Assistant Manager – Information Security

Assistant Manager – Information Security

Full-Time No working from home possible
J
  • Maintain and continuously improve the ISO 27001:2022 Information Security Management System, including policies, standards, procedures, documentation and Statement of Applicability.
  • Provide security and data protection assurance for new initiatives, changes and projects, embedding security-by-design and privacy-by-design.
  • Conduct information security risk assessments, prioritise threats and control gaps, track remediation and maintain the risk register.
  • Define, document and drive adoption of security controls across internal systems, third parties and public networks.
  • Provide governance and oversight to cyber security operations and liaise with specialist technical teams.
  • Coordinate threat intelligence and vulnerability management, remediation SLAs and external providers.
  • Support incident response, crisis management, operational resilience, business continuity and IT disaster recovery, including AWS cloud environments.
  • Support the Data Protection Officer with UK GDPR governance, ROPA, data retention, DSARs, DPIAs and personal data breach assessments.
  • Perform and govern security and data protection due diligence for suppliers, processors and critical third parties.
  • Partner with auditors, regulators and payment schemes; prepare evidence and support audits, certifications and reviews including ISO 27001, CHAPS, FPS, Bacs and SWIFT CSP.
  • Produce management reporting, metrics, KRIs, dashboards and committee packs on security posture, incidents, vulnerabilities, data protection and compliance.
  • Act as a first point of contact for security and data protection queries, alerts and events; maintain records and documentation.
  • Support security control reviews, vulnerability assessments, security awareness and data protection training.

Requirements

  • Bachelor’s degree in Information / Cyber Security, Computer Science or a related discipline; equivalent professional experience may be considered.
  • Relevant professional certifications are strongly preferred, for example CISM, CISSP, ISO 27001 Lead Implementer / Lead Auditor.
  • Technology-centric training and certification is an advantage.
  • 5+ years’ experience in information and cyber security implementation, management and governance, ideally within UK financial services, covering ISMS management, risk management, and management reporting.
  • Working knowledge of information security and data protection frameworks and regulation, including ISO 27001:2022, NIST CSF, UK GDPR, and awareness of FCA / PRA and payment scheme expectations.
  • Sound understanding of the cyber threat landscape, threat intelligence, vulnerability management and incident / breach management, with the ability to interpret events and drive effective remediation.
  • Working knowledge with security technologies and controls, including perimeter/edge security controls, data protection controls, SIEM / monitoring controls and cloud security.
  • Exposure to operational resilience, business continuity (ISO 22301) and IT disaster recovery, with awareness of FCA / PRA operational resilience expectations (SYSC 15A / SS1/21).
  • Excellent analytical, written and stakeholder-engagement skills, with the ability to produce audit-ready documentation and influence decision-making across technical and non-technical audiences.
  • Committed to continuous learning and keeping up to date with evolving threats, technologies and regulatory requirements.

Core Competencies

Demonstrates expertise in maintaining and improving ISO 27001:2022 Information Security Management Systems, conducting risk assessments, and ensuring compliance with UK GDPR and other regulatory frameworks. Proficient in incident response, vulnerability management, and producing audit-ready documentation for stakeholders.

Highest-signal resume keywords

  • ISO 27001:2022 Management
  • Information Security Risk Assessment
  • UK GDPR Compliance
  • Vulnerability Management
  • Incident Response

Hard Skills

  • Information Security Management
  • Risk Management
  • Data Protection Governance
  • Security Control Implementation
  • Threat Intelligence Analysis
  • Vulnerability Assessment
  • Business Continuity Planning
  • IT Disaster Recovery
  • Audit Documentation
  • Operational Resilience

Soft Skills

  • Analytical Skills
  • Stakeholder Engagement
  • Written Communication
  • Decision-Making InfluenceContinuous Learning

Certifications & Qualifications

  • CISM
  • CISSP
  • ISO 27001 Lead Implementer
  • ISO 27001 Lead Auditor

Industry Keywords

  • UK Financial Services
  • NIST CSF
  • FCA
  • PRA
  • CHAPS
  • FPS
  • Bacs
  • SWIFT CSP
  • ROPA
  • DPIA

Tools & Technologies

  • SIEM
  • Cloud Security
  • Perimeter Security Controls
  • Data Protection Controls
  • Monitoring Controls

#J-18808-Ljbffr

Assistant Manager – Information Security employer: Jobtailor

As a Client Services Coordinator at our dynamic company, you will thrive in a supportive work culture that prioritises employee growth and development. We offer comprehensive training, opportunities for advancement, and a collaborative environment where your contributions are valued. Located in a vibrant area, our team enjoys a healthy work-life balance and the chance to engage with diverse clients, making every day rewarding and meaningful.

J

Contact Details:

Jobtailor Recruitment Team