At a Glance
- Tasks: Lead the charge in enhancing our Information Security Management System and ensure compliance across major projects.
- Company: Join Mace Construct, a pioneering firm redefining the construction industry with innovation and responsibility.
- Benefits: Competitive salary, inclusive culture, and opportunities for professional growth.
- Other info: Dynamic environment with a focus on training and development for all team members.
- Why this job: Make a real impact on national infrastructure while safeguarding vital information security.
- Qualifications: 5+ years in information security management and strong knowledge of IS principles required.
The predicted salary is between 60000 - 80000 £ per year.
About the company
At Mace Construct, our purpose is to redefine the boundaries of ambition. We are innovators, trusted partners, construction experts. Founded on a belief that the built environment sector could be more efficient, innovative and responsible. We've built a reputation and track record for delivering projects better than ever before: safer, faster and greener. Transforming industries, supporting communities and leaving legacies.
About the project
Mace Dragados Joint Venture (MDJV) is the construction partner for the new HS2 Euston and Curzon Street Stations, working with HS2 Ltd and design partners to deliver new platforms, concourse structures, and interchange rail links.
About the role
The Information Security Lead is responsible for maintaining and continuously improving the Information Security Management System (ISMS), including supporting processes, across two major UK public infrastructure programmes delivered under a joint venture in Birmingham and London. The role ensures compliance with the client's contractual information and cyber security requirements, as well as parent-company and regulatory obligations. The postholder is also accountable for retaining ISO 27001 and Cyber Essentials Plus certifications, and for meeting the security obligations associated with nationally significant infrastructure projects.
What you'll be doing
- Develop and own our organisation-wide information security strategy, aligning it with client, parent company and regulatory requirements.
- Ensure compliance with the client's contractual information security and cyber security obligations, as detailed in the project's Information Security and Cyber Security Management Plan.
- Maintain the disaster recovery plan and incident management response aligned to parent company and client requirements.
- Lead the ICT Security team in implementing and maintaining secure IT systems.
- Lead on Data Protection Compliance through digital / project systems, maintaining / auditing systems and coordinating breach handling.
- Manage data retention systems across the project.
- Own the ISMS suite of policies, ensuring they remain current and embedded across the project.
- Provide IS performance reporting to Senior Leadership and the client.
- Maintain the ISO 27001, PAS1192-5 and Cyber Essentials Plus certifications through ongoing compliance and surveillance audits.
- Monitor and enforce information security requirements across the supply chain, including compliance checks and delivering supply chain audits for information security.
- Lead incident response efforts-investigating, containing, and remediating security events with precision and speed.
- Oversee security awareness training, empowering every employee to be a first line of defence.
- Collaborate with other discipline and IT teams to embed security into procurement, design, construction delivery and Handover.
- Undertake system access reviews and conduct regular risk assessments to identify and address weaknesses.
- Manage relationships with external auditors, regulators, and security vendors.
- Keep ahead of evolving threats, tools, and compliance frameworks (ISO 27001, NIST, GDPR, etc.).
- Manage Contractor Assessment, onboarding and IT exit Plans.
- Training and developing the project team and contractors around ICSC awareness.
What you'll bring
- Minimum 5 years' experience in an information security management role.
- Strong knowledge of IS principles, frameworks and risk management.
- Ability to develop and enforce IS policies.
- Experience in IT security infrastructure, including access controls, network security, endpoint protection, and secure communications.
- Cyber Essentials auditing.
- Hold a recognised information security qualification such as CISSP, CISM or ISO/IEC 27001 Lead Implementer / Lead Auditor.
- Compliance for BPSS clearance.
- Confident presenting to senior leadership, clients and non-technical audiences.
- Line management experience.
Nice to have
- Strong understanding of UK data protection legislation (UK GDPR, Data Protection Act 2018) and NIS Regulations.
- Competence in leading internal and external information security audits.
- Experience in creating and delivering training.
- Bachelor's degree or equivalent professional experience.
Mace is an inclusive employer and welcomes interest from a diverse range of candidates. Even if you feel you do not fulfil all of the criteria, please apply as you may still be the best candidate for this role or another role within our organisation.
Senior Information Security Lead — ISMS & Compliance in Birmingham employer: Mace Construct
At Mace Construct, we pride ourselves on being an innovative and responsible employer, dedicated to redefining the construction industry. Our collaborative work culture fosters creativity and inclusivity, while our commitment to employee development ensures that you will have ample opportunities for growth and advancement. Located in vibrant Birmingham and London, you will be part of significant infrastructure projects that not only enhance your professional skills but also contribute positively to the communities we serve.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Information Security Lead — ISMS & Compliance in Birmingham
✨Tip Number 1
Network like a pro! Reach out to people in the industry, attend events, and connect on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by researching the company and its projects. Understand their values and how your skills align with their goals. This will help you stand out and show that you're genuinely interested in the role.
✨Tip Number 3
Practice your responses to common interview questions, but keep it natural. Use the STAR method (Situation, Task, Action, Result) to structure your answers and highlight your achievements effectively.
✨Tip Number 4
Don’t forget to follow up after your interview! A quick thank-you email can leave a lasting impression and shows your enthusiasm for the position. Plus, it keeps you on their radar!
We think you need these skills to ace Senior Information Security Lead — ISMS & Compliance in Birmingham
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in information security management. We want to see how your skills align with the specific requirements of the role, so don’t hold back on showcasing your relevant achievements!
Showcase Your Certifications:If you've got any recognised qualifications like CISSP or ISO/IEC 27001, make them pop! We love seeing candidates who are serious about their professional development, so include these details prominently in your application.
Be Clear and Concise:When writing your application, keep it straightforward and to the point. We appreciate clarity, so avoid jargon and ensure your key points stand out. This will help us quickly see why you’re a great fit for the role!
Apply Through Our Website:Don’t forget to submit your application through our website! It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it’s super easy to do!
How to prepare for a job interview at Mace Construct
✨Know Your Stuff
Make sure you brush up on the key information security principles and frameworks relevant to the role. Familiarise yourself with ISO 27001, Cyber Essentials, and UK data protection legislation. Being able to discuss these confidently will show that you're not just a candidate, but a knowledgeable expert.
✨Showcase Your Experience
Prepare specific examples from your past roles where you've successfully implemented ISMS or led compliance initiatives. Use the STAR method (Situation, Task, Action, Result) to structure your answers. This will help you demonstrate your hands-on experience and problem-solving skills effectively.
✨Engage with the Interviewers
Don’t just wait for questions; engage with your interviewers by asking insightful questions about their current projects and challenges. This shows your genuine interest in the role and helps you understand how you can contribute to their goals, especially in relation to the HS2 project.
✨Prepare for Scenario Questions
Expect scenario-based questions that assess your ability to handle incidents or compliance issues. Think through potential situations you might face in the role and how you would respond. This will help you articulate your thought process and decision-making skills during the interview.