At a Glance
- Tasks: Lead and enhance global information security policies and governance across diverse environments.
- Company: Join a forward-thinking logistics company committed to security excellence.
- Benefits: Flexible working hours, competitive salary, and opportunities for professional growth.
- Other info: Dynamic role with travel opportunities and a focus on continuous improvement.
- Why this job: Make a real impact on global security strategies and protect vital information.
- Qualifications: 5+ years in Information Security with strong GRC experience and relevant certifications.
The predicted salary is between 60000 - 80000 £ per year.
Responsible for leading and maturing the company’s global information security policies and governance framework across warehouse and corporate environments. The role ensures that Neovia maintains a structured, risk-based, and scalable security posture aligned with business objectives, customer expectations, regulatory obligations, and the evolving threat landscape. Maintains awareness of new threats and creates vehicles for quickly addressing day zero risks. Supports global locations, ensuring that information security policies, standards, and control objectives are consistently defined, governed, and aligned with operational reality. Drives the development and maintenance of the Information Security Management System (ISMS), supports certificate initiatives (ISO 27001 etc.), oversees enterprise security risk management, and ensures structured audit readiness across regions by partnering with Neovia’s internal GRC and legal teams. Responsible for the security strategy, working with Engineering and leadership to recommend software and solutions to solve complex problems and make Neovia safer. Helps evaluate security capabilities, identify maturity gaps, and provide structured recommendations to IT and executive leadership to ensure ongoing improvement of Neovia’s security posture. Owns end-user testing and education. Ensures that technical solutions and products consider data sovereignty, regional legislation, customer contractual obligations, and compliance with security and IT policies and controls.
Job Responsibilities
- Security Strategy & Governance: Define and maintain the global Information Security roadmap aligned to business objectives and operational realities across core infrastructure locations and 60+ warehouses. Establish strategic security control objectives (e.g., least privilege, identity-first security, segmentation, zero trust principles) in line with industry and global standards from NIST, CIS, etc. Develop, maintain, and mature the Information Security Management System (ISMS). Create and update global security policies, standards, and procedures aligned to ISO 27001 and industry best practices. Ensure consistent governance and control ownership across IT and business functions.
- Risk Management & Regulatory Alignment: Own and maintain the enterprise Information Security risk register and supporting tools. Conduct and facilitate formal risk assessments across global sites and business functions. Define and document risk treatment and risk acceptance processes. Ensure consideration of regional legislation, data sovereignty, and cross-border data handling requirements in conjunction with legal and DPO. Provide structured reporting on risk posture and key risk indicators to IT and senior leadership.
- Compliance & Certification: Lead ISO 27001 readiness and certification initiatives. Coordinate internal and external audits across global operations. Maintain control mappings to regulatory, contractual, and customer requirements. Oversee remediation tracking and corrective action plans arising from audits or assessments. Ensure audit evidence collection processes are structured, repeatable, and consistent across locations.
Qualifications
- Bachelor’s in Computer Science; Information Systems or equivalent.
- Minimum 5 years of experience in Information Security, with exposure to Governance, Risk and Compliance (GRC).
- Demonstrated experience building, maintaining, or maturing an Information Security Management System (ISMS).
- Relevant experience supporting or leading ISO 27001 certification or similar regulatory frameworks.
- Experience managing enterprise security risk registers and facilitating formal risk assessments.
- Experience developing and maintaining security policies, standards, and governance documentation.
- Experience evaluating and recommending security technologies aligned to strategic control objectives.
- Experience reviewing third-party/vendor security questionnaires and assessing risk exposure.
- Experience operating within multi-site or global environments.
- Strong written communication skills with ability to produce executive-level documentation and reporting.
- Desired experience within logistics, warehousing, manufacturing, or other distributed operational environments.
- Experience operating across multiple regions with awareness of data sovereignty and regional regulatory requirements.
- Experience building multi-year security roadmaps and maturity models.
- Familiarity with frameworks such as NIST CSF, CIS Controls, or Zero Trust principles.
- Professional certifications such as CISM, CISSP, CRISC, or ISO 27001 Lead Implementer/Auditor.
Skills & Competencies
- This role requires strong strategic ownership, professional maturity, and the ability to influence across a globally distributed organization whilst building close relationships with engineering and other teams.
- Operate independently with minimal supervision.
- Translate complex technical controls into business risk language.
- Define clear control objectives and governance direction.
- Provide structured, data-driven recommendations to leadership.
- Influence engineering and business stakeholders without formal authority.
- Balance security maturity with operational and commercial realities.
- Demonstrate strong organizational and documentation discipline.
- Communicate effectively with senior leadership and cross-functional teams.
- Maintain a pragmatic, risk-based approach within a fast-moving logistics environment.
Additional Notes
- Must have the ability to travel domestically and internationally where required (relevant travel documentation required).
- Flexible working hours may be required to support global operations across multiple time zones.
- May be required to support major security incidents from a governance and risk advisory perspective.
- Role requires the ability to operate effectively across distributed warehouse and corporate environments.
Physical Requirements
- Work is primarily sedentary. Sits comfortably to do the work; however, there may be some walking, standing, bending, or lifting items weighing up to 15 pounds.
Security Awareness & Culture
- Own and evolve the global security awareness program using Caniphish toolset.
- Coordinate phishing simulations and targeted training campaigns.
- Track behavioral risk metrics and engagement trends.
- Drive continuous improvement in security culture across distributed operational environments.
- Be cognizant of new threat landscape and plan to test employees appropriately (i.e. WhatsApp).
Manager, Information Security employer: Neovia Logistics
Contact Detail:
Neovia Logistics Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Manager, Information Security
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the industry. Attend events, webinars, or even local meetups. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Don’t just apply and wait! Follow up on your applications. A quick email or LinkedIn message to the hiring manager can show your enthusiasm and keep you on their radar. It’s all about making that personal connection!
✨Tip Number 3
Prepare for interviews like it’s game day! Research the company, understand their security challenges, and come armed with ideas on how you can help. Show them you’re not just another candidate, but the one they need to elevate their security posture.
✨Tip Number 4
Leverage our website for job applications! We’ve got loads of resources to help you stand out. Plus, applying through us means you’ll be in the loop for any updates or tips we share along the way. Let’s get you that dream job!
We think you need these skills to ace Manager, Information Security
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience in information security, especially around governance and risk management. We want to see how your skills align with our needs, so don’t hold back on showcasing relevant projects!
Showcase Your Achievements: When detailing your past roles, focus on specific achievements rather than just responsibilities. Use metrics where possible to demonstrate how you’ve improved security postures or led successful initiatives. This helps us see the impact you've made in previous positions.
Be Clear and Concise: We appreciate clarity! Keep your application straightforward and to the point. Avoid jargon unless it’s necessary, and make sure your writing is easy to follow. This will help us understand your qualifications without getting lost in complex language.
Apply Through Our Website: For the best chance of being noticed, apply directly through our website. This ensures your application goes straight to the right team and allows us to process it efficiently. Plus, it shows you’re genuinely interested in joining us at StudySmarter!
How to prepare for a job interview at Neovia Logistics
✨Know Your Stuff
Make sure you’re well-versed in the latest information security trends and frameworks like ISO 27001, NIST, and CIS. Brush up on your knowledge of risk management and compliance, as these will be key topics during the interview.
✨Showcase Your Experience
Prepare to discuss specific examples from your past roles where you’ve successfully developed or maintained an Information Security Management System (ISMS). Highlight any experience with audits, risk assessments, and how you’ve influenced security strategies in previous positions.
✨Understand the Business
Familiarise yourself with Neovia’s business model and operational realities. Be ready to explain how your security strategies can align with their objectives and enhance their overall security posture while considering customer expectations and regulatory obligations.
✨Communicate Clearly
Practice translating complex technical concepts into business language. You’ll need to demonstrate your ability to communicate effectively with senior leadership and cross-functional teams, so think about how you can convey your ideas clearly and concisely.