Information Security Project Manager in London
Information Security Project Manager

Information Security Project Manager in London

London Full-Time 55000 - 65000 ÂŁ / year (est.) Home office (partial)
Linnworks

At a Glance

  • Tasks: Lead and coordinate information security projects while ensuring compliance and effective communication.
  • Company: Join a growing SaaS business with a collaborative and supportive culture.
  • Benefits: Remote work, flexible hours, health insurance, and a ÂŁ500 home office budget.
  • Other info: Enjoy a fantastic team culture and access to mental well-being support.
  • Why this job: Make a real impact on security while enabling business growth and innovation.
  • Qualifications: Experience in information security and strong project management skills required.

The predicted salary is between 55000 - 65000 ÂŁ per year.

The Information Security Project Manager is responsible for coordinating and driving the company’s information security activities in a pragmatic, commercially aware way. This role exists to manage security-related projects, audits, and customer security interactions, ensuring we remain compliant and credible without blocking sensible business decisions or over-engineering controls. This role reports to the Director of Technical Operations. Applicants must live in the UK and be able to work for any UK employer without sponsorship.

This role sits within the technology function and partners closely with Technical Operations, Engineering, Product, Legal, and Sales. The focus is on governance, coordination, and communication, not on dictating policy in isolation or acting as the final decision-maker on security matters. Final risk and tooling decisions sit with the Director of Technical Operations and the broader leadership team; the Information Security Project Manager’s job is to provide clear input, well-reasoned recommendations, and organised execution.

We are a growing SaaS business without PCI, PHI, or highly sensitive PII in scope, and we are not subject to HIPAA or classified/secret information regime – our security approach should be proportionate: strong, credible, and well-documented, but not theatrical or unnecessarily restrictive.

Key responsibilities
  • ISO 27001 and internal audits: Plan, coordinate, and execute internal audits and control reviews against ISO 27001 (and related frameworks where relevant). Maintain audit schedules, evidence repositories, and action logs so that we are consistently “audit ready” rather than scrambling before assessments. Work with control owners across the business to ensure that required processes are in place, understood, and operating in a pragmatic way. Track findings and remediation actions, ensuring owners are clear on what needs to be done and by when, and following up to completion. Support external ISO 27001 surveillance and recertification audits, including planning, evidence collation, and managing auditor queries.
  • Security projects and initiatives: Coordinate discrete security improvement projects (for example, rolling out new security tooling, tightening access controls, or updating key policies). Break down security initiatives into clear tasks, owners, and timelines, and keep stakeholders informed on progress and risks. Work with Technical Operations and Engineering to ensure technical changes are understood, documented, and reflected in our security posture. Help prioritise security work by articulating risk, impact, and effort, while understanding the wider commercial and delivery context.
  • Customer security, RFPs and RFQs: Partner with Sales, Pre-Sales, and Customer Success to respond to customer security questionnaires, RFPs, RFQs, and due diligence requests. Maintain and continuously improve a central library of standard security responses and artifacts (for example, summaries of our controls, certifications, and processes). Coordinate input from Technical Operations, Engineering, and Legal where deeper technical or contractual responses are required. Attend customer calls when needed to explain our security posture in clear, non-alarmist language and build confidence in our approach.
  • Security information and communication: Develop and maintain a clear, concise view of our security posture that can be communicated internally and to customers (for example, at a high level, how we handle data, access, monitoring, and incident response). Ensure that key facts (such as use of encryption at rest and in transit, SSO capabilities, backup approaches, and incident processes) are understood and kept up to date, even if technical details are owned by others. Translate technical explanations from engineers into language suitable for non-technical audiences, including customers and internal stakeholders. Help ensure that security-related messages are proportionate, avoiding both complacency and unnecessary drama.
  • Policies, standards, and pragmatic governance: Maintain a focused, manageable set of security policies and procedures that reflect how we actually operate. Work with policy owners to keep documents current, usable, and aligned to ISO 27001 and customer expectations, avoiding policy sprawl and unnecessary complexity. Coordinate periodic reviews of key policies and standards, ensuring changes are communicated and understood. Provide recommendations to the Director of Technical Operations on improvements to policies, controls, or tooling, with clear reasoning and trade-offs.
What this role is not
  • This is not a “head of security” or ultimate decision-maker role; final go/no-go and tooling decisions sit with the Director of Technical Operations and leadership.
  • This is not a role for writing endless policies or blocking change; it is about enabling sensible decisions with good information and structured follow-through.
  • This is not a hands-on security engineering or development role, though you will need enough technical understanding to ask good questions and interpret answers.
  • This is not an internal “police” function; success is based on collaboration, influence, and clarity, not on authority.
We’re looking for someone who brings most of the following:
  • Experience in information security, compliance, risk, or IT audit within a SaaS or technology environment.
  • Practical exposure to ISO 27001 (or similar frameworks), including audits, evidence gathering, and remediation follow-up.
  • Strong project management skills: planning, tracking, stakeholder management, and clear communication.
  • Ability to understand and discuss topics such as encryption at rest/in transit, access control, SSO/identity providers, backup and recovery, logging, and incident response, with the option to lean on specialists for deep detail.
  • Comfortable working directly with customers and auditors, answering questions calmly and confidently.
  • Strong written skills for policies, reports, and customer responses; clear verbal communication with both technical and non-technical audiences.
  • Pragmatic and commercially aware: able to distinguish between theoretical risk and real-world impact.
  • Collaborative, working with teams to find workable solutions rather than simply saying “no”.
  • Organised and methodical, keeping track of multiple audits, projects, and requests without dropping details.
  • Calm and credible under pressure, especially during audits, customer escalations, or security-related incidents.
  • Comfortable asking questions, challenging assumptions, and highlighting risk while still respecting broader business priorities.
Why this role matters

Done well, this role gives the business confidence that our security posture is robust, evidenced, and well-articulated, without turning security into a blocker for growth. It ensures we meet our obligations to customers and auditors, support sales with clear and honest answers, and make security improvements in a deliberate, organised, and commercially sensible way.

Why us?
  • Remote & flexible working – with hybrid options in London or Chichester
  • Fantastic team culture based on trust and belonging.
  • Laptop & home office budget – ÂŁ500 to set up your ideal workspace.
  • Private Medical Insurance with Aviva, including Dental & Optical.
  • Mental well-being support – Access therapy, mental health sessions, and yoga through a free premium subscription to Headspace.
  • EAP confidential benefit – 24/7 access to compassionate guidance & expert advice.
  • 25 days holiday +

Information Security Project Manager in London employer: Linnworks

As an Information Security Project Manager at our growing SaaS business, you'll thrive in a supportive and collaborative environment that values trust and belonging. We offer remote and flexible working options, a generous home office budget, and comprehensive health benefits, including private medical insurance and mental well-being support. Join us to make a meaningful impact on our security posture while enjoying ample opportunities for professional growth and development.
Linnworks

Contact Detail:

Linnworks Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Information Security Project Manager in London

✨Tip Number 1

Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

✨Tip Number 2

Prepare for interviews by researching the company and its security posture. Understand their challenges and be ready to discuss how your experience aligns with their needs. Show them you’re not just another candidate, but someone who gets their world.

✨Tip Number 3

Practice your communication skills! You’ll need to explain complex security concepts in simple terms. Try explaining your past projects to friends or family who aren’t in tech – if they get it, you’re golden!

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who take that extra step to engage with us directly.

We think you need these skills to ace Information Security Project Manager in London

Information Security Management
ISO 27001
Project Management
Stakeholder Management
Risk Assessment
Audit Coordination
Technical Communication
Customer Engagement
Policy Development
Evidence Gathering
Remediation Tracking
Collaboration
Attention to Detail
Calmness Under Pressure
Commercial Awareness

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience in information security and project management. We want to see how your skills align with the specific responsibilities mentioned in the job description.

Showcase Your Communication Skills: Since this role involves a lot of collaboration, emphasise your ability to communicate complex security concepts clearly. Use examples from your past experiences where you successfully translated technical jargon into understandable language for non-technical audiences.

Be Pragmatic and Commercially Aware: Demonstrate your understanding of balancing security needs with business objectives. We’re looking for someone who can make sensible decisions without over-engineering controls, so share instances where you’ve done just that.

Apply Through Our Website: We encourage you to submit your application directly through our website. It’s the best way for us to receive your details and ensures you don’t miss out on any important updates regarding your application.

How to prepare for a job interview at Linnworks

✨Know Your ISO 27001 Inside Out

Make sure you’re well-versed in ISO 27001 and its requirements. Brush up on your knowledge of audits, evidence gathering, and remediation processes. Being able to discuss these topics confidently will show that you understand the framework and can apply it pragmatically.

✨Showcase Your Project Management Skills

Prepare to discuss your project management experience in detail. Think of specific examples where you’ve planned, tracked, and communicated effectively with stakeholders. Highlight how you’ve broken down complex projects into manageable tasks and kept everyone informed along the way.

✨Communicate Clearly with Non-Technical Audiences

Practice translating technical jargon into simple language. You’ll need to explain security concepts to customers and non-technical team members, so being able to articulate your thoughts clearly is crucial. Use examples from your past experiences to demonstrate this skill.

✨Emphasise Collaboration Over Authority

This role is all about working with others, not dictating policy. Be ready to share examples of how you’ve successfully collaborated with different teams to achieve security goals. Show that you can influence decisions while respecting the broader business context.

Information Security Project Manager in London
Linnworks
Location: London

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>