At a Glance
- Tasks: Lead and enhance our information security across the business, ensuring a robust cybersecurity posture.
- Company: Fast-growing e-commerce company prioritising security and innovation.
- Benefits: Competitive salary, flexible working, and opportunities for professional growth.
- Why this job: Make a real impact in a hands-on role that shapes our security culture.
- Qualifications: Experience in information security and familiarity with AWS security services.
- Other info: Join a dynamic team where your contributions directly influence our security strategy.
The predicted salary is between 60000 - 75000 £ per year.
We are looking for an Information Security Manager to take ownership of information security across the business. You will be the go-to authority on cybersecurity, managing security tooling, driving compliance programmes, leading risk assessments and communicating security posture to senior leadership. We have built strong foundations and we need someone to own this domain full-time: to keep raising the bar, strengthen what’s in place and embed security into the way the whole organisation works. This is a hands-on role in a fast-growing e-commerce business where security is treated as a priority, not an afterthought.
What You’ll Do
- Security Operations & Tooling
- Own and continuously strengthen our cloud security posture across AWS as our primary platform, with oversight of our Azure and GCP environments.
- Manage and optimise our WAF, bot management and DDoS protection to keep our platform secure and performant.
- Drive vulnerability management across cloud infrastructure and application code, ensuring timely prioritisation and resolution.
- Lead incident response - coordinate detection, investigation, containment and post-incident reviews.
- Maintain and evolve security monitoring, alerting and operational runbooks to ensure consistent coverage.
- Governance, Compliance & Policy
- Own and evolve the company’s information security policy framework, ensuring policies remain current, practical and enforced.
- Drive UK GDPR, DPA 2018 and PCI-DSS compliance in partnership with the Technology Director and development team.
- Lead the security dimension of vendor and third-party risk assessments.
- Deliver clear, confident security reporting to senior leadership and due diligence audiences.
- Risk Management & Security Culture
- Maintain and develop the technology risk register, running regular risk assessments aligned to business continuity planning.
- Champion security awareness across the business through training programmes, phishing simulations and practical guidance.
- Evaluate the security implications of new tools, integrations and emerging technologies including AI-assisted development.
- Contribute to architecture and design reviews, ensuring security is built in from the start.
What We’re Looking For
- Required Experience in an information security role (Security Manager, Security Analyst, GRC lead or similar), ideally within a technology or e-commerce environment.
- Working knowledge of AWS security services such as Security Hub, GuardDuty, IAM, CloudTrail and KMS. AWS is our primary cloud provider and hands-on familiarity is important.
- Practical understanding of UK GDPR, DPA 2018 and PCI-DSS compliance requirements.
- Experience building or maturing security governance policies, risk registers, incident response procedures.
- Ability to communicate security risk and posture clearly to both technical teams and senior leadership.
- Hands-on comfort with security tooling, log analysis and vulnerability triage - this isn’t a role where you only write documents.
Nice to Have
- Relevant certifications such as CompTIA Security+, CISM, AWS Security Specialty or ISO 27001 Lead Implementer.
- Experience with WAF and bot management in a production e-commerce context.
- Familiarity with SIEM, SOAR or security automation tooling.
- Exposure to ISO 27001 implementation or SOC 2 readiness programmes.
- Experience with multi-cloud security across Azure and GCP.
- Background in e-commerce, retail or DTC brands.
What Success Looks Like
In your first six months you’ll have:
- Taken full ownership of our security tooling and established a clear, measurable improvement plan.
- Built a structured vulnerability management lifecycle with defined SLAs and visible progress.
- Strengthened our policy framework and set direction toward a recognised maturity framework.
- Delivered security reporting that gives senior leadership a clear and confident view of our posture.
- Launched a security awareness programme with measurable engagement across the business.
- Built strong working relationships across the technology team and the wider business.
Behaviours & Traits
- Commercially wired - you think in LTV, contribution margin, and payback periods, not just campaign metrics.
- Ownership mindset - you don’t wait to be told; you identify the gap and go close it.
- Comfortable with ambiguity - the playbook doesn’t fully exist yet; you’ll write it.
- Bias for testing - you run experiments, read the data, and act on it quickly.
- Customer-obsessed without being soft - you understand what makes Protein Works’ community tick and you use that commercially.
Information Security Manager in Liverpool employer: Protein Works
Contact Detail:
Protein Works Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Information Security Manager in Liverpool
✨Tip Number 1
Network like a pro! Reach out to folks in the industry on LinkedIn or at events. A friendly chat can lead to opportunities that aren’t even advertised yet.
✨Tip Number 2
Show off your skills! Create a portfolio or a personal project that highlights your expertise in information security. This gives you something tangible to discuss during interviews.
✨Tip Number 3
Prepare for the interview by researching the company’s security posture and recent news. Tailor your answers to show how you can specifically help them strengthen their security.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive!
We think you need these skills to ace Information Security Manager in Liverpool
Some tips for your application 🫡
Show Your Passion for Security: When writing your application, let your enthusiasm for information security shine through. We want to see that you’re not just ticking boxes but genuinely excited about keeping our e-commerce platform secure.
Tailor Your Experience: Make sure to highlight your relevant experience in information security, especially with AWS and compliance frameworks like UK GDPR and PCI-DSS. We love seeing how your background aligns with what we need!
Be Clear and Concise: Communicate your skills and experiences clearly. Use straightforward language to explain complex security concepts, as you'll need to do this with senior leadership too. We appreciate clarity over jargon!
Apply Through Our Website: Don’t forget to submit your application through our website! It’s the best way for us to receive your details and ensures you’re considered for the role. We can’t wait to hear from you!
How to prepare for a job interview at Protein Works
✨Know Your Stuff
Make sure you brush up on your knowledge of AWS security services and compliance requirements like UK GDPR and PCI-DSS. Be ready to discuss how you've applied this knowledge in previous roles, as it shows you're not just familiar with the theory but can also put it into practice.
✨Show Your Hands-On Experience
This role is all about being hands-on, so be prepared to share specific examples of how you've managed security tooling or led incident responses. Highlight any direct experience with vulnerability management and how you've improved security postures in past positions.
✨Communicate Clearly
You'll need to convey complex security concepts to both technical teams and senior leadership. Practice explaining your past projects in simple terms, focusing on the impact and results. This will demonstrate your ability to bridge the gap between tech and business.
✨Emphasise Your Ownership Mindset
The company is looking for someone who takes initiative and ownership. Prepare examples of times when you've identified gaps in security processes and taken action to close them. This will show that you're proactive and ready to take charge in a fast-paced environment.