Information Security & Data Protection Manager

Information Security & Data Protection Manager

Full-Time 60000 - 85000 £ / year (est.) Home office (partial)
The Focusrite Group

At a Glance

  • Tasks: Lead our Information Security and Data Protection programmes, ensuring compliance and governance.
  • Company: Join a dynamic tech company focused on innovation and inclusivity.
  • Benefits: Enjoy flexible working, private healthcare, and exciting company events.
  • Other info: Great opportunities for personal development and a supportive work culture.
  • Why this job: Make a real impact in security and privacy while growing your career.
  • Qualifications: Experience in Information Security and a passion for learning new skills.

The predicted salary is between 60000 - 85000 £ per year.

We're looking for an Information Security Compliance Specialist to take ownership of our Information Security, Data Protection, and AI Governance programmes across the Focusrite Group. You will be the operational owner of our Information Security and Data Protection (ISDP) framework informed by ISO 27001 (ISMS), ISO 27701 (PIMS), Cyber Essentials and NIST CSF keeping us aligned to those standards and ready for certification and audit.

Working alongside development, IT, and business teams, you will advise on security and privacy requirements for new and changing systems, ensuring appropriate controls are designed in, evidenced, and verified after implementation. You will also own the Group's response to emerging risks in AI, translating evolving regulation (EU AI Act, UK AI principles, ICO guidance) into practical governance.

About you

Several years' experience in Information Security and Data Protection, with a good understanding of IT systems, web operations, cloud platforms, and secure coding practices (including OWASP). Comfortable engaging at all levels of the organisation and externally, with the gravitas to influence security and privacy outcomes and reduce the impact of change. The position requires providing support and advice to all parts of the Group on Information Security and Data Protection.

  • Information Security Systems Framework & advisory: own the Information Security and Data Protection Framework and its documentation, and advise IT, development, and business teams on security requirements.
  • Tools & supplier assurance: run the Business Approved Tools process (including assessment of AI tools, vendors, and use cases), own designated Information Security tools, and conduct supplier audit assessments.
  • Certification & standards: own certification readiness for Cyber Essentials and lead new certification efforts as the business requires.
  • Threats, incidents & testing: monitor cyber threats and translate them for the business, own the incident management process (including phishing response and simulation exercises), and manage vulnerability scans and penetration testing (including external Red/Purple/Blue Team engagements).
  • Risk & resilience: conduct risk assessments across products, systems, and processes; own the Information Security and Data Protection risk register, contributing to the Group Risk Management process; and maintain and test the Business Continuity Plan (BCP).
  • AI Governance: own the AI Governance framework, AI system inventory, and alignment with ISO 42001, NIST AI RMF, and the EU AI Act where appropriate.
  • Data Protection compliance: primarily UK GDPR and Data Protection Act, EU GDPR, and US state privacy laws (including CCPA/CPRA).
  • Data subject rights & assessments: handle Data Subject Rights requests (Subject Access, erasure, rectification, restriction, objection, portability, and rights relating to automated decision-making) and run Data Protection Impact Assessments (DPIAs).
  • Records & registers: maintain the Records of Processing Activities (RoPA) under Article 30 for controller and processor activities, the lawful basis register, consent records, and Legitimate Interest Assessments (LIAs).
  • Notices, cookies & marketing: operate Privacy Notices and Cookie Tools (OneTrust), and advise on PECR and e-privacy compliance including direct marketing and electronic communications.
  • Privacy by Design & training: help product managers and developers embed Privacy by Design, and design and deliver Data Protection training and awareness across the Group.
  • Retention & breach management: own the retention schedule and deletion/anonymisation processes, and own personal data breach handling (including detection triage, 72‑hour ICO/EU supervisory authority notification, data subject notification where required, and the breach register).
  • Third parties & international transfers: manage processor and sub‑processor governance (Article 28 due diligence, Data Processing Agreements, processor register) and international data transfers (SCCs, the UK IDTA/Addendum, and Transfer Risk Assessments).
  • Change Management: review and provide security and data protection sign‑off on changes to systems, products, and processes; participate in the Change Advisory Board (CAB) and ensure security and privacy risks are assessed before changes are approved; own change management procedures relating to Information Security and Data Protection, ensuring evidence is captured for audit; ensure security and privacy requirements are embedded in the SDLC and release processes, working with development and operational teams; track and report on the security impact of significant business, technology, and organisational change initiatives.
  • Compliance: generate monthly compliance and activity reports and other reports as required by senior management.
  • Internal Audit: reviewing Financial System compliance activities; performing Internal Information Security Audits; performing Internal Data Protection Audits.
  • External audit: be the key contact for any IT / Data Protection related audits by external bodies, ensuring requested data is supplied, complete, and accurate; take ownership of any related audit issues; generate audit support documents.

You will be expected to keep up to date with developments in the security, privacy, and AI regulatory landscape, translating these into practical actions for the Group. We understand that not all candidates will have in depth experience of all these elements, so we welcome applications from candidates who meet most of the criteria and have a desire to learn the rest.

Benefits

Flexible/hybrid working, company pension, life insurance, private healthcare, Health Cash Plan, enhanced maternity and paternity pay, employee purchase scheme, group bonus scheme, company music events, offsite company parties and free lunch in the canteen. We arrange company training sessions and encourage personal development. The Focusrite Group is dedicated to building a great place to work and as an equal opportunity employer we are committed to Diversity and Inclusion.

Information Security & Data Protection Manager employer: The Focusrite Group

At Focusrite Group, we pride ourselves on being an exceptional employer, offering a dynamic work culture that champions flexibility and personal development. With a strong commitment to diversity and inclusion, our employees benefit from a comprehensive package including private healthcare, enhanced parental leave, and opportunities for continuous training, all while working in a collaborative environment that values innovation and security excellence.

The Focusrite Group

Contact Details:

The Focusrite Group Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Security & Data Protection Manager

Tip Number 1

Network like a pro! Reach out to folks in the industry on LinkedIn or at events. A friendly chat can open doors that a CV just can't.

Tip Number 2

Prepare for interviews by researching the company and its culture. Tailor your answers to show how you fit into their world, especially around security and data protection.

Tip Number 3

Practice makes perfect! Do mock interviews with friends or use online platforms. The more comfortable you are, the better you'll perform when it counts.

Tip Number 4

Don't forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who take that extra step!

We think you need these skills to ace Information Security & Data Protection Manager

Information Security Management
Data Protection Compliance
ISO 27001
ISO 27701
Cyber Essentials
NIST CSF
Risk Assessment

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Information Security & Data Protection Manager role. Highlight relevant experience and skills that align with the job description, especially around ISO standards and data protection compliance.

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how your background makes you a great fit for our team. Don’t forget to mention any ongoing training or certifications!

Showcase Your Achievements:When detailing your experience, focus on specific achievements rather than just duties. Use metrics where possible to demonstrate your impact in previous roles, especially in areas like risk management and compliance.

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands and shows us you’re serious about joining StudySmarter!

How to prepare for a job interview at The Focusrite Group

Know Your Standards

Familiarise yourself with ISO 27001, ISO 27701, and Cyber Essentials. Be ready to discuss how these frameworks apply to the role and share examples of how you've implemented similar standards in past positions.

Showcase Your Technical Savvy

Brush up on your knowledge of IT systems, cloud platforms, and secure coding practices like OWASP. Prepare to explain how you’ve engaged with these technologies and how they relate to information security and data protection.

Prepare for Scenario Questions

Expect questions about handling data breaches or managing risks. Think of specific situations where you successfully navigated challenges in information security and be ready to share your thought process and outcomes.

Demonstrate Your Communication Skills

This role requires engaging with various teams. Practice articulating complex security concepts in simple terms. Be prepared to discuss how you’ve influenced security outcomes in previous roles and how you can do the same here.