At a Glance
- Tasks: Manage information security incidents and drive continuous improvement across the organisation.
- Company: Join TwinStream, a leader in technical excellence and exceptional service.
- Benefits: Enjoy a competitive salary, private healthcare, flexible working, and generous holidays.
- Why this job: Make a real impact on security culture while working remotely in a dynamic environment.
- Qualifications: Proven experience in information security management and strong communication skills.
- Other info: Be part of an inclusive team that values diversity and offers excellent career growth.
The predicted salary is between 60000 - 80000 £ per year.
TwinStream was formed to consolidate our founders’ collective expertise and experience into one business, providing technical excellence and exceptional service to our clients. We have teams working both on-site with clients and remotely from home.
We’re looking for a hands-on, mid-to-senior information security practitioner who enjoys getting involved in the practical aspects of security. This role focuses on delivery, updating and writing policies, delivering training, and providing clear, pragmatic security advice across TwinStream. You’ll work independently, owning day-to-day information security activities without line management responsibilities. While we may occasionally bring in specialist support, you’ll be trusted to drive the work forward. This role concentrates on governance, risk, and compliance rather than IT operations. You won’t be configuring systems or running security tools—our IT teams handle that—allowing you to focus on enabling secure delivery and building a positive security culture.
Key Responsibilities
- Manage information security incidents and security risks across the organisation
- Own and maintain the Information Security Management System (ISMS), including creating and updating policies, procedures, and guidance
- Ensure adherence to information security policies and standards
- Drive a programme of continuous information security improvement
- Embed and promote a positive security culture across the business
- Ensure compliance with relevant certifications and regulatory requirements, including ISO 27001, Cyber Essentials Plus, UK GDPR/Data Protection Act, and MOD CSM v3 and v4
- Plan and coordinate security audits (internal, external, customer, and penetration testing), managing evidence collection and tracking findings through to resolution
- Provide information security expertise to projects, services, and business initiatives, including developing or contributing to Security Management Plans
- Design and deliver information security training and awareness activities
- Contribute to Business Continuity, Disaster Recovery, and internal audit activities
- Act as the primary point of contact for information security across TwinStream
Key Skills
- Proven experience in an Information Security Manager or similar role, including security incident management, risk management, security governance, and providing practical information security guidance
- Experience embedding information security into the design, development, and delivery of software-based solutions, including secure development practices, cloud services, and integrated platforms
- Strong understanding of recognised information security frameworks and certifications, particularly ISO 27001 and Cyber Essentials Plus
- Good knowledge of relevant UK legislation and regulatory requirements
- Comfortable working remotely (within the UK) in a flexible, fast-paced environment
- Strong organisational skills with the ability to manage priorities effectively
- Excellent written and verbal communication skills, with the ability to tailor messaging for different audiences
- Relevant professional certifications such as CISSP (highly desirable), CISM, or ISO 27001 Lead Implementer/Auditor
- Ability and willingness to undergo UK Security Clearance (minimum SC level)
Desired Skills
- Experience in information security roles within the UK defence sector, national security sector, or other highly regulated industries
- Existing UK Security Clearance (SC)
- Familiarity with MOD security frameworks, including CSM v3 and v4, IPSA, and FSC
- Experience using the Atlassian suite, particularly Jira
- Demonstrated experience in managing security incidents and leading incident response teams
- Ability to present and be the focal point for security matters across the business
- Experience in supporting the security controller role in various security frameworks
- Understanding of insider threat operational and governance requirements, and experience in applying them
Benefits and Perks
- Pension Plan: 8% employer contribution
- Private Medical Healthcare: comprehensive private medical care including dental and optical for you and your family
- Learning and Development: autonomous growth opportunities
- Flexible Working: balanced work-life integration
- Electric Vehicle Scheme: salary sacrifice scheme for an EV lease
- Holidays: 28 days of annual leave plus bank holidays
- Team Events: quarterly meetings plus Christmas and summer parties
- Additional Benefits: life assurance and cycle-to-work scheme
To meet the security requirements of certain clients and industries we serve, any job offer will be contingent upon the successful completion of a security screening process. At TwinStream, we take pride in being an equal opportunity employer. We celebrate diversity and are committed to fostering an inclusive environment where all individuals are valued and respected. We welcome applications from qualified candidates regardless of race, religion, disability, age, sexual orientation, or gender.
Information Security Manager in Bristol employer: Twinstream
Contact Detail:
Twinstream Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Information Security Manager in Bristol
✨Tip Number 1
Network like a pro! Reach out to your connections in the information security field and let them know you're on the lookout for opportunities. A friendly chat can lead to insider info about job openings that aren't even advertised yet.
✨Tip Number 2
Get involved in online communities and forums related to information security. Share your knowledge, ask questions, and engage with others. This not only boosts your visibility but also helps you stay updated on industry trends and potential job leads.
✨Tip Number 3
Prepare for interviews by practising common questions specific to information security roles. Think about how you can showcase your experience with risk management and compliance. We want you to shine when it comes to discussing your hands-on skills!
✨Tip Number 4
Don't forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, we love seeing candidates who are genuinely interested in joining TwinStream and contributing to our positive security culture.
We think you need these skills to ace Information Security Manager in Bristol
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience in information security. Use keywords from the job description to show us you understand what we're looking for.
Showcase Your Skills: Don’t just list your qualifications; give us examples of how you've applied your skills in real-world situations. We want to see how you’ve managed security incidents or improved security policies in previous roles.
Be Clear and Concise: When writing your application, keep it straightforward. We appreciate clarity, so avoid jargon and get straight to the point about your relevant experience and achievements.
Apply Through Our Website: We encourage you to submit your application through our website. It’s the best way for us to receive your details and ensures you’re considered for the role without any hiccups!
How to prepare for a job interview at Twinstream
✨Know Your Stuff
Make sure you brush up on your knowledge of information security frameworks, especially ISO 27001 and Cyber Essentials Plus. Be ready to discuss how you've applied these in past roles, as well as any relevant legislation like the UK GDPR.
✨Showcase Your Practical Experience
Since this role is hands-on, prepare examples of how you've managed security incidents or risks in previous positions. Highlight your experience in creating and updating policies, and how you've embedded security into software development processes.
✨Communicate Clearly
You'll need to tailor your communication for different audiences, so practice explaining complex security concepts in simple terms. Think about how you can convey your ideas effectively during the interview, especially when discussing training and awareness activities.
✨Demonstrate Your Organisational Skills
This role requires strong organisational skills, so be prepared to discuss how you manage priorities and handle multiple tasks. Share specific examples of how you've successfully coordinated security audits or managed compliance with various standards.