Mannok Administration Buildings, 187 Ballyconnell Road, Derrylin, Enniskillen, Co. Fermanagh, BT92 9GP
Contact us if you have any queries about a particular role, we’ll be happy to help!
+44 (0) 28 677 48866
hr@mannokbuild.com
The Information Security Specialist is responsible for supporting and strengthening Mannok’s information security and governance framework and ensuring the confidentiality, integrity and availability of company information, systems and services.
The role will support the Mannok Information Security Management System (ISMS), compliance with ISO 27001 as well as other applicable security focused requirements. Working closely with IT, business functions and third-party suppliers, the Information Security Specialist will identify and manage security risks, coordinate security initiatives, support incident response activities and promote a strong culture of information security awareness across the organisation.
Key Responsibilities:
Information Security Governance & Compliance
- Support the ongoing development, implementation and continual improvement of Mannok’s Information Security Management System (ISMS).
- Maintain and manage the information security policy and procedure framework, ensuring documentation remains current, effective and aligned to business requirements.
- Support compliance with ISO27001 and other related IT and security related audit requirements.
- Coordinate internal and external audits and maintain associated evidence, records and corrective action plans.
- Monitor and report on information security performance, risks and compliance activities.
- Conduct information security risk assessments across systems, applications, infrastructure, business processes and third-party suppliers.
- Maintain security risk registers and support the implementation of appropriate mitigation measures.
- Identify security gaps and continuously assess the effectiveness of security controls.
- Support business stakeholders in understanding and managing information security risks within their areas of responsibility.
Security Operations & Monitoring
- Monitor security alerts, events and reports to identify potential threats, vulnerabilities and suspicious activity.
- Support the investigation, management and resolution of information security incidents.
- Document incidents, root causes, lessons learned and improvement opportunities.
- Coordinate vulnerability assessments, penetration testing activities and remediation programmes.
- Monitor the effectiveness of security controls including endpoint protection, firewalls, backup solutions, encryption, identity management and multi-factor authentication.
Security in Projects & Change
- Support IT and business projects to ensure security requirements are considered from design through implementation.
- Contribute to solution reviews and security assessments for new technologies, systems and services.
- Support supplier security reviews and third-party risk assessments.
- Assist with the implementation of security improvement initiatives across the organisation.
Security Awareness & Culture
- Develop and deliver information security awareness activities, campaigns and training programmes.
- Promote awareness of cyber threats including phishing, ransomware, social engineering and data protection risks.
- Monitor participation in mandatory security awareness training and support continual improvement initiatives.
- Act as a trusted advisor to colleagues on information security matters.
- Prepare regular security metrics, reports and dashboards for management.
- Track security improvements, vulnerabilities, incidents and compliance activities.
- Research emerging threats, vulnerabilities and industry trends, recommending appropriate controls and countermeasures.
- Support the achievement of annual security objectives and continuous improvement initiatives.
The Ideal Candidate Will Have:
- Degree in Information Security, Cyber Security, Computer Science, Information Technology or a related discipline.
- Minimum three years’ experience in information security, cyber security, IT risk, compliance or a related discipline.
- Strong understanding of information security principles, frameworks and control environments.
- Experience supporting information security audits, risk assessments and compliance activities.
- Knowledge of ISO 27001 OR NIS2 and general information security best practice.
- Good understanding of:
- Identity and Access Management / Security Monitoring / Endpoint Security
- Vulnerability Management
- Network Security
- Experience working with Microsoft technologies including Microsoft 365, Azure and Entra ID.
- Strong analytical and problem-solving skills.
- Excellent written and verbal communication skills.
- Ability to communicate technical security concepts to non-technical audiences.
#J-18808-Ljbffr