At a Glance
- Tasks: Lead and improve the Information Security Management System to ensure compliance and security.
- Company: Join a forward-thinking organisation committed to information security excellence.
- Benefits: Competitive salary, flexible working options, and a comprehensive benefits package.
- Other info: Opportunity to mentor junior team members and influence senior management.
- Why this job: Make a real impact on security governance while developing your career in a dynamic environment.
- Qualifications: Experience with ISO 27001, Cyber Essentials, and strong risk management skills required.
The predicted salary is between 60000 - 75000 £ per year.
The InfoSec Manager owns and drives the SCS’s Information Security Management System (ISMS), ensuring it stays certified, compliant, and continually improving. The role is accountable for maintaining compliance with ISO 27001, Cyber Essentials Plus, and the HS2 information security requirements set out in WI‑835, including BPSS screening and UK‑based data hosting. The purpose is to achieve, maintain, and demonstrate full compliance for the duration of the project while strengthening security governance, reducing risk, and keeping the ISMS audit‑ready.
Key Responsibilities
- Lead the implementation, maintenance, and continual improvement of the ISMS in line with ISO 27001.
- Ensure the ISMS remains audit‑ready, risk‑driven, and aligned with organisational and contractual requirements.
- Own and maintain the full suite of ISMS documentation including policies, processes, procedures, standards, and records.
- Achieve and maintain ISO 27001 certification, ensuring controls, evidence, and processes remain compliant year‑round.
- Achieve and maintain Cyber Essentials Plus certification, leading the implementation of required technical and organisational controls.
- Ensure compliance with HS2 WI‑835 requirements, including BPSS screening and UK‑based data hosting.
- Lead a comprehensive audit programme (internal, external, CE+, penetration testing) to assess control effectiveness and drive corrective actions.
- Maintain and communicate an effective information security risk management framework that enables informed decision‑making at senior levels.
- Drive proactive risk identification, assessment, treatment, and monitoring across the organisation.
- Recommend and deploy organisational and technical controls that are proportional, cost‑effective, and aligned with risk appetite and available resources.
- Champion a strong security culture across SCS JV, ensuring policies and expectations are understood and embedded.
- Lead the design and delivery of security training and awareness, ensuring all staff— from the board to delivery units—maintain good security behaviours.
- Influence and support process owners to improve processes where security weaknesses are identified.
- Work within and improve existing processes to enhance security governance and operational efficiency.
- Ensure security requirements are considered in projects, procurement, supplier onboarding, and change initiatives.
- Lead, mentor, and develop junior InfoSec team members, ensuring the team has the competence and capability to run an effective ISMS.
- Influence senior managers to secure the necessary resources to sustain and improve the security function.
- Drive continual improvement of security controls, behaviours, and processes in line with ISO 27001, Cyber Essentials, and industry best practice.
- Track emerging risks, threats, and compliance changes, ensuring the ISMS evolves to remain effective and relevant.
Essential Qualifications
- Demonstrable experience working with ISO 27001 and/or an ISO 27001 aligned ISMS.
- Demonstrable experience working with Cyber Essentials.
- Certified Information Security Manager (CISM) or equivalent qualification.
- Demonstrable understanding of cloud technology.
- Demonstrable working understanding of security technology and how it’s deployed to create effective technical controls (e.g., firewalls, IDS, IAM, MFA, SSO, DLP, CASB, MDM, EDR).
- Demonstrable risk‑management knowledge and the ability to influence senior management on risk treatment decisions.
- Working knowledge of Microsoft 365 and associated applications (e.g., Windows, Word, Excel, PowerPoint).
- Working knowledge of the UK Data Protection Act (DPA) / GDPR.
- Demonstrable good level of written and spoken English.
Desirable Qualifications
- Commonly identifiable security qualification (e.g., CISA, CRISC, CDPSE, CGEIT, CCOA, CISSP).
- Experience of other InfoSec standards (e.g., NIST, PCI‑DSS, SOC).
- Working knowledge of Microsoft 365 / Azure security.
- Experience leading audit processes (internal, external, pen testing).
- Experience with recent cyber security incidents.
- Expert knowledge of Microsoft 365 and its associated applications.
- Ability to demonstrate that you meet the minimum job criteria and person specification.
Salary Competitive with excellent benefits package. Flexible working: We welcome you to ask about flexibility you need—part‑time, remote or compressed hours. We will explore what’s possible.
Information Security Manager in City of Westminster employer: SCS Railways
As an Information Security Manager at SCS, you will be part of a dynamic team dedicated to maintaining the highest standards of information security. Our commitment to employee growth is reflected in our supportive work culture, where mentorship and continuous improvement are prioritised. With competitive salaries, flexible working arrangements, and a focus on fostering a strong security culture, SCS offers a rewarding environment for professionals looking to make a meaningful impact in the field of information security.
StudySmarter Expert Advice🤫
We think this is how you could land Information Security Manager in City of Westminster
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the InfoSec world. Attend industry events, webinars, or local meetups. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your skills! Create a personal project or contribute to open-source initiatives related to information security. This not only boosts your CV but also gives you real-world experience to chat about in interviews.
✨Tip Number 3
Prepare for those interviews! Research common questions for InfoSec Manager roles and practice your answers. Be ready to discuss your experience with ISO 27001 and Cyber Essentials, as well as how you've handled risk management in the past.
✨Tip Number 4
Apply through our website! We’ve got loads of opportunities waiting for you. Tailor your application to highlight your relevant experience and show us why you’re the perfect fit for the role. Don’t miss out!
We think you need these skills to ace Information Security Manager in City of Westminster
Some tips for your application 🫡
Tailor Your CV:Make sure your CV speaks directly to the role of Information Security Manager. Highlight your experience with ISO 27001 and Cyber Essentials, and don’t forget to mention any relevant certifications. We want to see how your skills align with what we’re looking for!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you’re passionate about information security and how your background makes you the perfect fit for our team. Keep it engaging and personal—let us know who you are beyond the qualifications.
Showcase Your Achievements:When detailing your experience, focus on specific achievements that demonstrate your ability to maintain compliance and improve security governance. Use metrics where possible to show the impact of your work. We love numbers that tell a story!
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, you’ll find all the details you need about the role and our company culture there!
How to prepare for a job interview at SCS Railways
✨Know Your Standards
Make sure you’re well-versed in ISO 27001 and Cyber Essentials. Brush up on the specific requirements and how they apply to the role. Being able to discuss these standards confidently will show that you’re serious about compliance and security.
✨Showcase Your Experience
Prepare examples from your past work where you’ve successfully implemented or maintained an ISMS. Highlight any audits you’ve led or participated in, and be ready to discuss how you’ve driven improvements in security governance.
✨Understand Risk Management
Be prepared to talk about your approach to risk management. Think of specific instances where you identified risks and how you influenced senior management to make informed decisions. This will demonstrate your ability to align security with business objectives.
✨Communicate Security Culture
Discuss how you’ve fostered a strong security culture in previous roles. Share strategies you’ve used for training and awareness, and how you’ve engaged staff at all levels. This shows you can champion security across the organisation.