Assistant Manager Information Security in London

Assistant Manager Information Security in London

London Full-Time 60000 - 60000 £ / year (est.) Home office (partial)
I

At a Glance

  • Tasks: Protect the bank's data and ensure compliance with security standards.
  • Company: Join a leading bank focused on information security and resilience.
  • Benefits: Enjoy 25 days leave, private medical insurance, and hybrid working options.
  • Other info: Dynamic role with opportunities for continuous learning and career growth.
  • Why this job: Make a real impact in safeguarding vital information assets.
  • Qualifications: 5+ years in cyber security and relevant certifications preferred.

The predicted salary is between 60000 - 60000 £ per year.

Description

The role plays a vital role in safeguarding the bank’s information assets and data, and in maintaining the governance frameworks that evidence a resilient and well-controlled security posture.

The role is primarily focused on information / cyber security, data protection and resilience maintaining the ISO 27001:2022 Information Security Management System (ISMS), supporting the bank’s data protection obligations and upkeeping cyber resilience, and providing management with timely, accurate and risk-focused reporting on the bank’s security and compliance posture.

The role proactively supports the bank’s compliance with UK regulatory requirements, industry standards and best practice, while contributing to the development and enhancement of security and data protection frameworks, policies and controls.

It also supports the bank’s operational resilience; business continuity and IT disaster recovery arrangements.

Drawing on strong analytical skills, sound knowledge of cyber security and data protection, and an understanding of the bank’s security infrastructure (including AWS cloud environments), the role helps the bank maintain cyber and operational resilience, protect against financial and reputational risk, and foster a culture of sound security across the organisation.

MAIN DUTIES

  • Information Security & Risk Management
  • Maintain and continuously improve the ISO 27001:2022 ISMS, including the Statement of Applicability, information security policies, standards and procedures, and the supporting documentation register, ensuring they remain current, mapped to control frameworks and audit-ready.
  • Provide proactive security and data protection assurance for new initiatives, change and ongoing projects, ensuring security-by-design and privacy-by-design requirements are embedded from design through implementation.
  • Conduct information security risk assessments to identify, evaluate and prioritise threats and control gaps, ensuring effective controls are agreed, implemented, tracked to closure and reflected in the risk register.
  • Define, document and drive adoption of security controls that protect information flows across internal systems, third parties and public networks, in line with the ISMS and regulatory requirements.
  • Act as the governance and oversight interface to the bank’s cyber security operations, liaising with the specialist technical teams that run day-to-day security monitoring, detection and remediation, rather than performing these activities hands-on.
  • Conduct and coordinate threat intelligence and vulnerability management interpreting relevant intelligence, tracking identified vulnerabilities against remediation SLAs, coordinating timely remediation with technology teams and external providers, and keeping abreast of the evolving threat landscape.
  • Support the maintenance and testing of incident response and crisis management procedures, contributing to the effective triage, coordination and post-incident review of security and data protection events while minimising business disruption.
  • Act as support for the bank’s operational resilience and business continuity arrangements, and working closely relevant stakeholders and IT on disaster recovery.
  • Conduct and contribute to business impact analyses, business continuity and IT disaster recovery plans and their testing (including the AWS cloud environment), helping ensure recovery objectives (RTO / RPO) are documented, achievable and evidenced, with lessons learned fed into improvements.
  • Data Protection Governance
  • Support the Data Protection Officer in operating the bank’s data protection framework under UK GDPR and applicable regulations.
  • Maintain the Record of Processing Activities (ROPA) and support data retention, data minimisation and records-management governance across the bank.
  • Support the handling of Data Subject Access Requests (DSARs) and other data subject rights, and the completion of Data Protection Impact Assessments (DPIAs) for new or changed processing.
  • Assess personal data breaches, contributing to containment, root-cause analysis and the assessment of notification obligations to the ICO and affected individuals within regulatory timeframes.
  • Contribute to data protection and processor due diligence within third-party and outsourcing arrangements.
  • Third-Party & Supply Chain Security
  • Perform and govern security and data protection due diligence and ongoing assurance of suppliers, processors and critical third parties, in line with supplier controls and regulatory expectations on outsourcing and third-party risk.
  • Track third-party findings, remediation actions and assurance evidence (e. g. certifications, attestations, control reports), escalating material risks as appropriate.
  • Assurance, Compliance & Reporting
  • Partner with auditors, regulators and payment schemes by preparing evidence, providing subject-matter expertise, and supporting internal and external audits, certifications and reviews (including ISO 27001 surveillance and scheme assurance such as CHAPS, FPS, Bacs and SWIFT CSP).
  • Advise stakeholders on information security and data protection regulatory obligations including breach assessment and notification helping the bank meet its regulatory and applicable payment scheme assurance expectations.
  • Evaluate and enhance the effectiveness of the bank’s information security and data protection policies, procedures and controls, driving continuous improvement and closure of audit and assessment findings.
  • Produce timely, accurate and risk-focused management reporting including metrics, key risk indicators (KRIs), dashboards and committee packs on security posture, incidents, vulnerabilities, data protection and compliance activities.
  • GENERAL
  • Act as a first point of contact for information security and data protection queries, alerts and events, coordinating responses via the bank’s incident management protocols and escalating to the Head of Information Security & Resilience as appropriate.
  • Undertake day-to-day administrative tasks, reporting and communication with relevant departments across the organisation.
  • Maintain security and data protection records, control documentation, dashboards and reports.
  • Assist in conducting reviews and assessments to identify and report potential vulnerabilities, weaknesses and threats.
  • Support the implementation, monitoring and governance of security controls that protect the bank’s data, systems and networks.
  • Support the delivery of security awareness and data protection training to foster a strong risk aware culture across the bank.

Requirements

EDUCATION & TRAINING

  • Bachelor’s degree in Information / Cyber Security, Computer Science or a related discipline; equivalent professional experience may be considered.
  • Relevant professional certifications are strongly preferred, for example CISM, CISSP, ISO 27001 Lead Implementer / Lead Auditor.

Technology-centric training and certification is an advantage.

EXPERIENCE AND SKILLS

  • 5+ years’ experience in information and cyber security implementation, management and governance, ideally within UK financial services, covering ISMS management, risk management, and management reporting.
  • Working knowledge of information security and data protection frameworks and regulation, including ISO 27001:2022, NIST CSF, UK GDPR, and awareness of FCA / PRA and payment scheme expectations.
  • Sound understanding of the cyber threat landscape, threat intelligence, vulnerability management and incident / breach management, with the ability to interpret events and drive effective remediation.
  • Working knowledge with security technologies and controls (e. g., Perimeter/edge security controls, data protection controls, SIEM / monitoring controls) and cloud security.
  • Exposure to operational resilience, business continuity (ISO 22301) and IT disaster recovery, with awareness of FCA / PRA operational resilience expectations (SYSC 15A / SS1/21).
  • Excellent analytical, written and stakeholder-engagement skills, with the ability to produce audit-ready documentation and influence decision-making across technical and non-technical audiences.
  • Committed to continuous learning, keeping up to date with evolving threats, technologies and regulatory requirements.

Benefits

  • 25 days annual leave entitlement plus 8 bank holidays
  • Pension scheme, 4% employer contribution
  • Private Medical Insurance
  • 60-40 Hybrid working after successful probation period
  • Training and development
  • Free gym access in the building

Assistant Manager Information Security in London employer: iFAST Global Bank

iFAST Global Bank Limited (iGB) is an exceptional employer that fosters a dynamic and collaborative work culture, ideal for professionals seeking to make a significant impact in the financial sector. With a strong focus on employee growth, iGB offers comprehensive training and development opportunities, competitive salaries, and a flexible working arrangement that promotes work-life balance. Located in a vibrant area, employees also enjoy additional perks such as private medical insurance and free gym access, making it a rewarding place to advance your career as a Senior Credit Executive.

I

Contact Details:

iFAST Global Bank Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Assistant Manager Information Security in London

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including iFAST Global Bank, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through iFAST Global Bank

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at iFAST Global Bank. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Assistant Manager Information Security in London

Information Security Management System (ISMS)
ISO 27001:2022
Data Protection
Cyber Security
Risk Management
Threat Intelligence
Vulnerability Management

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at iFAST Global Bank insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to iFAST Global Bank that you’re committed to staying ahead in the game.

How to prepare for a job interview at iFAST Global Bank

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at iFAST Global Bank to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at iFAST Global Bank.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.