At a Glance
- Tasks: Lead the implementation and management of ISO 27001 accreditation, ensuring robust information security.
- Company: Join Gateley Plc, a forward-thinking legal and professional services group.
- Benefits: Enjoy competitive pay, flexible working, and extensive learning opportunities.
- Other info: Be part of a diverse team that values collaboration and continuous improvement.
- Why this job: Make a real impact on information security while developing your career in a dynamic environment.
- Qualifications: Strong knowledge of ISO 27001 and experience in managing information security systems required.
The predicted salary is between 45000 - 55000 £ per year.
We are looking to appoint a senior role to lead both the implementation and ongoing management of our ISO 27001 accreditation. This role will play a key part in designing and embedding the management system, before taking full ownership of its day-to-day operation, governance, and continuous improvement. Working closely with IT, Professional Standards and teams across the business, the role will ensure controls are robust, risks are effectively managed, and audit requirements are consistently met.
There will be a significant focus on implementation in the initial phase, transitioning into long-term ownership of the standard. This includes driving compliance, leading audit activities, overseeing risk management, and delivering clear reporting, alongside embedding a culture of information security across the organisation.
Candidates must have strong working knowledge of ISO 27001 and demonstrable experience in implementing and managing compliant information security management systems. You will develop a strong understanding of Gateley’s ISO 27001 accreditation and play a central role in both its implementation and ongoing management.
Key Responsibilities:
- Leading the implementation, embedding and ongoing management of the ISO 27001 Information Security Management System (ISMS).
- Managing, maintaining and continuously improving ISO 27001 certification, ensuring ongoing compliance with the standard.
- Owning and developing the firm’s ISO 27001 documentation, ensuring policies, procedures, records and controls are robust, up to date and effectively managed.
- Leading internal audit activity, including planning, execution, reporting and ensuring timely closure of actions, with clear updates to senior stakeholders.
- Preparing for and managing external audits, acting as the primary point of contact for assessors and coordinating internal stakeholders.
- Chairing and supporting governance forums, including preparing agendas, papers, and tracking actions through to completion.
- Providing expert guidance to teams across the business on ISO 27001 and information security requirements, ensuring controls are understood and consistently applied.
- Driving awareness and engagement across the organisation to embed a strong information security culture.
- Managing client and supplier assurance activity, including responding to ISO 27001 security questionnaires and due diligence requests.
- Working closely with IT, Professional Standards, Risk, HR and Operations to ensure controls are effectively embedded and operating as intended.
Risk Management Coordination:
- Leading the implementation and ongoing oversight of the ISO 27001 risk management framework and associated documentation.
- Driving risk identification, assessment, treatment and monitoring activities across the business.
- Working closely with risk owners to ensure risk registers, incident logs and supporting records are accurate, up to date and effectively managed.
- Facilitating regular risk reviews and ensuring timely progression of mitigation and improvement actions.
Quality & Continuous Improvement:
- Championing high standards of governance, documentation and control effectiveness across the ISMS.
- Identifying and driving opportunities to strengthen processes, controls and ways of working.
- Embedding a culture of continuous improvement across information security practices, aligned to ISO 27001 requirements.
This role will take a leading position in both the implementation and subsequent ownership of ISO 27001, with a strong focus on embedding sustainable controls, maintaining compliance, and driving ongoing improvement across the organisation.
The team at Gateley Plc is a dynamic and collaborative environment where innovation thrives. Over recent years, we have expanded our team to include over 60 professionals who are dedicated to driving technological excellence and delivering innovative solutions. Our diverse team is structured across several key areas: IT Service, Infrastructure, Architecture, Security, Change Management, Engineering, Innovation and Client Solutions.
We value collaboration, continuous learning, and professional growth. This role will work in close partnership with the Professional Regulations and Standards team, ensuring a joined-up and consistent approach to governance, compliance, and risk management across the business.
The person:
- Strong working knowledge of ISO 27001, with demonstrable experience implementing and managing compliant information security management systems.
- Proven ability to design, embed and improve governance, controls and documentation within a regulated or professional services environment.
- Excellent attention to detail, with a focus on accuracy, quality and control effectiveness.
- Strong stakeholder management and communication skills, with the ability to influence and challenge at all levels of the business.
- Ability to manage multiple priorities independently, with a proactive and structured approach.
- Experience of planning, leading and chairing meetings, including governance forums.
- Comfortable working cross-functionally, building effective relationships across IT, Risk, HR and Operations.
- High levels of professionalism, discretion and integrity when handling sensitive information.
- Ability to work effectively under pressure and respond to changing priorities within a delivery environment.
- Strong organisational and documentation management skills, including experience with Microsoft Office and document management systems.
Desirable / Beneficial:
- Degree-level education or equivalent professional experience.
- Experience working with ISO management systems, particularly ISO 27001, with working knowledge of ISO 9001 beneficial.
- Experience within a professional services or regulated environment.
- Strong understanding of regulatory and compliance frameworks within a legal or professional services business.
- Ability to operate across multiple standards and frameworks where required, supporting broader quality and compliance initiatives.
This job description is not an exhaustive list due to the requirements of the role. Therefore, the job holder may be required from time to time to carry out other ad hoc tasks as requested.
ISMS Manager in Birmingham employer: Gateley
Gateley is an exceptional employer located in the vibrant city of Manchester, offering a dynamic work culture that fosters collaboration and innovation. As a Graduate Structural Engineer, you will benefit from a competitive remuneration package, generous annual leave, and ample opportunities for professional development, ensuring your growth in the engineering field. Join a supportive team that values your contributions and encourages you to make a meaningful impact in your career.
StudySmarter Expert Advice🤫
We think this is how you could land ISMS Manager in Birmingham
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Gateley, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Gateley
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Gateley. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace ISMS Manager in Birmingham
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Gateley insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Gateley that you’re committed to staying ahead in the game.
How to prepare for a job interview at Gateley
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Gateley to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Gateley.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.