At a Glance
- Tasks: Lead a team to align product design with security and privacy requirements.
- Company: Join a forward-thinking tech company focused on data security.
- Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
- Why this job: Make a real impact in safeguarding personal data and enhancing security practices.
- Qualifications: Experience in Information Security Management and strong communication skills required.
- Other info: Dynamic role with excellent career advancement potential in a collaborative environment.
The predicted salary is between 48000 - 72000 £ per year.
Engage is a business unit that builds software products that process personal data, and we are looking for an Information Security Manager who can align product design with security and privacy requirements. You will lead a team that manages technical and process security controls, and you will work within our broader security and governance model under the guidance of our security and privacy leaders. You will help keep our controls current, support audits, and ensure that product and services teams follow our security policies. You will also partner with compliance groups and external auditors to maintain certifications and meet regulatory needs. You will communicate risks to our security risk boards and leadership teams. You will succeed in this role by understanding our technology, staying current with security standards, and bringing strong experience from similar roles in distributed organizations.
This role will report to Senior Director of Software Development.
What you will do:
- Align to Precisely Information Security Management System across the Engage business unit that addresses the needs of Engage, staff, partners, customers, and other external stakeholders in line with relevant legislation and industry standards.
- Maintain current SOC 1 & 2 Type II, HIPAA HITECH and ISO 27001 & 27701 certification for Engage software products.
- Maintain documentation and processes necessary to comply with contractual obligations, customer security requirements and internal requirements.
- Propose changes to the Engage Information and Cyber Security systems, processes and procedures by continuously analysing and reviewing appropriate security technologies and practices as informed by Precisely standards.
- Ensure that information and Cyber Security risks to Engage are identified and managed appropriately. Communicate security risks to Precisely InfoSec Risk Board and senior leadership.
- Coordinate quarterly DAST scans, annual internal pen testing and annual third-party penetration testing across all Engage products.
- Maintain accurate security scorecards across all products. Work with product teams to prioritise work to improve security score.
- Coordinate annual legal review of privacy across Engage products.
- Assist investigations into information security breaches under Precisely Incident Response process with Precisely CyberSecurity Operations Center ensuring root-causes of such breaches are understood and addressed.
- Assist as SME in responding to information security questionnaires during RFP process.
What we are looking for:
Experience:
- Management of an Information Security Management System in a complex IT organisation encompassing service delivery, application development and IT infrastructure.
- Completion of Information Security questionnaires as part of RFP responses.
- Line management of team members.
Knowledge:
- An excellent understanding of best practice within Information Security and risk management including standards such as ISO 27001.
- A strong understanding of one or more areas or legislation and regulations that impact information Security e.g. GDPR, HIPAA, PCI DSS, CCPA.
- An understanding of current and emerging threats and countermeasures and the product challenges to addressing these threats.
- An understanding of Application Security threats and countermeasures.
- A good practical knowledge of security technologies and wider business solutions including DevOps, Identity and Access Management, penetration testing tools, remote working and cloud technologies.
Skills:
- The ability to work within a compliance or regulatory framework and to evidence continuous improvement.
- Excellent communication skills, both written and verbal. Ability to present complex or highly technical issues in simple and easy-to-understand formats.
- An ability to think and plan strategically and systematically while recognising the need to deliver to the business requirements.
- The ability to be pragmatic while balancing the needs of the business against security.
- The ability to cut through organisational and political barriers to achieve the overall goal.
Qualifications:
- An appropriate degree, equivalent qualification or experience.
Preferred requirements:
- One or more of the following qualifications are highly desirable: Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Certified Information systems Auditor (CISA), Achieved Senior or Lead level certification in the NCSC's Certified Cyber Professional scheme in one or more of Security and Information Risk Advisor (SIRA), IA Architect, IA Auditor, IT Security Officer.
- Experience using GRC platforms to define and manage InfoSec policies, prepare for audits and manage risk.
- Experience of tooling to manage RFP responses.
- Perform SAST/DAST scans & Pen Test assessments.
- Experience with automated cloud compliance.
The personal data that you provide as a part of this job application will be handled in accordance with relevant laws. For more information about how Precisely handles the personal data of job applicants, please see the Precisely Candidate Privacy Notice.
Information Security Manager employer: Precisely International Jobs
Contact Detail:
Precisely International Jobs Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Information Security Manager
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the industry. Attend meetups, webinars, or even local events. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your skills! Create a portfolio or a personal website that highlights your achievements and projects. This is a great way to demonstrate your expertise in information security and make a lasting impression on potential employers.
✨Tip Number 3
Prepare for interviews by researching the company and its security practices. Be ready to discuss how your experience aligns with their needs, especially around compliance and risk management. Tailor your answers to show you understand their challenges.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our team at Engage.
We think you need these skills to ace Information Security Manager
Some tips for your application 🫡
Tailor Your CV: Make sure your CV speaks directly to the role of Information Security Manager. Highlight your experience with security management systems and any relevant certifications. We want to see how your skills align with our needs!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how your background makes you a perfect fit for our team. Keep it engaging and personal, so we can get to know you better.
Showcase Your Communication Skills: Since this role involves communicating complex security issues, make sure your application reflects your ability to convey technical information clearly. Use straightforward language and examples that demonstrate your communication prowess.
Apply Through Our Website: We encourage you to apply through our website for a smoother process. It helps us keep track of applications and ensures you don’t miss out on any important updates. Plus, it’s super easy!
How to prepare for a job interview at Precisely International Jobs
✨Know Your Standards
Familiarise yourself with key security standards like ISO 27001, HIPAA, and GDPR. Be ready to discuss how these apply to the role and how you've implemented them in past positions.
✨Showcase Your Experience
Prepare specific examples from your previous roles where you managed an Information Security Management System or led a team. Highlight your achievements in maintaining certifications and improving security practices.
✨Communicate Clearly
Practice explaining complex security concepts in simple terms. You’ll need to communicate risks effectively to both technical teams and leadership, so clarity is key.
✨Stay Current with Trends
Research current and emerging threats in information security. Be prepared to discuss how you would address these challenges and what tools or strategies you would recommend for the company.