At a Glance
- Tasks: Lead a dynamic team to protect our brand and customer data while driving security initiatives.
- Company: Join ME+EM, a fast-growing luxury fashion brand with a vibrant culture.
- Benefits: Enjoy 33 days off, a birthday day off, and generous discounts.
- Why this job: Make a real impact in a creative environment while advancing your career in cybersecurity.
- Qualifications: Experience in Cyber Security and strong communication skills are essential.
- Other info: Be part of a diverse team that values inclusion and personal growth.
The predicted salary is between 60000 - 75000 £ per year.
About Us
ME+EM is one of the UK's fastest-growing luxury fashion brands. In addition to a thriving global digital presence, we operate flagship stores in London and Edinburgh, concessions within Harrods and Selfridges, and have recently expanded with new store openings in the U.S. At ME+EM we are an entrepreneurial, creative, and passionate group of people. We work hard, are enthusiastic to learn and are not afraid to take risks. Everyone contributes to our success at all levels, and that precisely what makes being a member of the team so rewarding. Our office and stores are always busy and fast paced, but we work just as hard to make sure it's fun, with social activities and biannual parties. We pride ourselves on being approachable, supportive, and welcoming and ensure that everyone's hard work is rewarded. It takes all these things to build a strong, successful business and our door is always open to new talent ready to contribute to our growth and evolution.
About the Role
As ME+EM continues its rapid global expansion, protecting our brand identity, our intellectual property, and our customers' data is paramount. We are looking for an operational leader to head our small but focused Information Security team. This is a "Player-Coach" role. You will line manage a talented Engineer and Analyst while remaining technically active, coordinating complex security projects across a range of departments. You are the bridge between high-level risk management and technical execution, ensuring that security enables - rather than hinders - our global growth.
Job Responsibilities
- Team Leadership & Orchestration
- Direct Management: Lead, mentor, and set the roadmap for the Information Security Engineer and Analyst. Focus on career development and technical cross-skilling.
- Workflow Management: Act as the "Traffic Controller" for the team, using Kanban to prioritise high-value tasks and ensuring the team stays focused on meaningful risk reduction rather than just "noise."
- Cross-Functional Liaison: Partner with teams across the business to ensure "Security by Design" is integrated into every new project.
- Third-Party Risk Management (TPRM)
- Vendor Due Diligence: Own the end-to-end security assessment process for all new global partners (e.g., SaaS providers, 3PL warehouses, marketing agencies).
- Continuous Monitoring: Implement a "Tiered Risk" framework to monitor existing partners, ensuring critical vendors meet our encryption, data handling, and availability standards.
- Supply Chain Resilience: Assess the security posture of third-party APIs and integrations to prevent data leaks or service disruptions.
- Operational Excellence & Incident Response
- Incident Commander: Lead the response to information security incidents. Act as the primary escalation point, coordinating containment while providing clear, non-technical updates to business leadership.
- Tooling & Automation: Oversee the optimisation of our security stack. Work with the Engineer to automate repetitive tasks and with the Analyst to improve threat detection accuracy.
- Vulnerability Management: Oversee our global scanning programme. Prioritise remediation based on business impact - ensuring our systems and infrastructure remain resilient.
- Security Validation & Pentesting
- Pentest Ownership: Own the global Penetration Testing schedule, ensuring all critical outward-facing assets (website, head office, stores) are tested regularly.
- Continuous Testing: Implement and oversee Continuous Security Testing or Attack Surface Management tools to identify vulnerabilities in real-time as our digital footprint scales.
- Remediation Management: Don't just "pass the report" to IT; work with the Engineer and Developers to validate fixes and ensure that high-risk findings are closed out within agreed SLAs.
- Governance, Risk & Compliance (GRC)
- Brand Protection: Manage DMARC and anti-phishing tools to defend ME+EM customers from fraudulent "copycat" websites and email scams.
- Global Data Privacy: Ensure our operations remain compliant with UK/EU GDPR and PCI-DSS 4.0 as we scale into the US and other international markets.
- Policy Maintenance: Ensure internal security policies are practical, up-to-date, and understood by the wider business.
The Ideal Candidate
- The Background: Experience in Cyber Security. You've likely been an Analyst or Engineer yourself and are ready to lead without losing your technical edge.
- The Mindset: You understand that in a fast growing luxury fashion brand, our ability to move quickly is everything. You can design solutions that maintain security without compromising on the businesses ability to deliver for our customers.
- The Tech Stack: Experience with enterprise Cloud Security (Google and Microsoft), EDR (e.g., SentinelOne), and SIEM.
- Communication: You can explain a "SQL Injection" to a developer and a "Supply Chain Risk" to a Creative Director with equal clarity.
Employee Benefits
- 33 days annual leave for full time employees (25 days holiday + 8 bank holidays)
- A day off to celebrate your birthday.
- Pension Scheme
- Group Life Insurance
- Employee Assistance Programme (EAP)
- Length of Service Award
- Refer a Friend Scheme
- Staff uniform for retail employees
- Generous Staff and Friends and Family Discount
- Annual Volunteer Day
- Cycle to Work Scheme
- Tech Scheme
- Eye Care Vouchers
- Real Living Wage Employer
- Employee led committees
- Social events and biannual parties
- Enhanced maternity and paternity package after 2 years of service.
ME+EM is an equal opportunities employer committed to fostering and preserving a culture of diversity, equality, and inclusion in our workforce. As an equal opportunities' employer, we do not discriminate against applicants based on race, colour, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. We believe that diversity enriches our workforce and strengthens our organisation. Therefore, we encourage minorities, LGBTQ+ candidates, and individuals with disabilities to apply for opportunities within our company. Please email [email protected] should you require any adjustments needed to take part in this recruitment process.
Information Security Operations Manager employer: Me+Em
Contact Detail:
Me+Em Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Information Security Operations Manager
✨Tip Number 1
Network like a pro! Reach out to people in the industry, attend events, and connect on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by researching the company and its culture. Understand their values and how your skills align with their goals. This will help you stand out as someone who truly gets what they’re about.
✨Tip Number 3
Practice your pitch! Be ready to explain your experience and how it relates to the role of Information Security Operations Manager. Keep it concise but impactful – you want to leave them wanting to know more!
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who are proactive and engaged with our brand.
We think you need these skills to ace Information Security Operations Manager
Some tips for your application 🫡
Tailor Your CV: Make sure your CV reflects the skills and experiences that align with the Information Security Operations Manager role. Highlight your leadership experience and technical expertise, as we want to see how you can bridge the gap between management and hands-on security work.
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to tell us why you're passionate about information security and how your background makes you the perfect fit for our team. Don’t forget to mention your understanding of the fast-paced luxury fashion industry!
Showcase Your Technical Skills: We’re looking for someone who’s not just a manager but also technically savvy. Be sure to include specific tools and technologies you’ve worked with, like EDR or SIEM, and any relevant certifications that demonstrate your expertise in cyber security.
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, it shows us you’re genuinely interested in joining our ME+EM family!
How to prepare for a job interview at Me+Em
✨Know Your Stuff
Make sure you brush up on your cyber security knowledge, especially around the tech stack mentioned in the job description. Be ready to discuss your experience with enterprise Cloud Security, EDR, and SIEM tools. This will show that you’re not just a leader but also technically savvy.
✨Show Your Leadership Style
As this role is about leading a small team, be prepared to share your approach to team management. Think of examples where you've mentored others or led projects. Highlight how you balance being a 'Player-Coach' while still getting your hands dirty with technical tasks.
✨Communicate Clearly
You’ll need to bridge the gap between technical and non-technical teams. Practice explaining complex concepts like SQL Injection or Supply Chain Risk in simple terms. This will demonstrate your ability to communicate effectively across different departments.
✨Understand the Business
Research ME+EM and its brand identity. Understand their values and how security plays a role in their global expansion. Be ready to discuss how you can contribute to their growth while ensuring robust security measures are in place.