At a Glance
- Tasks: Lead information security for Defence contracts, ensuring compliance and managing security incidents.
- Company: Join Serco, a global leader in delivering essential services across multiple sectors.
- Benefits: Enjoy flexible working, competitive pension, and discounts on leisure activities.
- Why this job: Make a real impact in national security while developing your career in a supportive environment.
- Qualifications: Experience with MOD policies, risk management, and relevant security certifications required.
- Other info: Dynamic role with opportunities for personal growth and a commitment to diversity.
The predicted salary is between 36000 - 60000 £ per year.
At Serco, we unite the right people, technology, and partners to solve some of the world's most pressing and complex challenges. From defence and space to healthcare, justice, transport and beyond, our UK operations deliver critical services across government sectors—driven by expertise in service design, programme management, engineering, and more.
As an Information Security Manager, you’ll take operational ownership of information security for new Defence contracts, ensuring compliance with MOD Secure by Design (SbD) standards and data protection legislation. You’ll oversee security arrangements across Serco, its partners, and subcontractors, maintaining rigorous audit and assurance processes. This role is key to ensuring secure contract delivery, managing security incidents, and preparing for evolving MOD requirements. You’ll work closely with Data Protection Champions, senior leaders, and Defence stakeholders to uphold the highest security standards across the business.
Key Accountabilities- Lead information security management across new Defence contracts, ensuring compliance with MOD standards such as Secure by Design, DefStan -, and HMG/NCSC guidance.
- Conduct risk assessments and gap analyses using frameworks like NIST SP and ISO , developing action plans to address deficiencies.
- Oversee security assurance activities, including incident response, investigations, and engagement with external audit providers (, CHECK pen-tests and security health checks).
- Support project and design phases with security advice on technical, procedural, personnel, and physical controls, aligned to contractual requirements and MOD certifications.
- Establish and manage internal and external Security Working Groups to drive coordinated security efforts with Serco teams, partners, and suppliers.
- Provide guidance on data protection compliance, working closely with Data Protection Champions and promoting awareness across the Defence Business Unit.
- Deliver security awareness training and foster a proactive security culture within contracts, maintaining certifications like Cyber Essentials Plus and ISO .
- Comprehensive knowledge of and experience with current MOD policies and standards (, Secure by Design, JSP , DefStan - / DCPP)
- ISO Lead Implementer / Auditor
- CISSP or CISM certified
- Data Protection Compliance knowledge and privacy certifications
- Risk management knowledge utilising recognised frameworks, such as NIST
- Experience in the production and delivery of security awareness training
- A willingness to travel to Serco and MOD sites is necessary for the effective delivery of this role.
- The Infosec Lead (Defence Growth) must be able to achieve and maintain formal UK Security Clearance (SC)
Why Serco: Serco’s purpose is to impact a better future - we bring together the right people, the right technology, and the right partners to create innovative solutions that deliver positive impact and address some of the most urgent and complex challenges facing governments globally. Our services are powered by more than , colleagues working across multiple sectors including defence, space, migration, justice, healthcare, transport, and customer services in four regions: UK & Europe, North America, Asia Pacific, and the Middle East.
In this position, your work is vital to the business, in terms of decisions and growth. You will gain a world of opportunity working for a globally operating business delivering essential services across 5 vital sectors, personal growth, achievement, and development won’t be hard to find. You’ll also work with great people. You’ll find yourself working in a highly motivated, supportive environment where no two days are the same, with experienced colleagues who strive for excellence.
What we offer:- days annual leave plus bank holidays.
- Annual leave purchase scheme.
- Up to 6% contributory pension scheme
- Flexible working options.
- Free onsite parking.
- Serco discounts which include cinema, merlin entertainment and online shopping discounts, and discounts on mobile phone plans and leisure centre memberships.
- A range of benefits to support the health and wellbeing of you and your family such as Employee Assistance Programme, Health Cash Plans, free flu jabs and more.
- A wealth of career development training to suit your future aspirations. These range from role specific training, leadership coaching, formal study and much more to support you to build your career with Serco.
- A safe and supportive culture.
- A company passionate about diversity and inclusion.
Information Security Manager (Defence)-MyTechnology in Solihull employer: Serco
Contact Detail:
Serco Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Information Security Manager (Defence)-MyTechnology in Solihull
✨Tip Number 1
Network like a pro! Reach out to current or former employees at Serco on LinkedIn. A friendly chat can give us insider info about the company culture and the role, plus it might just get your foot in the door.
✨Tip Number 2
Prepare for the interview by brushing up on MOD policies and standards. We want to show that we know our stuff, especially around Secure by Design and data protection legislation. It’ll help us stand out as the ideal candidate!
✨Tip Number 3
Practice makes perfect! Get a friend to do a mock interview with us. Focus on articulating our experience with risk assessments and security management. The more comfortable we are, the better we’ll perform when it counts.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure our application gets seen by the right people. Plus, we can tailor our application to highlight how we meet the specific needs of the Information Security Manager role.
We think you need these skills to ace Information Security Manager (Defence)-MyTechnology in Solihull
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Information Security Manager role. Highlight your experience with MOD standards and any relevant certifications like CISSP or CISM. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how you can contribute to our mission at Serco. Be sure to mention your experience with risk assessments and security training.
Showcase Your Achievements: Don’t just list your responsibilities; showcase your achievements! Whether it's leading a successful security initiative or improving compliance rates, we love to see how you've made an impact in your previous roles.
Apply Through Our Website: We encourage you to apply through our website for the best chance of success. It’s straightforward and ensures your application gets to the right people. Plus, you’ll find all the details you need about the role there!
How to prepare for a job interview at Serco
✨Know Your MOD Standards
Familiarise yourself with the MOD Secure by Design standards and other relevant policies like JSP and DefStan. Being able to discuss these frameworks confidently will show that you understand the compliance landscape and can effectively manage security for Defence contracts.
✨Showcase Your Risk Management Skills
Prepare to discuss your experience with risk assessments and gap analyses using frameworks like NIST SP and ISO. Bring examples of how you've developed action plans to address deficiencies, as this will demonstrate your proactive approach to information security management.
✨Engage with Security Assurance Activities
Be ready to talk about your involvement in security assurance activities, including incident response and investigations. Highlight any experiences with external audits or pen-tests, as this will illustrate your hands-on knowledge in maintaining rigorous security standards.
✨Promote a Security Culture
Discuss how you've fostered a proactive security culture in previous roles, especially through training and awareness initiatives. Sharing specific examples of how you've engaged teams and promoted compliance will resonate well with the interviewers at Serco.