Information Security Manager

Information Security Manager

Full-Time 80000 - 85000 £ / year (est.) No working from home possible
NHBC

At a Glance

  • Tasks: Lead and improve NHBC's Information Security Management System while ensuring compliance and risk management.
  • Company: Join NHBC, a leader in safeguarding innovation and security.
  • Benefits: Enjoy a competitive salary, performance bonus, and 27 days annual leave.
  • Other info: Work hybrid in Milton Keynes or London with excellent career growth opportunities.
  • Why this job: Make a real impact on security strategy and culture in a collaborative environment.
  • Qualifications: Proven experience in information security and strong knowledge of ISO 27001.

The predicted salary is between 80000 - 85000 £ per year.

At NHBC, information security is about more than protecting systems; it's about enabling the business to innovate confidently while safeguarding our customers, colleagues and reputation. We're looking for an experienced Information Security Manager to play a pivotal role in strengthening our security and risk capability across the organisation.

Working closely with the Chief Information Security Officer (CISO), you'll lead the development and continual improvement of our Information Security Management System (ISMS), ensuring security is embedded into everything we do. You'll work across technology and business teams, influencing decisions, managing security risk and helping ensure compliance with key regulatory and industry standards.

This is an opportunity for someone who enjoys combining strategic thinking with hands-on delivery, someone who can build strong relationships, provide pragmatic advice and make security an enabler rather than a barrier.

What you'll be doing

  • Leading the continual improvement of NHBC's Information Security Management System (ISMS), aligned to ISO 27001 and NCSC guidance.
  • Embedding security, operational resilience and regulatory requirements into projects, business processes and technology change.
  • Owning and maintaining information security policies, standards and governance documentation.
  • Leading security due diligence and assurance activities for suppliers and third parties, supporting PRA operational resilience and outsourcing requirements.
  • Working with risk and compliance teams to identify, assess and manage information security risks and controls.
  • Monitoring the effectiveness of security controls and driving meaningful improvements where needed.
  • Producing insightful risk metrics, reporting and management information to support governance and executive decision-making.
  • Delivering engaging security awareness initiatives that help build a positive security culture.
  • Acting as a trusted adviser across the business, translating complex security requirements into practical, business-focused solutions.

What we’re looking for

You’ll be an experienced information security professional who understands how to balance security, risk and business priorities in a regulated environment. You’ll also have:

  • Experience leading information security within a risk-led organisation.
  • Proven experience implementing and operating an Information Security Management System (ISMS).
  • Strong knowledge of ISO 27001, NCSC guidance and NIST Cybersecurity Framework.
  • Experience embedding security into business processes, projects and technology delivery.
  • A solid understanding of cloud, digital and emerging AI-related security risks.
  • Experience working with third-party risk, supplier assurance and operational resilience requirements.
  • Knowledge of PRA/FCA regulations, UK GDPR and the Data Protection Act 2018.
  • Experience working within a Three Lines of Defence model and alongside architecture and engineering teams.
  • Excellent communication and stakeholder management skills, with the ability to influence at all levels.
  • Professional certifications such as CISSP, CISM, CISA or equivalent.

Why join NHBC?

This is a role where you’ll have genuine influence, helping shape the organisation’s security strategy while working with a wide range of stakeholders across the business. You’ll join a collaborative team that values practical thinking, continuous improvement and delivering security that enables the organisation to succeed.

What we offer

Our benefits package includes: 27 days annual leave +

Information Security Manager employer: NHBC

NHBC is an excellent employer that values its employees by fostering a collaborative work culture in Milton Keynes, where teamwork and communication are at the forefront of our operations. We offer comprehensive training and development opportunities to ensure your professional growth while providing a supportive environment that prioritises customer service excellence. Join us to be part of a dedicated team committed to making a meaningful impact in the building and inspections sector.

NHBC

Contact Details:

NHBC Recruitment Team

We think you need these skills to ace Information Security Manager

Information Security Management System (ISMS)
ISO 27001
NCSC guidance
NIST Cybersecurity Framework
Risk Management
Supplier Assurance
Operational Resilience