ISO27001 ISMS Lead — Security & Compliance (Hybrid) in Epsom

ISO27001 ISMS Lead — Security & Compliance (Hybrid) in Epsom

Epsom Full-Time 60000 - 75000 £ / year (est.) No working from home possible
KINTO UK Limited

At a Glance

  • Tasks: Lead the charge in Information Security and compliance at Toyota Financial Services UK.
  • Company: Join a forward-thinking team at Toyota Financial Services, where innovation meets security.
  • Benefits: Enjoy a competitive salary, annual bonus, car allowance, and extensive benefits package.
  • Other info: Embrace a culture of growth with learning opportunities and a focus on wellbeing.
  • Why this job: Make a real impact on information security while working in a hybrid environment.
  • Qualifications: Experience in ISMS and strong stakeholder management skills are essential.

The predicted salary is between 60000 - 75000 £ per year.

Competitive salary, annual bonus, car allowance and an extensive benefits package.

Responsible for all aspects of Information Security within Toyota Financial Services UK, including compliance with Corporate Policies, the ongoing promotion of Information Security across the organisation and to operate an effective Information Security Management System (ISMS).

The Business Technology Solutions (BTS) department are responsible for delivering end-to-end business technology and change through their four key functions of Governance, Projects & Change, Delivery and Technical Operations. They look after both TFSUK and KINTO UK. The mission of BTS is to Give (the Business the technology, applications and services it needs), to Guide (the Business through Change using their expertise and experience) and to Guard (always protect the Business, its Customers & its Data).

What you’ll be doing:

  • Maintain, mature and align the BTS’ ISMS with ISO27001:2022 through management and evolution of the company’s Information Security policies, maintaining best practice and alignment with Corporate and Regulatory requirements, including the Global Information Security Group framework (GISG), General Data Protection Regulation (GDPR), Sarbanes-Oxley (SOX) PCI-DSS & Cyber Essentials Plus.
  • Manage Information Security aspects of the third-party due diligence process, including subject matter expertise to support onboarding of new suppliers, ongoing assessment of existing suppliers, contract reviews.
  • Manage/Co-ordinate or provide reporting material for regular information security meetings including supplier security reviews, risk register reviews, metrics.
  • Provide clear and actionable information security reporting to senior leadership.
  • Manage/operate Information Security related tools such as GRC tool and Supplier assessment tool.
  • Own and maintain the BTS Risk register, ensuring risks are identified, assessed and documented in accordance with internal risk methodology, including exception handling.
  • Working in partnership with the Data Protection Officer (DPO) & Legal & Compliance to protect the organisation’s information.
  • Overseeing Audit Findings and any associated remediation across BTS including gathering, management and submission of control evidence to support assurance activities, internal compliance reviews (GISG) and any regulatory requirements.
  • Manage the Information Security Awareness programme, including maintenance of the training schedule, annual employee training, creation of materials and assist with co-ordination of monthly phishing campaigns.
  • Proactively raising the profile of Information Security across the organisation, its stakeholders, vendors and customers.
  • Working in partnership with the Business & BTS teams to ensure all Projects, Changes, policies and procedures are compliant with corporate information security policies.
  • Management of the annual Security Incident Response Test (SIRT), as well as ensuring the remediation of any findings.
  • Undertake Security related Testing, including Phishing, Security Incident Response Tests.
  • Co-ordinate response to security incidents and breaches to ensure any impact is contained and relevant information obtained to facilitate analysis and improvement plans.
  • Maturing the Information Security mindset across TFS UK.

What you’ll get to own:

  • Management of TFSUK’s ISO27001 certification, ensuring the ongoing certification is retained.
  • Management of TFSUK’s GISG posture, ensuring compliance against the extensive control set.
  • Management of the GISG Vendor Assessment process for Information Security assurance of all TFSUK vendors.
  • Development & Management of the Information Security Strategy and subsequent annual reviews.
  • Oversight of remediation work for all open IT audit findings.
  • Management of IT Risk Register and ongoing monthly reviews.
  • Information Security Reporting & Performance KPIs.

Key Experience & Skills:

  • Proven experience in developing, implementing, maintaining and leading an effective ISMS and information security control assurance programme.
  • Strong stakeholder management skills, including technical members of staff and senior executives, stakeholder negotiation and influencing.
  • Good analytical skills.
  • Strong understanding of ISO27001, GDPR, SOX & Information Security Risk Management.
  • Understanding of information security tools.
  • Experience with business continuity, third party risk management and incident management.

Attributes & Behaviours:

  • Strong written and verbal communication skills.
  • Ability to interact professionally with a broad range of technical and non-technical stakeholders across the business.
  • Keen problem solver and critical thinker.
  • Strong multi-tasker, able to work effectively on several projects at one time in a busy and time-driven work environment.
  • Proactive, determined and self-motivated.

At Toyota Financial Services (TFS) it is more than just an externally bench-marked salary and bonus, we also offer:

  • Hybrid working pattern is 2 days in the office and 3 days from a location of your choice.
  • Access to attractive car schemes for you (& your family) for Toyota & Lexus cars.
  • Excellent pension scheme (up to 6% employee contribution and 15% employer contribution).
  • Generous annual leave of 25 days which increases with service and holiday purchase option.
  • Private Medical Healthcare (single, partner/spouse and dependent children) with Digital GP Service.
  • Group Income Protection cover with Aviva including physical, mental, and financial wellbeing services.
  • Employee Assistance Program.
  • Eye tests.
  • Onsite gym, Sports and Social Club, & flu jabs to keep you healthy.
  • Wellbeing hour each month and many more initiatives throughout the year to encourage a healthy mind and body, and to raise awareness and celebrate diversity, equity and inclusion.
  • Dress for your day policy to make you feel comfortable at work.
  • Eco HQ, free parking & restaurant.
  • Two volunteering days per year.
  • Reward gateway voucher discounts.
  • Flexible working scheme and we welcome flexible working conversations at interview.
  • Regular 121s with your manager, a personal development review (PReview) each quarter.
  • A wide range of learning & development opportunities including Linked In Learning courses.
  • £250 contribution towards you learning something new outside of work.
  • Annual events (e.g., summer party, BBQ & Xmas party) including Countdown to Christmas events every December - it is so much fun!

Our Recruitment Process

At Toyota Financial Services (TFS) we value everyone and are pleased to be recognised as a Disability Confident Employer. We are committed to supporting disabled applicants throughout the recruitment process. Should you meet the minimum criteria for this role and wish to apply under the DC scheme, you may be moved forward to the next stage. Please ensure to add this information into your application. When it comes to recruitment, please do let us know if we can adjust our process to meet your accessibility needs. Some examples of how we might be able to help are listed below:

  • Providing a copy of interview questions before the interview.
  • Organising a time and location that best suits you.
  • Allowing additional time for the assessment and interview.
  • We are happy to review any adjustment on a case-by-case basis to support you to be your best self.

ISO27001 ISMS Lead — Security & Compliance (Hybrid) in Epsom employer: KINTO UK Limited

At Toyota Financial Services UK, we pride ourselves on being an exceptional employer, offering a competitive salary and extensive benefits package that includes hybrid working options, generous annual leave, and a strong focus on employee wellbeing. Our vibrant work culture fosters collaboration and innovation, providing ample opportunities for personal and professional growth through regular development reviews and access to learning resources. Join us in a dynamic environment where your contributions to Information Security will be valued and recognised, all while enjoying the perks of working at our Eco HQ with excellent facilities.

KINTO UK Limited

Contact Details:

KINTO UK Limited Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land ISO27001 ISMS Lead — Security & Compliance (Hybrid) in Epsom

Tip Number 1

Network like a pro! Reach out to your connections in the industry, especially those who work at Toyota Financial Services or similar companies. A friendly chat can open doors and give you insider info about the role.

Tip Number 2

Prepare for the interview by researching the company’s values and recent projects. Show us that you’re not just another candidate; you’re genuinely interested in how you can contribute to their mission of giving, guiding, and guarding.

Tip Number 3

Practice your responses to common interview questions, but keep it natural. We want to see your personality shine through, so don’t be afraid to share your experiences and how they relate to the ISO27001 ISMS Lead role.

Tip Number 4

Follow up after your interview with a thank-you email. It’s a simple gesture that shows your appreciation and keeps you fresh in their minds. Plus, it’s a great chance to reiterate your enthusiasm for the position!

We think you need these skills to ace ISO27001 ISMS Lead — Security & Compliance (Hybrid) in Epsom

ISO27001
Information Security Management System (ISMS)
GDPR
Sarbanes-Oxley (SOX)
PCI-DSS
Cyber Essentials Plus
Stakeholder Management

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience with ISO27001 and information security. We want to see how your skills align with the role, so don’t hold back on showcasing your relevant achievements!

Showcase Your Communication Skills:Since this role involves interacting with various stakeholders, it’s crucial to demonstrate your strong written communication skills. Use clear and concise language in your application to reflect your ability to convey complex information effectively.

Highlight Your Problem-Solving Abilities:We love a keen problem solver! In your application, share examples of how you've tackled challenges in previous roles, especially those related to information security or compliance. This will show us you’re proactive and ready to take on the responsibilities of the position.

Apply Through Our Website:Don’t forget to submit your application through our website! It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it gives you a chance to explore more about our company culture and values.

How to prepare for a job interview at KINTO UK Limited

Know Your ISO27001 Inside Out

Make sure you’re well-versed in ISO27001:2022 and its requirements. Brush up on the key principles and how they apply to Toyota Financial Services. Being able to discuss specific examples of how you've implemented or managed an ISMS will show your expertise.

Showcase Your Stakeholder Management Skills

Prepare to discuss your experience in managing relationships with both technical and non-technical stakeholders. Think of examples where you’ve successfully influenced decisions or navigated complex negotiations, as this role requires strong communication skills.

Be Ready for Scenario-Based Questions

Expect questions that ask how you would handle specific security incidents or compliance challenges. Practise articulating your thought process and decision-making steps clearly, as this will demonstrate your problem-solving abilities and critical thinking.

Highlight Your Continuous Improvement Mindset

Discuss how you’ve contributed to maturing information security practices in previous roles. Be prepared to share examples of how you’ve identified areas for improvement and implemented changes, as this aligns with the proactive approach TFS is looking for.