Focusrite

At a Glance

  • Tasks: Lead our Information Security and Data Protection programmes while ensuring compliance with industry standards.
  • Company: Join a dynamic music technology company with a focus on innovation and collaboration.
  • Benefits: Enjoy flexible working, private healthcare, and a supportive environment for personal development.
  • Other info: Be part of a vibrant culture with exciting company events and opportunities for growth.
  • Why this job: Make a real impact in the evolving field of AI governance and data protection.
  • Qualifications: Experience in Information Security and Data Protection with strong IT systems knowledge.

The predicted salary is between 60000 - 85000 £ per year.

Based: Remote (UK)/High Wycombe/London (N7)/Hybrid

Term: Permanent, Full time

Reporting to: Chief Information Officer (CIO)

Salary: £60000 - £85000 pa + excellent benefits

Overview

We’re looking for an Information Security Compliance Specialist to take ownership of our Information Security, Data Protection, and AI Governance programmes across the Focusrite Group. You will be the operational owner of our Information Security and Data Protection (ISDP) framework informed by ISO 27001 (ISMS), ISO 27701 (PIMS), Cyber Essentials and NIST CSF keeping us aligned to those standards and ready for certification and audit.

Working alongside development, IT and business teams, you will advise on security and privacy requirements for new and changing systems, ensuring appropriate controls are designed in, evidenced, and verified after implementation. You will also own the Group’s response to emerging risks in AI, translating evolving regulation (EU AI Act, UK AI principles, ICO guidance) into practical governance.

Responsibilities

  • Information Security Systems:
    • Framework & advisory: Own the Information Security and Data Protection Framework and its documentation, and advise IT, development, and business teams on security requirements.
    • Tools & supplier assurance: Run the Business Approved Tools process (including assessment of AI tools, vendors, and use cases), own designated Information Security tools, and conduct supplier audit assessments.
    • Certification & standards: Own certification readiness for Cyber Essentials and lead new certification efforts as the business requires.
    • Threats, incidents & testing: Monitor cyber threats and translate them for the business, own the incident management process (including phishing response and simulation exercises), and manage vulnerability scans and penetration testing (including external Red/Purple/Blue Team engagements).
    • Risk & resilience: Conduct risk assessments across products, systems, and processes; own the Information Security and Data Protection risk register, contributing to the Group Risk Management process; and maintain and test the Business Continuity Plan (BCP).
    • AI Governance: Own the AI Governance framework, AI system inventory, and alignment with ISO 42001, NIST AI RMF, and the EU AI Act where appropriate.
  • Data Protection compliance (UK GDPR, EU GDPR, US state privacy laws including CCPA/CPRA):
    • Data subject rights & assessments: Handle Data Subject Rights requests and run Data Protection Impact Assessments (DPIAs).
    • Records & registers: Maintain Records of Processing Activities, lawful basis register, consent records, and Legitimate Interest Assessments.
    • Notices, cookies & marketing: Operate Privacy Notices and Cookie Tools, and advise on PECR and e‑privacy compliance including direct marketing and electronic communications.
    • Privacy by Design & training: Help product managers and developers embed Privacy by Design, design and deliver Data Protection training and awareness across the Group.
    • Retention & breach management: Own retention schedule, deletion/anonymisation processes, and personal data breach handling including detection triage, 72‑hour ICO/EU supervisory authority notification, data subject notification where required, and the breach register.
    • Third parties & international transfers: Manage processor and sub‑processor governance, data transfer mechanisms, and transfer risk assessments.
  • Change Management:
    • Review and provide security and data protection sign‑off on changes to systems, products, and processes.
    • Participate in the Change Advisory Board (CAB) and ensure security and privacy risks are assessed before changes are approved.
    • Own change management procedures relating to Information Security and Data Protection, ensuring evidence is captured for audit.
    • Ensure security and privacy requirements are embedded in the SDLC and release processes, working with development and operational teams.
    • Track and report on the security impact of significant business, technology, and organisational change initiatives.
  • Compliance & Audits:
    • Generate monthly compliance and activity reports and other reports as required by senior management.
    • Internal Audit: Reviewing Financial System compliance activities. Performing Internal Information Security Audits. Performing Internal Data Protection Audits.
    • External audit: Be the key contact for any IT/Data Protection related audits by external bodies, ensuring requested data is supplied, complete, and accurate. Take ownership of any related audit issues. Generate audit support documents.

Keep up to date with developments in the security, privacy, and AI regulatory landscape, translating these into practical actions for the Group.

Qualifications

Several years’ experience in Information Security and Data Protection, with a good understanding of IT systems, web operations, cloud platforms, and secure coding practices (including OWASP). Comfortable engaging at all levels of the organisation and externally, with the gravitas to influence security and privacy outcomes and reduce the impact of change. The position requires providing support and advice to all parts of the Group on Information Security and Data Protection.

Benefits

  • Flexible/hybrid working.
  • Company pension.
  • Life insurance.
  • Private healthcare.
  • Health Cash Plan.
  • Enhanced maternity and paternity pay.
  • Employee purchase scheme.
  • Group bonus scheme.
  • Company music events, offsite company parties and free lunch.
  • Company training sessions and encouragement of personal development.

Information Security & Data Protection Manager employer: Focusrite

At Focusrite Group, we pride ourselves on being an exceptional employer, offering a dynamic work culture that fosters collaboration and innovation. With flexible hybrid working arrangements, comprehensive benefits including private healthcare and enhanced parental leave, and a strong commitment to employee development through training and personal growth opportunities, we ensure our team members thrive both professionally and personally. Join us in a role that not only challenges you but also allows you to make a meaningful impact in the fields of Information Security and Data Protection.

Focusrite

Contact Details:

Focusrite Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Security & Data Protection Manager

Tip Number 1

Network like a pro! Reach out to folks in the industry on LinkedIn or at events. A friendly chat can open doors that applications alone can't.

Tip Number 2

Prepare for interviews by researching the company and its culture. Tailor your answers to show how your skills align with their needs, especially in Information Security and Data Protection.

Tip Number 3

Practice makes perfect! Do mock interviews with friends or use online platforms. The more comfortable you are speaking about your experience, the better you'll perform.

Tip Number 4

Don't forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, we love seeing candidates who take that extra step.

We think you need these skills to ace Information Security & Data Protection Manager

Information Security Management
Data Protection Compliance
ISO 27001
ISO 27701
Cyber Essentials
NIST CSF
Risk Assessment

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Information Security & Data Protection Manager role. Highlight relevant experience and skills that align with our job description, especially around ISO standards and data protection compliance.

Craft a Compelling Cover Letter:Your cover letter should tell us why you're the perfect fit for this role. Share specific examples of how you've managed information security frameworks or handled data protection issues in the past. Make it personal and engaging!

Showcase Your Knowledge:We want to see your understanding of current trends in information security and data protection. Mention any relevant certifications or training you've completed, and don’t hesitate to discuss your approach to emerging risks, especially in AI governance.

Apply Through Our Website:For the best chance of success, apply directly through our website. This ensures your application gets to the right people quickly and shows us you’re serious about joining the StudySmarter team!

How to prepare for a job interview at Focusrite

Know Your Frameworks

Familiarise yourself with ISO 27001, ISO 27701, and the Cyber Essentials standards. Be ready to discuss how you've applied these frameworks in previous roles, as this will show your practical understanding of information security and data protection.

Showcase Your Advisory Skills

Prepare examples of how you've advised teams on security and privacy requirements. Highlight specific instances where your guidance led to successful implementation of security controls or improved compliance, as this will demonstrate your ability to influence outcomes.

Stay Current on Regulations

Keep up to date with the latest developments in AI governance and data protection laws, such as the EU AI Act and UK GDPR. Being able to discuss recent changes and their implications will show that you're proactive and knowledgeable about the regulatory landscape.

Demonstrate Risk Management Experience

Be prepared to talk about your experience with risk assessments and incident management processes. Share specific examples of how you've identified and mitigated risks in past roles, as this will illustrate your capability in maintaining a robust security posture.