At a Glance
- Tasks: Lead the implementation of cutting-edge cyber security strategies and manage security operations.
- Company: Join Sword, a leader in tech solutions for Energy, Public, and Finance sectors.
- Benefits: Enjoy flexible working, competitive salary, and personalised career development.
- Why this job: Make a real impact in digital transformation while working with a talented team.
- Qualifications: Experience in IT security and strong knowledge of Microsoft security technologies required.
- Other info: Diverse and inclusive workplace with excellent growth opportunities.
The predicted salary is between 36000 - 60000 £ per year.
Sword is a leading provider of business technology solutions within the Energy, Public and Finance Sectors, driving transformational change within our clients. We use proven technology, specialist teams and domain expertise to build solid technical foundations across platforms, data and business applications. We have a passion for using technology to solve business problems, working in partnership with our clients to help them achieve their goals.
We are excited to announce that we are looking for an experienced Information Security Manager to join the security team. Reporting directly to the CISO and working directly with the IT Team, you will be responsible for the implementation and delivery of Sword's cyber security strategy and program.
Key Responsibilities- The Information Security Manager is primarily a technical role and will be required to operate with high levels of autonomy, effectively translating business objectives and risk management strategies into specific IT security processes enabled by security technologies and services.
- Security Operations – Implement and oversee the day‑to‑day running of security including M365 Security (Sentinel, Defender, Conditional Access) and Azure security protocols.
- Vulnerability Management – Proactive and risk‑based vulnerability management including attack surface management, system hardening, and cloud security posture management.
- Service Management – Ability to deliver security as a cohesive service through a combination of internal resources and external service providers.
- Incident Response – Oversee security incident management and drive enhancements to risk mitigation strategies through ongoing assessments.
- Security Culture – Drive improvements in the internal security culture through ongoing awareness, training, simulated phishing campaigns and a security champion network.
- Security Governance – Develop and refine security policies, frameworks, and procedures, maintaining alignment and accreditation with ISO 27001 and Cyber Essentials Plus.
- Risk Management – Support security risk assessments across vendors, projects, and internal teams, identifying areas of concern and driving remediation efforts.
- Regulatory & Client Requirements – Ensure Sword remains technically compliant with relevant legal, client and regulatory obligations, keeping pace with evolving security landscapes.
- Third‑Party & Supply Chain Security – Assess and manage technical security risks related to suppliers and partners, ensuring robust security measures are maintained.
- Continuous Improvement – Deliver the security program through a series of continuous and incremental improvements.
This is a challenging and rewarding role that offers the opportunity to work with a talented team and help our clients as they continue their Digital Transformation journey. If you have a passion for technology and enjoy leading and mentoring technical teams, we encourage you to apply for this role.
Requirements- Microsoft security architecture and technologies including EDR, Firewalls, SIEM, Microsoft Purview (including Data Labels, Protection, and DLP), IAM and Email Security.
- Managing IT security infrastructure (e.g. firewalls, intrusion prevention systems, web application firewalls, endpoint protection, SIEM, vulnerability management, Data Loss Prevention, Email Security, Identity and Access Management).
- Cyber Security Frameworks (NIST), regulations such as GDPR and NIS2, and industry standards such as ISO 27001.
- Experience designing the IT security requirements related to the deployment of applications and infrastructure.
- Running security awareness campaigns including regular business updates, simulated phishing campaigns and security training.
- Significant experience in a similar role, preferably in an international organisation, including working with a range of IT and IT security specialist suppliers.
- Major industry certification such as CISSP, CISM or CRISC.
- Certification in relevant Microsoft security technologies.
- Take ownership and accountability with a positive, can‑do attitude including an ability to self‑manage tasks and activities to consistently deliver results.
- Dedicated and proactive learner who keeps up to date with security trends and is continuously improving and refining skills.
- Excellent communication, negotiation and influencing skills – able to influence operational effectiveness across an organisation to achieve results.
At Sword, our core values and culture are based on caring about our people, investing in training and career development, and building inclusive teams where we are all encouraged to contribute to achieve success. We offer comprehensive benefits designed to support your professional development and enhance your overall quality of life.
Competitive Salary, here's what you can expect as part of our benefits package:
- Personalised Career Development: We create a development plan customised to your goals and aspirations, with a range of learning and development opportunities within a culture that encourages growth.
- Flexible working: Flexible work arrangements to support your work‑life balance. We can't promise to always be able to meet every request, however, are keen to discuss your individual preferences to make it work where we can.
- A Fantastic Benefits Package: This includes generous annual leave allowance, enhanced family‑friendly benefits, pension scheme, access to private health, well‑being and insurance schemes.
At Sword we are dedicated to fostering a diverse and inclusive workplace and are proud to be an equal opportunities employer, ensuring that all applicants receive fair and equal consideration for employment, regardless of whether they meet every requirement. If you don't tick all the boxes but feel you have some of the relevant skills and experience we're looking for, please do consider applying and highlight your transferable skills and experience. We embrace diversity in all its forms, valuing individuals regardless of age, disability, gender identity or reassignment, marital or civil partner status, pregnancy or maternity status, race, colour, nationality, ethnic or national origin, religion or belief, sex, or sexual orientation. Your perspective and potential are important to us.
If we can do anything to help make the hiring process more accessible, please let our talent acquisition team know when you apply so we can support any adjustments.
Information Security Manager in Scotland employer: Sword Group
Contact Detail:
Sword Group Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Information Security Manager in Scotland
✨Tip Number 1
Network like a pro! Reach out to your connections in the industry, attend relevant events, and engage with professionals on platforms like LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by researching Sword's values and recent projects. Tailor your responses to show how your experience aligns with their mission of driving transformational change. This will help you stand out as a candidate who truly gets what they're about.
✨Tip Number 3
Showcase your skills through practical examples. When discussing your experience, highlight specific instances where you've implemented security strategies or improved processes. This will demonstrate your hands-on expertise and problem-solving abilities.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, it shows you're genuinely interested in being part of the Sword team. So, get that application in and let’s make it happen!
We think you need these skills to ace Information Security Manager in Scotland
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Information Security Manager role. Highlight your experience with Microsoft security technologies and any relevant certifications like CISSP or CISM. We want to see how your skills align with our needs!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Share your passion for technology and how you’ve driven security improvements in past roles. Let us know why you’re excited about joining Sword and how you can contribute to our mission.
Showcase Your Achievements: Don’t just list your responsibilities; showcase your achievements! Use specific examples of how you’ve implemented security strategies or improved processes. We love seeing quantifiable results that demonstrate your impact.
Apply Through Our Website: We encourage you to apply through our website for a smoother application process. It’s the best way for us to receive your application and ensures you don’t miss out on any important updates from our team!
How to prepare for a job interview at Sword Group
✨Know Your Stuff
Make sure you brush up on Microsoft security architecture and technologies, especially EDR, SIEM, and IAM. Familiarise yourself with the Cyber Security Frameworks like NIST and ISO 27001, as these will likely come up during your chat.
✨Showcase Your Experience
Prepare to discuss your previous roles in security operations and incident management. Be ready to share specific examples of how you've implemented security strategies or managed vulnerabilities in past positions.
✨Demonstrate Leadership Skills
Since this role involves mentoring and leading teams, think of instances where you've successfully led a project or improved a security culture. Highlight your ability to influence and communicate effectively across different teams.
✨Ask Smart Questions
Prepare insightful questions about Sword's current security challenges or their approach to continuous improvement. This shows your genuine interest in the role and helps you gauge if the company aligns with your values.