Information Security Manager

Information Security Manager

Full-Time 43200 - 78000 £ / year (est.) No home office possible
S

At a Glance

  • Tasks: Lead and evolve our information security programme to protect data and systems.
  • Company: Join one of the largest water retailers in the UK with a supportive culture.
  • Benefits: Salary up to £65,000, bonus, 31 days leave, gym membership, and more.
  • Why this job: Make a meaningful impact on cybersecurity while growing your career.
  • Qualifications: Experience in information security and strong understanding of industry standards.
  • Other info: Fast-paced environment with opportunities for professional development and inclusivity.

The predicted salary is between 43200 - 78000 £ per year.

We’re looking for an experienced and forward‑thinking Information Security Manager to lead and evolve our company’s information security programme. In this pivotal role, you will be responsible for safeguarding our data, systems and services from ever‑changing cyber threats, ensuring they remain secure, compliant and resilient.

You’ll shape and implement our information security strategy, set governance standards, and drive secure‑by‑design principles across the business. Working closely with colleagues across IT, Change, HR, Procurement, Compliance and more, you’ll balance security, risk, usability and cost to support Business Stream’s strategic goals.

From managing system vulnerabilities, incident response and risk assessments, to leading supplier security oversight and championing a strong culture of cyber awareness, you will be our subject‑matter expert and primary point of contact for all cybersecurity matters. This role also includes responsibility for operational partnerships, such as managed SOC, SIEM and threat‑management services, and ensuring we continue to mature our security posture in line with recognised frameworks like ISO 27001, NIST and CIS Controls.

If you’re a strategic thinker with willingness and ability to get hands‑on, this role offers the opportunity to make a meaningful impact across the organisation.

Essential skills, knowledge & experience
  • Experience in information security, including leading or owning an information security programme, domain or team.
  • Strong understanding of industry frameworks and standards such as ISO 27001/2, CIS Controls, NIST CSF/800‑53, and established risk methodologies.
  • Hands‑on experience across cloud and modern IT security, particularly Microsoft Azure, M365, Entra, Sentinel, Purview, endpoint security and vulnerability management.
  • Proven capability in incident response, from detection through to lessons learned.
  • Excellent ability to translate technical risk into clear business impact, coupled with confident stakeholder engagement and executive‑level reporting skills.
  • Experience embedding security into change, conducting threat modelling, and steering secure design reviews.
  • Solid understanding of regulatory requirements, including GDPR and other relevant industry regulations.
  • Strong written and verbal communication skills, demonstrating clarity, influence and collaboration.
  • Professional certifications such as CISSP, CISM, CCSP, ISO 27001 Lead Implementer/Auditor, CEH or GIAC.
  • Experience managing security certifications, third‑party risk programmes and assurance activities.
  • Exposure to SIEM engineering, SOAR, IaC security (Terraform/Bicep), scripting for automation, and security tooling optimisation.
  • Knowledge of the water industry or its regulatory landscape.
  • Previous management experience - leading a team and/or managing vendors.

What’s in it for you? You’ll be a key team player in one of the largest water retailers in the UK, with lots of benefits and the chance to grow your career.

  • Salary up to £65,000 DOE plus bonus up to 20%
  • 31 days annual leave and six bank holidays
  • Subsidised staff restaurant and free gym membership
  • Salary sacrifice schemes including cycle to work

We’re passionate about providing a great place to work, where our colleagues feel trusted, valued, supported and empowered, whatever their background or role. And we’re committed to providing an inclusive workplace that welcomes and promotes diversity and provides equal opportunities for everyone. In everything we do, we’re driven to make a positive difference, and always strive to do the right thing by our customers, our people, our local communities and the environment. Life at Business Stream is fast‑paced and exciting, where no two days are the same.

Business Stream is one of the largest water retailers in the UK and a trusted service provider to over 300,000 business customers. With over 16 years’ experience of operating in a competitive water market – longer than any other retailer – we’re the chosen service provider for businesses and organisations ranging from small corner shops to large industrial estates. Headquartered in Edinburgh and employing around 350 people, we provide a range of services including metering and billing, water efficiency support and, water and waste water management solutions.

We’re looking to welcome exceptional people into our fantastic, high‑performing team so if you think this job is for you, we’d love to hear from you. To apply, please click the ‘Apply’ button at the bottom of this page, and send us a copy of your CV. The closing date for applications is Friday 20 February at 5pm.

If you consider yourself to have a disability, we encourage you to disclose that as part of your application. That means we can provide the necessary support and use your unique talents effectively.

Information Security Manager employer: Scottish Water Business Stream Limited

At Business Stream, we pride ourselves on being a leading employer in the water retail sector, offering a dynamic work environment where innovation and collaboration thrive. With competitive salaries, generous leave policies, and a commitment to employee development, we empower our team members to grow their careers while making a positive impact in the community. Our inclusive culture fosters diversity and ensures that every voice is heard, making it an exciting place to work for those passionate about information security.
S

Contact Detail:

Scottish Water Business Stream Limited Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Information Security Manager

✨Tip Number 1

Network like a pro! Reach out to your connections in the industry, attend relevant events, and engage with professionals on platforms like LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

✨Tip Number 2

Prepare for interviews by researching the company and its culture. Understand their information security challenges and be ready to discuss how your experience aligns with their needs. Tailor your responses to show you’re not just a fit for the role, but for the team too!

✨Tip Number 3

Showcase your hands-on experience! Be ready to share specific examples of how you've tackled security incidents or implemented security measures in past roles. This will demonstrate your practical knowledge and problem-solving skills.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our team at Business Stream.

We think you need these skills to ace Information Security Manager

Information Security Management
ISO 27001/2
CIS Controls
NIST CSF/800-53
Cloud Security (Microsoft Azure, M365)
Incident Response
Risk Assessment
Stakeholder Engagement
Threat Modelling
GDPR Compliance
Communication Skills
CISSP Certification
CISM Certification
Security Tooling Optimisation
Team Leadership

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the Information Security Manager role. Highlight your experience with information security programmes and relevant frameworks like ISO 27001 and NIST. We want to see how your skills align with our needs!

Showcase Your Hands-On Experience: Don’t just list your qualifications; show us your hands-on experience with cloud security, incident response, and risk assessments. We love candidates who can demonstrate their practical knowledge in real-world scenarios.

Communicate Clearly: Your written application should reflect your strong communication skills. Use clear and concise language to explain your achievements and how they relate to the role. Remember, clarity is key for us!

Apply Through Our Website: We encourage you to apply through our website for a smoother process. It’s the best way for us to receive your application and ensures you don’t miss any important updates from our team!

How to prepare for a job interview at Scottish Water Business Stream Limited

✨Know Your Frameworks

Make sure you brush up on your knowledge of industry frameworks like ISO 27001, NIST, and CIS Controls. Be ready to discuss how you've applied these in previous roles, as this will show your depth of understanding and practical experience.

✨Showcase Your Hands-On Experience

Prepare to share specific examples of your hands-on experience with cloud security, particularly with Microsoft Azure and M365. Highlight any incidents you've managed or vulnerabilities you've addressed, as this will demonstrate your capability in real-world scenarios.

✨Communicate Clearly

Practice translating technical jargon into business impact. You’ll need to engage with stakeholders at all levels, so being able to communicate complex information clearly and effectively is key. Think about how you can illustrate your points with relatable examples.

✨Emphasise Team Collaboration

Since this role involves working closely with various departments, be prepared to discuss how you've successfully collaborated with teams in the past. Share instances where you’ve embedded security into change processes or conducted secure design reviews, showcasing your ability to work cross-functionally.

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

S
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>