At a Glance
- Tasks: Lead the charge in protecting data and systems while managing security incidents.
- Company: Join a passionate charity dedicated to supporting the armed forces community.
- Benefits: Competitive salary, flexible working, and opportunities for professional growth.
- Why this job: Make a real difference by enhancing information security and compliance.
- Qualifications: Proven experience in information security and compliance management required.
- Other info: Dynamic team environment with a focus on continuous improvement.
The predicted salary is between 48000 - 72000 £ per year.
Overview
I am currently working with a Charity who are seeking a Head of Information Security and Compliance. You will join an ambitious, focused and dynamic team who are passionate about how technology can enable our staff to deliver incredible support to the armed forces community.
Role Purpose
The Information Security and Compliance Manager is responsible for developing, implementing, and maintaining security policies, procedures, and controls to protect the data and systems. They will play a pivotal role in the management and containment of security incidents, ensuring continuous improvement in their security posture while raising awareness for staff, volunteer and member communities. The post holder will lead on activities that assess, report and mitigate risk associated with third parties with the focus being to protect the confidentiality, integrity, and availability of information assets.
Key Responsibilities
Information Protection
- Take responsibility for their information and data protection policies, practices and settings to include sensitivity labels, data retention policies and data loss protection policies
- Collaborate with the Head of Risk, DPO and VCISO to identify and manage information security risks and mitigating controls
- Lead the wider business areas to ensure security policies and procedures are embedded in all business processes.
- Take an active role in in the containment and reporting of information security incidents, including detection, response, remediation and communication.
Third Party risk management
- Lead on the design and implementation of robust processes for reviewing & addressing the data security posture of third-party suppliers.
- Take a leading role in managing relationships with vendors and service providers to assess compliance with security and data protection policies and standards.
Policy, Audit & Reporting
- Take the lead on the review process for information security policies working to agreed re-view schedules. Ensure all policies are published and made available to all staff and volunteers increasing awareness among these groups.
- Develop policies and procedures in accordance with industry regulations and standards such as Data Protection Act 2018, PCI-DSS, and ISO27001.
- Monitor tools for data governance, data security, and compliance to manage information security risks and regulatory requirements and detect and investigate possible information security incidents.
Knowledge & Experience
- Significant proven experience in information security and compliance management.
- Familiarity with ITIL practices and risk management methodologies.
- Significant proven experience with cyber security incident management and response
- Strong knowledge of security standards and regulations, such as GDPR, PCI-DSS, and ISO27001
- Experience of delivering data protections specifically data loss prevention, sensitivity labelling and retention (using Microsoft Purview)
- Experience of managing projects through to completion
Skills & Attributes
- Excellent problem-solving skills and the ability to provide technical expertise and advice – Strong all round technical skills
- Strong communication and collaboration skills & proven ability to work effectively with various departments including senior leaders.
- Ability to explain technical solutions to a non-technical audience
- Ability to manage and organise own workload and be flexible and ready to adapt to changing demands
- Strong analytical skills with the proven ability to (use) on the data available to inform decisions and actions
Qualifications
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified Information Systems Auditor (CISA)
- Certified in Risk and Information Systems Control (CRISC)
#J-18808-Ljbffr
Information Security and Compliance Manager employer: Morgan Law
Contact Detail:
Morgan Law Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Information Security and Compliance Manager
✨Tip Number 1
Network like a pro! Get out there and connect with people in the industry. Attend events, join online forums, and don’t be shy about reaching out to professionals on LinkedIn. We all know that sometimes it’s not just what you know, but who you know!
✨Tip Number 2
Prepare for interviews by researching the charity and its mission. Understand their values and how your skills can help them achieve their goals. We want you to show that you’re not just another candidate, but someone who genuinely cares about making a difference.
✨Tip Number 3
Practice your responses to common interview questions, especially those related to information security and compliance. We recommend doing mock interviews with friends or using online resources to get comfortable. The more you practice, the more confident you’ll feel!
✨Tip Number 4
Don’t forget to follow up after your interview! A simple thank-you email can go a long way in showing your appreciation and keeping you top of mind. Plus, it’s a great opportunity to reiterate your enthusiasm for the role. And remember, check out our website for more opportunities!
We think you need these skills to ace Information Security and Compliance Manager
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the role of Information Security and Compliance Manager. Highlight your experience with security policies, incident management, and compliance standards like GDPR and ISO27001. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how you can contribute to our mission. Be sure to mention any relevant projects or experiences that showcase your expertise.
Showcase Your Problem-Solving Skills: In your application, don’t forget to highlight your problem-solving abilities. Share examples of how you've tackled security incidents or improved compliance processes in the past. We love seeing candidates who can think on their feet!
Apply Through Our Website: We encourage you to apply through our website for a smoother process. It helps us keep track of applications and ensures you get all the updates directly from us. Plus, it shows you're keen on joining our team!
How to prepare for a job interview at Morgan Law
✨Know Your Stuff
Make sure you brush up on the key regulations and standards mentioned in the job description, like GDPR, PCI-DSS, and ISO27001. Being able to discuss these confidently will show that you're not just familiar with them, but that you can apply them in real-world scenarios.
✨Showcase Your Experience
Prepare specific examples from your past roles where you've successfully managed information security incidents or developed policies. Use the STAR method (Situation, Task, Action, Result) to structure your answers, making it easy for the interviewer to see your impact.
✨Communicate Clearly
Since you'll need to explain technical solutions to non-technical audiences, practice simplifying complex concepts. During the interview, aim to communicate your ideas clearly and concisely, demonstrating your strong communication skills.
✨Ask Insightful Questions
Prepare thoughtful questions about the charity's current security posture and how they handle third-party risk management. This shows your genuine interest in the role and helps you gauge if the organisation aligns with your values and expertise.