Job Description
IT Security Manager- Cyber Security Manager β PCI-DSS
/n
Location: Luton, 2 days per week on-site.
/n
Our client, a national organisation with offices near Luton, are seeking an experienced IT Security Manager to lead and enhance their security landscape while owning their Tier 1 PCI-DSS compliance programme. This is a fantastic opportunity for a hands-on security specialist who enjoys operating at both strategic and technical levels, working closely with senior stakeholders to drive security best practice across the organisation.
/n
Reporting to the Head of Technical Delivery, you will be the go-to expert for all aspects of cyber security, governance, risk, and compliance. This is a standalone role offering significant ownership and influence, making it ideal for someone who enjoys autonomy and genuinely shaping an organisation's security strategy.
/n
Key Responsibilities
/n
Cyber Security:
/n
/n
- Develop and continuously improve the organisation's cyber security strategy, controls, and policies.
/n
- Monitor emerging threats and ensure effective protection across endpoint, network, cloud, and identity environments.
/n
- Lead security incident response activities, investigations, and remediation efforts.
/n
- Drive vulnerability management and penetration testing programmes through to successful resolution.
/n
- Act as the internal cyber security subject matter expert.
/n
/n
PCI-DSS Compliance & Audit:
/n
/n
- Take ownership of end-to-end PCI-DSS compliance activities.
/n
- Lead annual audit and attestation processes, working closely with external assessors.
/n
- Manage compliance documentation, evidence gathering, and control frameworks.
/n
- Coordinate with technical and business teams to embed compliance requirements into day-to-day operations.
/n
- Provide compliance reporting and updates to senior stakeholders.
/n
/n
Governance, Risk & Compliance:
/n
/n
- Support wider compliance initiatives including ISO 27001, Cyber Essentials, and GDPR.
/n
- Maintain security policies, standards, and procedures.
/n
- Conduct risk assessments and manage the security risk register.
/n
- Deliver security awareness initiatives across the business.
/n
- Manage relationships with third-party suppliers, security vendors, and auditors.
/n
/n
Essential Skills & Experience
/n
/n
- Proven experience within IT or Cyber Security with ownership of PCI-DSS compliance in a Tier 1 environment.
/n
- Strong understanding of security frameworks, controls, and governance practices.
/n
- Experience managing security incidents, vulnerability remediation, and audit activities.
/n
- Ability to engage confidently with senior stakeholders and external auditors.
/n
- Comfortable working independently and taking ownership of a broad security remit.
/n
/n
Desirable
/n
/n
- CISSP, CISM, CISA, PCI ISA, or similar industry certifications.
/n
- Experience within retail, hospitality, payments, or other highly regulated environments.
/n
- Knowledge of Azure, AWS, and modern SOC/SIEM technologies.
/n
/n
If you're an experienced IT Security Manager, Cyber Security Manager, Information Security Manager, or PCI Compliance Specialist looking for your next challenge, we'd love to hear from you.
IT Security Manager - PCI-DSS in Luton employer: Marshall Wolfe
At Marshall Wolfe, we pride ourselves on being an excellent employer by fostering a dynamic work culture that prioritises innovation and collaboration. Our London office offers a hybrid working model, allowing for flexibility while ensuring team cohesion with in-office days. We are committed to employee growth, providing ample opportunities for professional development in the rapidly evolving FinTech sector, making it a rewarding place for those passionate about secure cloud engineering.