At a Glance
- Tasks: Lead cyber security and privacy initiatives across multiple platforms and ensure compliance.
- Company: Join a forward-thinking organisation dedicated to safeguarding children and promoting well-being.
- Benefits: Competitive salary, professional development opportunities, and a supportive work environment.
- Why this job: Make a real difference in protecting data and privacy while working with cutting-edge technology.
- Qualifications: 8-10 years in cyber security or privacy operations with strong risk management skills.
- Other info: Diverse and inclusive workplace committed to personal and professional growth.
The predicted salary is between 48000 - 72000 £ per year.
The ISP Cyber Security & Privacy Manager will own and operate ISP’s technology security and data privacy control framework across TDDA platforms, integrations, and data products. This role operationalises security-by-design and privacy-by-design across delivery, ensuring ISP operates with IPO-grade controls, audit-ready evidence, and consistent gating of change. The role is not advisory only — it has active decision rights to define controls and block non-compliant delivery.
Scope & Complexity
- Enterprise-wide, multi-country environment
- Operates across ERP, HRIS, SIS, CRM, EdTech, Data Platform, Integrations and AI products
- Works with outsourced cyber partners but retains ISP accountability
- Balances strong control with pragmatic delivery enablement
ISP Principles
- Begin with our children and students. Our children and students are at the heart of what we do. Simply, their success is our success. Wellbeing and safety are both essential for learners and learning. Therefore, we are consistent in identifying potential safeguarding and Health & Safety issues and acting and following up on all concerns appropriately.
- Treat everyone with care and respect. We look after one another, embrace similarities and differences and promote the well-being of self and others.
- Operate effectively. We focus relentlessly on the things that are most important and will make the most difference. We apply school policies and procedures and embody the shared ideas of our community.
- Are financially responsible. We make financial choices carefully based on the needs of the children, students and our schools.
- Learn continuously. Getting better is what drives us. We positively engage with personal and professional development and school improvement.
Key Responsibilities
- Security & Privacy Governance Operating Model
- Design and operate TDDA security and privacy governance framework
- Maintain TDDA technology risk register inputs
- Establish security/privacy decision forums and cadence
- Produce quarterly security & privacy posture report
- Privacy-by-Design & DPIA Operations
- Define DPIA thresholds and workflow
- Own DPIA templates and guidance
- Ensure DPIAs are embedded into demand-to-delivery process
- Maintain DPIA register and evidence
- Security Architecture Standards
- Define mandatory security patterns for:
- Identity & access management
- Encryption (at rest & in transit)
- Logging & monitoring
- Segregation of duties
- Key management
- Delivery Gating & Controls
- Ensure initiatives touching data, integrations or AI are security & privacy reviewed
- Gate releases through CAB where controls are not met
- Ensure security and privacy evidence is part of release readiness
- Third-Party & Vendor Risk
- Define minimum security/privacy assurance requirements
- Support vendor due diligence
- Maintain third-party assurance register
- Audit & Evidence
- Maintain audit-ready evidence packs:
- Access reviews
- DPIAs
- Change logs
- Third-party assurance
- Support internal and external audits
- Enablement
- Define secure SDLC expectations with Engineering & Architecture
- Provide training and guidance to TDDA teams
- Decision Rights
- Define mandatory security and privacy controls for TDDA delivery
- Gate or block releases where controls are not met
- Define minimum third-party assurance requirements
Key Responsibilities (Day-to-Day)
- Run DPIA process
- Maintain security standards catalogue
- Review designs through Design Authority
- Participate in CAB
- Track and report risks
Key Deliverables (First 6 Months)
- DPIA workflow live and embedded
- TDDA security standards catalogue
- Third-party assurance checklist
- Quarterly security & privacy report
- First full evidence pack
Success Measures / KPIs
- 100% qualifying initiatives gated through DPIA & security review
- Reduction in unknown integrations / shadow data flows
- Audit evidence completeness and timeliness
- Improved access governance (review completion, least privilege adoption)
Skills, Qualifications and Experience
- 8–10+ years in cyber security and/or privacy operations
- Experience in regulated, multi-country environments
- Strong DPIA and vendor risk expertise
- Risk-based thinking
- Pragmatic control design
- Clear communicator
- Calm under pressure
ISP Commitment to Safeguarding Principles
ISP is committed to safeguarding and promoting the welfare of children and young people and expects all staff and volunteers to share this commitment. All post holders are subject to appropriate vetting procedures, including an online due diligence search, references and satisfactory Criminal Background Checks or equivalent covering the previous 10 years’ employment history.
ISP Commitment to Diversity, Equity, Inclusion, and Belonging
ISP is committed to strengthening our inclusive culture by identifying, hiring, developing, and retaining high-performing teammates regardless of gender, ethnicity, sexual orientation and gender expression, age, disability status, neurodivergence, socio-economic background or other demographic characteristics. Candidates who share our vision and principles and are interested in contributing to the success of ISP through this role are strongly encouraged to apply.
Cyber Security & Privacy Manager in London employer: International Schools Partnership
Contact Detail:
International Schools Partnership Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Cyber Security & Privacy Manager in London
✨Tip Number 1
Network like a pro! Get out there and connect with people in the cyber security and privacy field. Attend industry events, webinars, or even local meetups. You never know who might have the inside scoop on job openings or can refer you to someone looking for your skills.
✨Tip Number 2
Showcase your expertise! Create a personal website or LinkedIn profile that highlights your experience in cyber security and privacy. Share articles, insights, or projects you've worked on. This not only demonstrates your knowledge but also makes you more memorable to potential employers.
✨Tip Number 3
Prepare for interviews like a champ! Research the company and its values, especially their commitment to safeguarding and diversity. Be ready to discuss how your experience aligns with their mission and how you can contribute to their goals in cyber security and privacy.
✨Tip Number 4
Apply through our website! We love seeing candidates who are genuinely interested in joining our team. Make sure to tailor your application to highlight your relevant experience and how it fits with the role of Cyber Security & Privacy Manager. Let's get you on board!
We think you need these skills to ace Cyber Security & Privacy Manager in London
Some tips for your application 🫡
Tailor Your CV: Make sure your CV speaks directly to the Cyber Security & Privacy Manager role. Highlight relevant experience, especially in cyber security and privacy operations, and don’t forget to mention any work in regulated environments!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you’re passionate about this role and how your skills align with ISP’s commitment to safeguarding and promoting the welfare of children and young people.
Showcase Your Achievements: When detailing your experience, focus on specific achievements that demonstrate your expertise in DPIA processes, vendor risk management, and security governance. Numbers and outcomes can really make your application stand out!
Apply Through Our Website: We encourage you to apply through our website for a smoother process. It helps us keep track of applications and ensures you don’t miss out on any important updates from us!
How to prepare for a job interview at International Schools Partnership
✨Know Your Stuff
Make sure you brush up on your cyber security and privacy knowledge. Understand the key responsibilities of the role, especially around DPIA processes and security governance frameworks. Being able to discuss these topics confidently will show that you're serious about the position.
✨Showcase Your Experience
Prepare specific examples from your past roles that demonstrate your expertise in managing security and privacy controls. Highlight your experience in regulated environments and how you've successfully navigated challenges in multi-country settings.
✨Understand Their Values
ISP places a strong emphasis on the well-being of children and students. Be ready to discuss how your values align with theirs, particularly around safeguarding and promoting welfare. This will help you connect on a personal level during the interview.
✨Ask Smart Questions
Prepare thoughtful questions that show your interest in the role and the company. Inquire about their current security challenges or how they measure success in the Cyber Security & Privacy Manager role. This not only demonstrates your enthusiasm but also gives you valuable insights into the company culture.