At a Glance
- Tasks: Lead and enhance our information security strategy for major UK infrastructure projects.
- Company: Mace Construct, a pioneering construction firm focused on innovation and responsibility.
- Benefits: Competitive salary, inclusive culture, and opportunities for professional growth.
- Other info: Dynamic work environment with a commitment to diversity and inclusion.
- Why this job: Join us to make a real impact on national infrastructure while ensuring top-notch security.
- Qualifications: 5+ years in information security management with strong IS principles knowledge.
The predicted salary is between 60000 - 80000 £ per year.
About the company
At Mace Construct, our purpose is to redefine the boundaries of ambition. We are innovators, trusted partners, construction experts. Founded on a belief that the built environment sector could be more efficient, innovative and responsible. We've built a reputation and track record for delivering projects better than ever before: safer, faster and greener. Transforming industries, supporting communities and leaving legacies.
About the project
Mace Dragados Joint Venture (MDJV) is the construction partner for the new HS2 Euston and Curzon Street Stations, working with HS2 Ltd and design partners to deliver new platforms, concourse structures, and interchange rail links.
About the role
The Information Security Lead is responsible for maintaining and continuously improving the Information Security Management System (ISMS), including supporting processes, across two major UK public infrastructure programmes delivered under a joint venture in Birmingham and London. The role ensures compliance with the client's contractual information and cyber security requirements, as well as parent-company and regulatory obligations. The postholder is also accountable for retaining ISO 27001 and Cyber Essentials Plus certifications, and for meeting the security obligations associated with nationally significant infrastructure projects.
What you'll be doing
- Develop and own our organisation-wide information security strategy, aligning it with client, parent company and regulatory requirements.
- Ensure compliance with the client's contractual information security and cyber security obligations, as detailed in the project's Information Security and Cyber Security Management Plan.
- Maintain the disaster recovery plan and incident management response aligned to parent company and client requirements.
- Lead the ICT Security team in implementing and maintaining secure IT systems.
- Lead on Data Protection Compliance through digital / project systems, maintaining / auditing systems and coordinating breach handling.
- Manage data retention systems across the project.
- Own the ISMS suite of policies, including the IS Policy Statement, Acceptable Use Policy, Remote Working Policy, Information Classification and Handling Policy, and Clear Desk Policy, ensuring they remain current and embedded across the project.
- Provide IS performance reporting to Senior Leadership and the client.
- Maintain the ISO 27001, PAS1192-5 and Cyber Essentials Plus certifications through ongoing compliance and surveillance audits.
- Monitor and enforce information security requirements across the supply chain, including compliance checks and delivering supply chain audits for information security.
- Lead incident response efforts-investigating, containing, and remediating security events with precision and speed.
- Oversee security awareness training, empowering every employee to be a first line of defence.
- Collaborate with other discipline and IT teams to embed security into procurement, design, construction delivery and Handover.
- Undertake system access reviews and conduct regular risk assessments to identify and address weaknesses.
- Manage relationships with external auditors, regulators, and security vendors.
- Keep ahead of evolving threats, tools, and compliance frameworks (ISO 27001, NIST, GDPR, etc.).
- Manage Contractor Assessment, onboarding and IT exit Plans.
- Training and developing the project team and contractors around ICSC awareness.
What you'll bring
- Minimum 5 years' experience in an information security management role.
- Strong knowledge of IS principles, frameworks and risk management.
- Ability to develop and enforce IS policies.
- Experience in IT security infrastructure, including access controls, network security, endpoint protection, and secure communications.
- Cyber Essentials auditing.
- Hold a recognised information security qualification such as CISSP, CISM or ISO/IEC 27001 Lead Implementer / Lead Auditor, with relevant professional membership (e.g. CIISec) desirable.
- Compliance for BPSS clearance.
- Confident presenting to senior leadership, clients and non-technical audiences.
- Line management experience.
Nice to have
- Strong understanding of UK data protection legislation (UK GDPR, Data Protection Act 2018) and NIS Regulations.
- Competence in leading internal and external information security audits.
- Experience in creating and delivering training.
- Bachelor's degree or equivalent professional experience.
Mace is an inclusive employer and welcomes interest from a diverse range of candidates. Even if you feel you do not fulfil all of the criteria, please apply as you may still be the best candidate for this role or another role within our organisation.
Information Security Manager in Birmingham employer: Mace Construct
At Mace Construct, we pride ourselves on being an innovative and responsible employer, dedicated to redefining the construction industry. Our collaborative work culture fosters professional growth and development, offering employees the opportunity to engage in significant infrastructure projects like HS2 while ensuring compliance with the highest information security standards. With a commitment to safety, sustainability, and community support, we provide a rewarding environment where every team member can thrive and contribute to meaningful legacies.
StudySmarter Expert Advice🤫
We think this is how you could land Information Security Manager in Birmingham
✨Tip Number 1
Network like a pro! Reach out to people in the industry, attend events, and connect on LinkedIn. We all know that sometimes it’s not just what you know, but who you know that can help you land that dream job.
✨Tip Number 2
Prepare for interviews by researching the company and its projects. Understand their values and how they align with your skills. We want you to show them that you’re not just another candidate, but the perfect fit for their team!
✨Tip Number 3
Practice your responses to common interview questions, especially those related to information security. We suggest doing mock interviews with friends or using online resources to boost your confidence and refine your answers.
✨Tip Number 4
Don’t forget to follow up after your interview! A simple thank-you email can go a long way in keeping you top of mind. We believe it shows your enthusiasm and professionalism, which employers love to see.
We think you need these skills to ace Information Security Manager in Birmingham
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Information Security Manager role. Highlight your relevant experience and skills that align with the job description, especially around IS principles and compliance.
Craft a Compelling Cover Letter:Your cover letter should tell us why you're the perfect fit for this role. Share specific examples of how you've developed and enforced IS policies or led security teams in the past.
Showcase Your Qualifications:Don’t forget to mention your recognised information security qualifications like CISSP or ISO/IEC 27001. These are key to showing us you have the expertise we’re looking for!
Apply Through Our Website:We encourage you to apply through our website for a smoother application process. It helps us keep track of your application and ensures you don’t miss out on any important updates!
How to prepare for a job interview at Mace Construct
✨Know Your Stuff
Make sure you brush up on the key information security principles and frameworks relevant to the role. Familiarise yourself with ISO 27001, Cyber Essentials, and UK data protection legislation. Being able to discuss these confidently will show that you're not just a candidate, but a knowledgeable expert.
✨Showcase Your Experience
Prepare specific examples from your past roles that demonstrate your experience in managing information security systems and compliance. Highlight any successful audits or incident responses you've led, as well as how you've developed IS policies. This will help the interviewers see your practical skills in action.
✨Engage with the Team
Since this role involves leading a team, be ready to discuss your line management experience. Think about how you've trained and developed team members in the past, and be prepared to share your approach to fostering a culture of security awareness within an organisation.
✨Ask Smart Questions
Prepare thoughtful questions about Mace Construct's current information security challenges and their approach to compliance. This shows your genuine interest in the role and helps you understand how you can contribute to their goals. Plus, it gives you a chance to assess if the company is the right fit for you.