At a Glance
- Tasks: Lead our Information Security and Data Protection programmes while ensuring compliance with industry standards.
- Company: Join Focusrite, a global leader in music technology with a vibrant culture.
- Benefits: Enjoy flexible working, private healthcare, and exciting company events.
- Other info: Be part of a diverse team dedicated to innovation and sustainability.
- Why this job: Make a real impact in the music tech industry while shaping data protection and security.
- Qualifications: Experience in Information Security and Data Protection, with a passion for learning.
The predicted salary is between 60000 - 85000 £ per year.
Based: Remote (UK)/High Wycombe/London (N7)/Hybrid
Term: Permanent, Full time
Reporting to: Chief Information Officer (CIO)
Salary: £60k - £85k pa + excellent benefits
The Role:
We're looking for an Information Security Compliance Specialist to take ownership of our Information Security, Data Protection, and AI Governance programmes across the Focusrite Group. You will be the operational owner of our Information Security and Data Protection (ISDP) framework informed by ISO 27001 (ISMS), ISO 27701 (PIMS), Cyber Essentials and NIST CSF keeping us aligned to those standards and ready for certification and audit.
Working alongside development, IT, and business teams, you will advise on security and privacy requirements for new and changing systems, ensuring appropriate controls are designed in, evidenced, and verified after implementation. You will also own the Group's response to emerging risks in AI, translating evolving regulation (EU AI Act, UK AI principles, ICO guidance) into practical governance.
About you:
Several years' experience in Information Security and Data Protection, with a good understanding of IT systems, web operations, cloud platforms, and secure coding practices (including OWASP). Comfortable engaging at all levels of the organisation and externally, with the gravitas to influence security and privacy outcomes and reduce the impact of change. The position requires providing support and advice to all parts of the Group on Information Security and Data Protection.
You will be responsible for:
- Information Security Systems: Framework & advisory: own the Information Security and Data Protection Framework and its documentation, and advise IT, development, and business teams on security requirements.
- Tools & supplier assurance: run the Business Approved Tools process (including assessment of AI tools, vendors, and use cases), own designated Information Security tools, and conduct supplier audit assessments.
- Certification & standards: own certification readiness for Cyber Essentials and lead new certification efforts as the business requires.
- Threats, incidents & testing: monitor cyber threats and translate them for the business, own the incident management process (including phishing response and simulation exercises), and manage vulnerability scans and penetration testing (including external Red/Purple/Blue Team engagements).
- Risk & resilience: conduct risk assessments across products, systems, and processes; own the Information Security and Data Protection risk register, contributing to the Group Risk Management process; and maintain and test the Business Continuity Plan (BCP).
- AI Governance: own the AI Governance framework, AI system inventory, and alignment with ISO 42001, NIST AI RMF, and the EU AI Act where appropriate.
Data Protection compliance primarily UK GDPR and Data Protection Act, EU GDPR, and US state privacy laws (including CCPA/CPRA), to own and maintain all requirements including:
- Data subject rights & assessments: handle Data Subject Rights requests (Subject Access, erasure, rectification, restriction, objection, portability, and rights relating to automated decision-making) and run Data Protection Impact Assessments (DPIAs).
- Records & registers: maintain the Records of Processing Activities (RoPA) under Article 30 for controller and processor activities, the lawful basis register, consent records, and Legitimate Interest Assessments (LIAs).
- Notices, cookies & marketing: operate Privacy Notices and Cookie Tools (OneTrust), and advise on PECR and e-privacy compliance including direct marketing and electronic communications.
- Privacy by Design & training: help product managers and developers embed Privacy by Design, and design and deliver Data Protection training and awareness across the Group.
- Retention & breach management: own the retention schedule and deletion/anonymisation processes, and own personal data breach handling (including detection triage, 72-hour ICO/EU supervisory authority notification, data subject notification where required, and the breach register).
- Third parties & international transfers: manage processor and sub-processor governance (Article 28 due diligence, Data Processing Agreements, processor register) and international data transfers (SCCs, the UK IDTA/Addendum, and Transfer Risk Assessments).
Change Management:
- Review and provide security and data protection sign-off on changes to systems, products, and processes.
- Participate in the Change Advisory Board (CAB) and ensure security and privacy risks are assessed before changes are approved.
- Own change management procedures relating to Information Security and Data Protection, ensuring evidence is captured for audit.
- Ensure security and privacy requirements are embedded in the SDLC and release processes, working with development and operational teams.
- Track and report on the security impact of significant business, technology, and organisational change initiatives.
Compliance:
- Generate monthly compliance and activity reports and other reports as required by senior management.
- Internal Audit:
- Reviewing Financial System compliance activities.
- Performing Internal Information Security Audits.
- Performing Internal Data Protection Audits.
- External audit:
- Be the key contact for any IT / Data Protection related audits by external bodies, ensuring requested data is supplied, complete, and accurate.
- Take ownership of any related audit issues.
- Generate audit support documents.
You will be expected to keep up to date with developments in the security, privacy, and AI regulatory landscape, translating these into practical actions for the Group.
We understand that not all candidates will have in-depth experience of all these elements, so we welcome applications from candidates who meet most of the criteria and have a desire to learn the rest. Please provide details in your covering letter of additional training requirements / certifications in progress etc.
About Us:
Focusrite plc is a global music and audio group that develops and markets music technology products. Used by audio professionals and amateur musicians alike, our solutions facilitate the high-quality production of recorded and live sound. Our audio technology brands stand together, seeking to enrich lives through music by removing barriers to creativity – ‘we make music easy to make’.
The Focusrite Group trades under thirteen established and rapidly growing brands: Focusrite, Focusrite Pro, Novation, ADAM Audio, Sequential, Oberheim, Martin Audio, Optimal Audio, Ampify Music, Linea Research, Sonnox, OutBoard and TiMax. With a high-quality reputation and a rich heritage spanning decades, its brands are category leaders in the music-making industry.
Music technology is an enriching space to work in and we enjoy a Group-wide open-door culture which encourages innovation. This culture, combined with a passion for the inspirational solutions we create, has led to the group winning numerous accolades, including six Queen's Awards, the AIM Company of the Year Award 2021 and regular appearances in 'The Sunday Times 100 Best Small Companies to Work For’.
The Focusrite Group is dedicated to building a great place to work and as an equal opportunity employer we are committed to Diversity and Inclusion. The group mission is to cultivate an equitable culture, internally and externally, where all people feel they are welcome, safe and positively represented, because at Focusrite they truly are. Equally, we recognise the major impact that climate change is having on our world and work every day towards being industry leaders in a carbon neutral future.
Benefits include flexible/hybrid working, company pension, life insurance, private healthcare, Health Cash Plan, enhanced Maternity and Paternity pay, employee purchase scheme, group bonus scheme, company music events, offsite company parties and free lunch in the canteen. We arrange company training sessions and encourage personal development.
Information Security & Data Protection Manager in High Wycombe employer: The Focusrite Group
At Focusrite, we pride ourselves on being an exceptional employer, offering a vibrant work culture that fosters creativity and innovation in the music technology industry. With flexible hybrid working options, comprehensive benefits including private healthcare and enhanced parental leave, and a strong commitment to employee growth through training and development opportunities, we ensure our team members feel valued and supported. Join us in a collaborative environment where your contributions directly impact our mission to make music easy to create, all while being part of a diverse and inclusive community.
StudySmarter Expert Advice🤫
We think this is how you could land Information Security & Data Protection Manager in High Wycombe
✨Tip Number 1
Network like a pro! Reach out to people in the industry, attend events, and connect on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by researching the company and its culture. Understand their values and how they align with your own. This will help you tailor your responses and show that you're genuinely interested in being part of the team.
✨Tip Number 3
Practice common interview questions and scenarios related to Information Security and Data Protection. Use the STAR method (Situation, Task, Action, Result) to structure your answers and demonstrate your problem-solving skills.
✨Tip Number 4
Don’t forget to follow up after your interview! A simple thank-you email can leave a lasting impression and show your enthusiasm for the role. Plus, it keeps you on their radar as they make their decision.
We think you need these skills to ace Information Security & Data Protection Manager in High Wycombe
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Information Security & Data Protection Manager role. Highlight relevant experience and skills that align with the job description, especially around ISO standards and data protection compliance.
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how your background makes you a great fit for our team. Don’t forget to mention any ongoing training or certifications!
Showcase Your Achievements:When detailing your experience, focus on specific achievements rather than just duties. Use metrics where possible to demonstrate your impact in previous roles, especially in areas like risk management and compliance.
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands and shows us you’re serious about joining the StudySmarter family!
How to prepare for a job interview at The Focusrite Group
✨Know Your Standards
Familiarise yourself with ISO 27001, ISO 27701, and Cyber Essentials. Be ready to discuss how these standards apply to the role and how you can ensure compliance within the organisation.
✨Showcase Your Experience
Prepare specific examples from your past roles that demonstrate your expertise in Information Security and Data Protection. Highlight situations where you've successfully implemented security measures or managed data protection compliance.
✨Engage with AI Governance
Since AI is a hot topic, be prepared to discuss your understanding of emerging regulations like the EU AI Act. Share your thoughts on how these regulations can be practically applied within the company’s framework.
✨Ask Insightful Questions
Prepare questions that show your interest in the company's culture and approach to security. For instance, ask about their current challenges in data protection or how they foster collaboration between teams on security initiatives.