Information & Cyber Security Manager

Information & Cyber Security Manager

Full-Time 65000 - 78000 £ / year (est.) No working from home possible
The Works Stores Ltd

At a Glance

  • Tasks: Lead our information and cyber security programme to protect technology and data.
  • Company: Join The Works, a company that inspires creativity and learning.
  • Benefits: Enjoy 33 days holiday, 25% discount, and access to exclusive discounts.
  • Other info: Flexible working options and a supportive, inclusive culture await you.
  • Why this job: Make a real impact by safeguarding our systems and customer information.
  • Qualifications: Experience in information security leadership and strong knowledge of compliance frameworks.

The predicted salary is between 65000 - 78000 £ per year.

Location: Hybrid - 1 - 2 days at our Support Centre in Coleshill, Birmingham.

At The Works, we inspire reading, learning, creativity and play. As our Information & Cyber Security Manager, you'll play a vital role in protecting the technology, data and systems that keep our business running safely and securely.

Working closely with the Director of Technology Services, you'll lead our information and cyber security programme, helping to create a resilient, trusted and secure environment for colleagues and customers alike. Your responsibilities will include:

  • Delivering the enterprise-wide information security strategy aligned to business objectives and regulatory requirements.
  • Establishing and governing security frameworks and policies (e.g. ISO 27001, NIST, PCI DSS, Cyber Essentials Plus), ensuring ongoing compliance and audit readiness.
  • Leading security risk management, maintaining the risk register with clear ownership, mitigation plans, and effective tracking/reporting.
  • Owning the security programme roadmap and investment plan, prioritising initiatives to address risk, compliance, and business change.
  • Overseeing security operations and incident response, working with the outsourced SOC to ensure effective monitoring, escalation, and regulatory-compliant breach management.
  • Managing threat and vulnerability capabilities, including penetration testing, threat intelligence, and proactive threat hunting across the estate.
  • Owning data security and regulatory compliance, including DLP strategy, PCI environments, DPIAs, and partnership with the DPO on GDPR obligations.
  • Embedding security into architecture and technology, ensuring security-by-design across platforms, cloud environments, and change programmes.
  • Owning third-party security and supplier assurance, managing vendors and ensuring ongoing compliance, risk visibility, and performance against SLAs.
  • Building and leading a high-performing security function, driving team capability, stakeholder engagement, and a strong organisational security culture through awareness and training.

Skills/Behaviours That Will Set You Apart:

  • Demonstrable experience in information security leadership roles.
  • Strong working knowledge of GDPR, PCI DSS, ISO 27001, Cyber Essentials, and NIST Cybersecurity Framework.
  • Experience running vulnerability management programmes and interpreting threat intelligence.
  • Understanding of the retail-specific threat landscape and drive to keep abreast of threats.
  • Experience managing SOC providers and security vendors, including SLA governance and escalation management.
  • Hands-on or oversight experience with SIEM, SOAR, EDR/XDR, DLP, and vulnerability scanning tooling.
  • Strong stakeholder communication skills, including the ability to translate technical risk into business impact.

As a great leader, you’ll create an environment that’s more than just co-workers — it’s a team. Key leadership qualities include:

  • Aligning goals with values to connect your team’s goals to the company’s values and purpose.
  • Ensuring clear communication of goals, expectations, and roles.
  • Leading by example and demonstrating expected behaviours and attitudes.
  • Providing constructive feedback regularly and recognising achievements.
  • Empowering your team by delegating tasks and trusting them to handle them.
  • Addressing conflicts promptly and fostering an open environment for discussion.
  • Understanding and considering the feelings and perspectives of your team members.

Our PERKS really are ‘The Works’:

  • 25% Colleague Discount - Plus, exclusive Double Discount days!
  • MyWorks - Access exclusive online discounts across hundreds of retailers, holidays, utilities deals, tech and more.
  • Family Friendly Leave - Enhanced maternity, paternity and adoption pay.
  • Holiday – 33 days including bank holidays.
  • Holiday Purchase - Purchase an additional 5 days.
  • Can-Do Academy - Access to further training and development.
  • Stream - Claim early access to 50% of your wages as you earn them.
  • Share Scheme - Own a piece of The Works!
  • 24/7 support for you and your family through our Employee Assistance Programme.
  • Healthcare Cash Plan – To support your everyday healthcare costs.
  • And loads more! – Long Service Awards, pension, life assurance, Cycle to Work and optional charity giving.

Our Purpose is to inspire reading, learning, creativity and play. We are proud to have an inclusive culture where everyone truly feels able to be themselves. Our roles are open to all, including under-represented groups. We are open to discussions around working hours and flexible working.

Information & Cyber Security Manager employer: The Works Stores Ltd

The Works is an exceptional employer, recognised as the 10th Best Big Company to Work For in 2024, offering a vibrant work culture that inspires creativity and learning. With generous benefits including a 25% colleague discount, enhanced family leave, and access to the Can-Do Academy for professional development, employees are empowered to grow and thrive. Located in Coleshill, Birmingham, the hybrid working model fosters flexibility while ensuring meaningful engagement across teams, making it a truly rewarding place to work.

The Works Stores Ltd

Contact Details:

The Works Stores Ltd Recruitment Team

We think you need these skills to ace Information & Cyber Security Manager

Information Security Leadership
GDPR Compliance
PCI DSS Knowledge
ISO 27001 Familiarity
NIST Cybersecurity Framework Understanding
Vulnerability Management
Threat Intelligence Interpretation