Information Security Manager

Information Security Manager

Full-Time 60000 - 75000 £ / year (est.) No working from home possible
SCS Railways

At a Glance

  • Tasks: Lead and enhance our Information Security Management System to ensure compliance and security.
  • Company: Join a forward-thinking organisation committed to information security excellence.
  • Benefits: Competitive salary, flexible working options, and a comprehensive benefits package.
  • Other info: Opportunity to mentor junior team members and drive continuous improvement in security practices.
  • Why this job: Make a real impact on security governance while developing your career in a dynamic environment.
  • Qualifications: Experience with ISO 27001, Cyber Essentials, and strong risk management skills required.

The predicted salary is between 60000 - 75000 £ per year.

The InfoSec Manager owns and drives the SCS’s Information Security Management System (ISMS), ensuring it stays certified, compliant, and continually improving. The role is accountable for maintaining compliance with ISO 27001, Cyber Essentials Plus, and the HS2 information security requirements set out in WI‑835, including BPSS screening and UK‑based data hosting. The purpose is to achieve, maintain, and demonstrate full compliance for the duration of the project while strengthening security governance, reducing risk, and keeping the ISMS audit‑ready.

Key Responsibilities

  • Lead the implementation, maintenance, and continual improvement of the ISMS in line with ISO 27001.
  • Ensure the ISMS remains audit‑ready, risk‑driven, and aligned with organisational and contractual requirements.
  • Own and maintain the full suite of ISMS documentation including policies, processes, procedures, standards, and records.
  • Achieve and maintain ISO 27001 certification, ensuring controls, evidence, and processes remain compliant year‑round.
  • Achieve and maintain Cyber Essentials Plus certification, leading the implementation of required technical and organisational controls.
  • Ensure compliance with HS2 WI‑835 requirements, including BPSS screening and UK‑based data hosting.
  • Lead a comprehensive audit programme (internal, external, CE+, penetration testing) to assess control effectiveness and drive corrective actions.
  • Maintain and communicate an effective information security risk management framework that enables informed decision‑making at senior levels.
  • Drive proactive risk identification, assessment, treatment, and monitoring across the organisation.
  • Recommend and deploy organisational and technical controls that are proportional, cost‑effective, and aligned with risk appetite and available resources.
  • Champion a strong security culture across SCS JV, ensuring policies and expectations are understood and embedded.
  • Lead the design and delivery of security training and awareness, ensuring all staff— from the board to delivery units—maintain good security behaviours.
  • Influence and support process owners to improve processes where security weaknesses are identified.
  • Work within and improve existing processes to enhance security governance and operational efficiency.
  • Ensure security requirements are considered in projects, procurement, supplier onboarding, and change initiatives.
  • Lead, mentor, and develop junior InfoSec team members, ensuring the team has the competence and capability to run an effective ISMS.
  • Influence senior managers to secure the necessary resources to sustain and improve the security function.
  • Drive continual improvement of security controls, behaviours, and processes in line with ISO 27001, Cyber Essentials, and industry best practice.
  • Track emerging risks, threats, and compliance changes, ensuring the ISMS evolves to remain effective and relevant.

Essential Qualifications

  • Demonstrable experience working with ISO 27001 and/or an ISO 27001 aligned ISMS.
  • Demonstrable experience working with Cyber Essentials.
  • Certified Information Security Manager (CISM) or equivalent qualification.
  • Demonstrable understanding of cloud technology.
  • Demonstrable working understanding of security technology and how it’s deployed to create effective technical controls (e.g., firewalls, IDS, IAM, MFA, SSO, DLP, CASB, MDM, EDR).
  • Demonstrable risk‑management knowledge and the ability to influence senior management on risk treatment decisions.
  • Working knowledge of Microsoft 365 and associated applications (e.g., Windows, Word, Excel, PowerPoint).
  • Working knowledge of the UK Data Protection Act (DPA) / GDPR.
  • Demonstrable good level of written and spoken English.

Desirable Qualifications

  • Commonly identifiable security qualification (e.g., CISA, CRISC, CDPSE, CGEIT, CCOA, CISSP).
  • Experience of other InfoSec standards (e.g., NIST, PCI‑DSS, SOC).
  • Working knowledge of Microsoft 365 / Azure security.
  • Experience leading audit processes (internal, external, pen testing).
  • Experience with recent cyber security incidents.
  • Expert knowledge of Microsoft 365 and its associated applications.
  • Ability to demonstrate that you meet the minimum job criteria and person specification.

Salary Competitive with excellent benefits package. Flexible working: We welcome you to ask about flexibility you need—part‑time, remote or compressed hours. We will explore what’s possible.

Information Security Manager employer: SCS Railways

As an Information Security Manager at SCS, you will be part of a dynamic team dedicated to maintaining the highest standards of information security. Our commitment to employee growth is reflected in our supportive work culture, where mentorship and continuous improvement are prioritised. With competitive salaries, flexible working options, and a focus on fostering a strong security culture, SCS offers a rewarding environment for professionals looking to make a meaningful impact in the field of information security.

SCS Railways

Contact Details:

SCS Railways Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Security Manager

Tip Number 1

Network like a pro! Get out there and connect with folks in the InfoSec world. Attend industry events, join online forums, or even hit up LinkedIn. The more people you know, the better your chances of landing that dream job.

Tip Number 2

Show off your skills! Create a portfolio or a personal website where you can showcase your experience with ISO 27001, Cyber Essentials, and any cool projects you've worked on. This gives potential employers a taste of what you can bring to the table.

Tip Number 3

Prepare for interviews like it’s a big game day! Research the company, understand their security needs, and be ready to discuss how you can help them maintain compliance and improve their ISMS. Confidence is key!

Tip Number 4

Don’t forget to apply through our website! We’ve got loads of opportunities waiting for you, and applying directly can sometimes give you an edge. Plus, we love seeing candidates who are proactive about their job search!

We think you need these skills to ace Information Security Manager

ISO 27001
Cyber Essentials Plus
Information Security Management System (ISMS)
Risk Management
Audit Processes
Security Governance
Technical Controls Deployment

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience with ISO 27001 and Cyber Essentials. We want to see how your skills align with the role, so don’t hold back on showcasing your relevant achievements!

Showcase Your Knowledge:In your written application, demonstrate your understanding of information security principles and frameworks. Mention any specific projects or experiences that relate to maintaining compliance and improving ISMS, as this will really catch our eye.

Be Clear and Concise:Keep your writing clear and to the point. Use bullet points where appropriate to make it easy for us to read through your qualifications and experiences. Remember, we’re looking for someone who can communicate effectively!

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows you’re keen to join our team at StudySmarter!

How to prepare for a job interview at SCS Railways

Know Your Standards

Make sure you’re well-versed in ISO 27001 and Cyber Essentials. Brush up on the specific requirements and how they apply to the role. Being able to discuss these standards confidently will show that you’re serious about compliance and security.

Showcase Your Experience

Prepare examples from your past work where you’ve successfully implemented or maintained an ISMS. Highlight any audits you’ve led or participated in, and be ready to discuss how you’ve driven improvements in security governance.

Understand Risk Management

Be prepared to talk about your approach to risk management. Think of specific instances where you identified risks and how you influenced senior management to make informed decisions. This will demonstrate your ability to align security with business objectives.

Communicate Effectively

Since this role involves training and influencing others, practice explaining complex security concepts in simple terms. Show that you can engage with various stakeholders, from technical teams to senior management, ensuring everyone understands their role in maintaining security.