Cyber Security & Privacy Manager in London

Cyber Security & Privacy Manager in London

London Full-Time 48000 - 84000 Β£ / year (est.) No home office possible
Go Premium
I

At a Glance

  • Tasks: Lead cyber security and privacy initiatives across multiple platforms and ensure compliance.
  • Company: Join a forward-thinking organisation dedicated to safeguarding children and promoting well-being.
  • Benefits: Competitive salary, professional development, and a commitment to diversity and inclusion.
  • Why this job: Make a real impact in cyber security while ensuring the safety of learners.
  • Qualifications: 8-10 years in cyber security with strong expertise in risk management.
  • Other info: Dynamic role with opportunities for growth in a supportive environment.

The predicted salary is between 48000 - 84000 Β£ per year.

The ISP Cyber Security & Privacy Manager will own and operate ISP’s technology security and data privacy control framework across TDDA platforms, integrations, and data products. This role operationalises security-by-design and privacy-by-design across delivery, ensuring ISP operates with IPO-grade controls, audit-ready evidence, and consistent gating of change. The role is not advisory only β€” it has active decision rights to define controls and block non-compliant delivery.

Scope & Complexity

  • Enterprise-wide, multi-country environment
  • Operates across ERP, HRIS, SIS, CRM, EdTech, Data Platform, Integrations and AI products
  • Works with outsourced cyber partners but retains ISP accountability
  • Balances strong control with pragmatic delivery enablement

ISP Principles

  • Begin with our children and students. Our children and students are at the heart of what we do. Simply, their success is our success. Wellbeing and safety are both essential for learners and learning. Therefore, we are consistent in identifying potential safeguarding and Health & Safety issues and acting and following up on all concerns appropriately.
  • Treat everyone with care and respect. We look after one another, embrace similarities and differences and promote the well-being of self and others.
  • Operate effectively. We focus relentlessly on the things that are most important and will make the most difference. We apply school policies and procedures and embody the shared ideas of our community.
  • Are financially responsible. We make financial choices carefully based on the needs of the children, students and our schools.
  • Learn continuously. Getting better is what drives us. We positively engage with personal and professional development and school improvement.

Key Responsibilities

  • Security & Privacy Governance Operating Model
    • Design and operate TDDA security and privacy governance framework
    • Maintain TDDA technology risk register inputs
    • Establish security/privacy decision forums and cadence
    • Produce quarterly security & privacy posture report
  • Privacy-by-Design & DPIA Operations
    • Define DPIA thresholds and workflow
    • Own DPIA templates and guidance
    • Ensure DPIAs are embedded into demand-to-delivery process
    • Maintain DPIA register and evidence
  • Security Architecture Standards
    • Define mandatory security patterns for:
    • Identity & access management
    • Encryption (at rest & in transit)
    • Logging & monitoring
    • Segregation of duties
    • Key management
  • Delivery Gating & Controls
    • Ensure initiatives touching data, integrations or AI are security & privacy reviewed
    • Gate releases through CAB where controls are not met
    • Ensure security and privacy evidence is part of release readiness
  • Third-Party & Vendor Risk
    • Define minimum security/privacy assurance requirements
    • Support vendor due diligence
    • Maintain third-party assurance register
  • Audit & Evidence
    • Maintain audit-ready evidence packs:
    • Access reviews
    • DPIAs
    • Change logs
    • Third-party assurance
    • Support internal and external audits
  • Enablement
    • Define secure SDLC expectations with Engineering & Architecture
    • Provide training and guidance to TDDA teams
  • Decision Rights
    • Define mandatory security and privacy controls for TDDA delivery
    • Gate or block releases where controls are not met
    • Define minimum third-party assurance requirements

Key Responsibilities (Day-to-Day)

  • Run DPIA process
  • Maintain security standards catalogue
  • Review designs through Design Authority
  • Participate in CAB
  • Track and report risks

Key Deliverables (First 6 Months)

  • DPIA workflow live and embedded
  • TDDA security standards catalogue
  • Third-party assurance checklist
  • Quarterly security & privacy report
  • First full evidence pack

Success Measures / KPIs

  • 100% qualifying initiatives gated through DPIA & security review
  • Reduction in unknown integrations / shadow data flows
  • Audit evidence completeness and timeliness
  • Improved access governance (review completion, least privilege adoption)

Skills, Qualifications and Experience

  • 8–10+ years in cyber security and/or privacy operations
  • Experience in regulated, multi-country environments
  • Strong DPIA and vendor risk expertise
  • Risk-based thinking
  • Pragmatic control design
  • Clear communicator
  • Calm under pressure

ISP Commitment to Safeguarding Principles

ISP is committed to safeguarding and promoting the welfare of children and young people and expects all staff and volunteers to share this commitment. All post holders are subject to appropriate vetting procedures, including an online due diligence search, references and satisfactory Criminal Background Checks or equivalent covering the previous 10 years’ employment history.

ISP Commitment to Diversity, Equity, Inclusion, and Belonging

ISP is committed to strengthening our inclusive culture by identifying, hiring, developing, and retaining high-performing teammates regardless of gender, ethnicity, sexual orientation and gender expression, age, disability status, neurodivergence, socio-economic background or other demographic characteristics. Candidates who share our vision and principles and are interested in contributing to the success of ISP through this role are strongly encouraged to apply.

Cyber Security & Privacy Manager in London employer: International Schools Partnership Limited

At ISP, we pride ourselves on being an exceptional employer, offering a dynamic work environment that prioritises the well-being and safety of our children and students. Our commitment to continuous learning and professional development ensures that employees have ample opportunities for growth, while our inclusive culture fosters respect and collaboration among diverse teams. Located in a multi-country setting, the role of Cyber Security & Privacy Manager not only provides the chance to make a meaningful impact but also offers the unique advantage of working with cutting-edge technology in a supportive and audit-ready framework.
I

Contact Detail:

International Schools Partnership Limited Recruiting Team

StudySmarter Expert Advice 🀫

We think this is how you could land Cyber Security & Privacy Manager in London

✨Tip Number 1

Network like a pro! Get out there and connect with people in the cyber security and privacy field. Attend industry events, webinars, or even local meetups. You never know who might have the inside scoop on job openings or can put in a good word for you.

✨Tip Number 2

Show off your skills! Create a personal project or contribute to open-source initiatives related to cyber security. This not only boosts your portfolio but also demonstrates your hands-on experience and passion for the field.

✨Tip Number 3

Prepare for interviews by practising common questions specific to cyber security and privacy roles. Think about how your experience aligns with the responsibilities listed in the job description. We want to see you shine!

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who are genuinely interested in joining our mission to keep data safe and secure.

We think you need these skills to ace Cyber Security & Privacy Manager in London

Cyber Security Operations
Data Privacy Management
DPIA Expertise
Risk Assessment
Security Governance Framework
Vendor Risk Management
Audit Compliance
Security Architecture Standards
Identity & Access Management
Encryption Techniques
Communication Skills
Calm Under Pressure
Pragmatic Control Design
Multi-Country Regulatory Knowledge
Training and Guidance Provision

Some tips for your application 🫑

Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience in cyber security and privacy. Use keywords from the job description to show that you understand what we're looking for.

Showcase Relevant Experience: When detailing your work history, focus on your achievements in similar roles. Mention specific projects or initiatives where you've implemented security and privacy controls, especially in multi-country environments.

Be Clear and Concise: Keep your application straightforward and to the point. We appreciate clarity, so avoid jargon and ensure your key skills and experiences shine through without unnecessary fluff.

Apply Through Our Website: We encourage you to submit your application directly through our website. This way, we can ensure your application is reviewed promptly and you’re considered for this exciting opportunity!

How to prepare for a job interview at International Schools Partnership Limited

✨Know Your Stuff

Make sure you brush up on your cyber security and privacy knowledge, especially around DPIAs and risk management. Familiarise yourself with the latest trends and regulations in the field, as well as the specific technologies mentioned in the job description.

✨Showcase Your Experience

Prepare to discuss your past experiences in cyber security and privacy operations. Be ready to share specific examples of how you've implemented security frameworks or managed vendor risks in multi-country environments. This will demonstrate your hands-on expertise.

✨Understand Their Values

ISP places a strong emphasis on the wellbeing of children and students. Be prepared to discuss how your approach to cyber security aligns with their commitment to safeguarding and promoting welfare. Show that you understand the importance of these principles in your work.

✨Ask Smart Questions

Prepare thoughtful questions about the role and the company’s approach to security and privacy. Inquire about their current challenges or initiatives related to data protection and how they measure success. This shows your genuine interest and strategic thinking.

Cyber Security & Privacy Manager in London
International Schools Partnership Limited
Location: London
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

I
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>