Senior ISO 27001 ISMS Lead (Governance & Audits) in Birmingham

Senior ISO 27001 ISMS Lead (Governance & Audits) in Birmingham

Birmingham Full-Time 60000 - 80000 £ / year (est.) Home office (partial)
Gateley

At a Glance

  • Tasks: Lead the implementation and management of ISO 27001 accreditation, ensuring robust controls and compliance.
  • Company: Join Gateley Plc, a dynamic tech-driven company with a collaborative culture.
  • Benefits: Enjoy competitive pay, flexible working, and a range of perks including wellness programmes and learning opportunities.
  • Other info: Diversity and inclusion are key; we welcome applicants from all backgrounds.
  • Why this job: Make a real impact on information security while developing your career in a supportive environment.
  • Qualifications: Strong knowledge of ISO 27001 and experience in managing information security systems required.

The predicted salary is between 60000 - 80000 £ per year.

We are looking to appoint a senior role to lead both the implementation and ongoing management of our ISO 27001 accreditation. This role will play a key part in designing and embedding the management system, before taking full ownership of its day‑to‑day operation, governance, and continuous improvement. Working closely with IT, Professional Standards and teams across the business, the role will ensure controls are robust, risks are effectively managed, and audit requirements are consistently met. There will be a significant focus on implementation in the initial phase, transitioning into long‑term ownership of the standard. This includes driving compliance, leading audit activities, overseeing risk management, and delivering clear reporting, alongside embedding a culture of information security across the organisation.

Candidates must have strong working knowledge of ISO 27001 and demonstrable experience in implementing and managing compliant information security management systems. You will develop a strong understanding of Gateley’s ISO 27001 accreditation and play a central role in both its implementation and ongoing management.

Key Responsibilities
  • Leading the implementation, embedding and ongoing management of the ISO 27001 Information Security Management System (ISMS)
  • Managing, maintaining and continuously improving ISO 27001 certification, ensuring ongoing compliance with the standard
  • Owning and developing the firm’s ISO 27001 documentation, ensuring policies, procedures, records and controls are robust, up to date and effectively managed
  • Leading internal audit activity, including planning, execution, reporting and ensuring timely closure of actions, with clear updates to senior stakeholders
  • Preparing for and managing external audits, acting as the primary point of contact for assessors and coordinating internal stakeholders
  • Chairing and supporting governance forums, including preparing agendas, papers, and tracking actions through to completion
  • Providing expert guidance to teams across the business on ISO 27001 and information security requirements, ensuring controls are understood and consistently applied
  • Driving awareness and engagement across the organisation to embed a strong information security culture
  • Managing client and supplier assurance activity, including responding to ISO 27001 security questionnaires and due diligence requests
  • Working closely with IT, Professional Standards, Risk, HR and Operations to ensure controls are effectively embedded and operating as intended
  • Leading the implementation and ongoing oversight of the ISO 27001 risk management framework and associated documentation
  • Driving risk identification, assessment, treatment and monitoring activities across the business
  • Working closely with risk owners to ensure risk registers, incident logs and supporting records are accurate, up to date and effectively managed
  • Facilitating regular risk reviews and ensuring timely progression of mitigation and improvement actions
Quality & Continuous Improvement
  • Championing high standards of governance, documentation and control effectiveness across the ISMS
  • Identifying and driving opportunities to strengthen processes, controls and ways of working
  • Embedding a culture of continuous improvement across information security practices, aligned to ISO 27001 requirements

This role will take a leading position in both the implementation and subsequent ownership of ISO 27001, with a strong focus on embedding sustainable controls, maintaining compliance, and driving ongoing improvement across the organisation.

Person

Candidates will be able to demonstrate the following attributes:

  • Strong working knowledge of ISO 27001, with demonstrable experience implementing and managing compliant information security management systems
  • Proven ability to design, embed and improve governance, controls and documentation within a regulated or professional services environment
  • Excellent attention to detail, with a focus on accuracy, quality and control effectiveness
  • Strong stakeholder management and communication skills, with the ability to influence and challenge at all levels of the business
  • Ability to manage multiple priorities independently, with a proactive and structured approach
  • Experience of planning, leading and chairing meetings, including governance forums
  • Comfortable working cross‑functionally, building effective relationships across IT, Risk, HR and Operations
  • High levels of professionalism, discretion and integrity when handling sensitive information
  • Ability to work effectively under pressure and respond to changing priorities within a delivery environment
  • Strong organisational and documentation management skills, including experience with Microsoft Office and document management systems
Desirable / Beneficial
  • Degree-level education or equivalent professional experience
  • Experience working with ISO management systems, particularly ISO 27001, with working knowledge of ISO 9001 beneficial
  • Experience within a professional services or regulated environment
  • Strong understanding of regulatory and compliance frameworks within a legal or professional services business
  • Ability to operate across multiple standards and frameworks where required, supporting broader quality and compliance initiatives
Benefits

With support, coaching and feedback from some of the most engaging colleagues around our great development and progression opportunities will reward your commitment and loyalty. We offer a competitive remuneration package where you’ll be rewarded for your individual performance with an opportunity to receive an annual bonus. In addition, we have a wide range of learning and development opportunities via our Learn platform to develop new skills and progress your career. Our My Flex comprehensive rewards package includes options covering annual leave (and the benefit of purchasing extra days), cycle to work, critical illness benefit, employee assistance programme, group personal pension, health care, season ticket loan and many more benefits (grade dependent). Finally, with Perks At Work/Home you can select a host of retail benefits that suit your needs alongside a Community Online Academy, free courses for all from fitness to coding to languages to hip hop dance.

Diversity, inclusion and well being

Diversity, inclusion and well being is an important part of Gateley’s culture and values. We recruit talented people from a diverse range of backgrounds and cultures, providing equal opportunities for all to join our team regardless of age, sex, race, sexual orientation, disability, or culture. We create an exciting and rewarding place to work that aims to fulfil everyone’s potential and together to achieve personal and business goals. We offer flexible working patterns to help our staff achieve a good work‑life balance and we encourage candidates seeking flexibility in their next role to apply for any of our vacancies.

Senior ISO 27001 ISMS Lead (Governance & Audits) in Birmingham employer: Gateley

At Gateley Plc, we pride ourselves on being an exceptional employer, offering a dynamic and collaborative work environment that fosters innovation and professional growth. Our commitment to employee development is reflected in our comprehensive benefits package, which includes competitive remuneration, flexible working options, and extensive learning opportunities through our Learn platform. Join us in a culture that values diversity, inclusion, and well-being, where your contributions are recognised and rewarded, making it a truly fulfilling place to advance your career in information security management.

Gateley

Contact Details:

Gateley Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior ISO 27001 ISMS Lead (Governance & Audits) in Birmingham

Tip Number 1

Network like a pro! Reach out to your connections in the industry, especially those who have experience with ISO 27001. A friendly chat can lead to insider info about job openings or even a referral.

Tip Number 2

Prepare for interviews by brushing up on your ISO 27001 knowledge. Be ready to discuss how you've implemented and managed ISMS in the past. We want to hear your success stories!

Tip Number 3

Showcase your soft skills! Communication and stakeholder management are key in this role. Think of examples where you’ve influenced decisions or led teams effectively.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, we love seeing candidates who take that extra step to connect with us directly.

We think you need these skills to ace Senior ISO 27001 ISMS Lead (Governance & Audits) in Birmingham

ISO 27001
Information Security Management Systems (ISMS)
Governance
Audit Management
Risk Management
Stakeholder Management
Communication Skills

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience with ISO 27001. We want to see how your skills align with the role, so don’t hold back on showcasing your relevant achievements!

Showcase Your Governance Skills:Since this role is all about governance and audits, be sure to include specific examples of how you've designed and implemented controls in previous roles. We love seeing real-life applications of your expertise!

Be Clear and Concise:When writing your application, keep it straightforward and to the point. Use bullet points where possible to make it easy for us to read through your qualifications and experiences quickly.

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it’s super easy!

How to prepare for a job interview at Gateley

Know Your ISO 27001 Inside Out

Make sure you have a solid grasp of ISO 27001 principles and practices. Brush up on your knowledge of the standard, its requirements, and how it applies to information security management systems. Be ready to discuss specific examples from your past experiences where you've successfully implemented or managed these standards.

Prepare for Scenario-Based Questions

Expect questions that ask you to demonstrate how you would handle real-world situations related to governance, audits, and risk management. Think about challenges you've faced in previous roles and how you overcame them. Use the STAR method (Situation, Task, Action, Result) to structure your answers effectively.

Showcase Your Stakeholder Management Skills

This role requires strong communication and stakeholder management abilities. Prepare to discuss how you've influenced and engaged with various teams in the past. Highlight your experience in chairing meetings and leading governance forums, as well as how you ensure everyone is on the same page regarding compliance and security practices.

Demonstrate a Culture of Continuous Improvement

Be ready to talk about how you've driven improvements in processes and controls within an organisation. Share specific examples of how you've identified opportunities for enhancement and successfully implemented changes. This will show your commitment to not just maintaining standards but also advancing them.