Information Security & GRC Specialist in Manchester

Information Security & GRC Specialist in Manchester

Manchester Full-Time 40500 - 49500 £ / year (est.) Home office (partial)
V

At a Glance

  • Tasks: Own and improve our Information Security Management System while ensuring compliance and audit readiness.
  • Company: Join Vix Technology, a global leader in transport and payment solutions.
  • Benefits: Hybrid work model, competitive salary, and opportunities for professional growth.
  • Other info: Dynamic international team with a focus on continuous improvement and collaboration.
  • Why this job: Make a real-world impact on security for public transport systems used by millions.
  • Qualifications: Experience with ISO 27001 and strong communication skills are essential.

The predicted salary is between 40500 - 49500 £ per year.

At Vix Technology, we build technology that helps millions of people move around cities every day. Our fare collection, payments and transit solutions operate across more than 200 cities and regions worldwide. With technology supporting critical transport and payment services, security, resilience and trust are fundamental to what we do.

We're looking for an Information Security & GRC Specialist to join our Manchester team. This is a great opportunity for someone with a few years' experience in information security, GRC, technology risk or audit who's ready to take more ownership and broaden their experience within a global technology business.

The Role

You'll take day-to-day ownership of our Information Security Management System (ISMS), helping ensure Vix remains compliant, audit-ready and continually improving. Working across Security, Engineering, Technology and the wider business, you'll coordinate ISO 27001 activities, prepare for internal and external audits, manage evidence and help drive remediation actions through to completion. You'll also gain exposure to PCI DSS and wider security frameworks, supporting customer assessments, regulatory requirements and security assurance activities.

This isn't a role where you'll simply identify gaps and write reports. We want someone who can build relationships across the business, translate security requirements into practical actions and help get things fixed.

What You'll Be Doing

  • Own the day-to-day coordination and continuous improvement of our ISMS.
  • Support ISO 27001 certification, surveillance and internal audits.
  • Coordinate audit evidence and work with stakeholders to close findings and remediation actions.
  • Maintain security policies, procedures, controls and compliance documentation.
  • Support PCI DSS and wider security compliance and assurance activities.
  • Track and report on compliance status, risks, upcoming audits and outstanding actions.
  • Help develop our approach across ISO 27017, ISO 27018 and ISO 22301.

About You

You'll have practical experience working with ISO 27001 and an ISMS, ideally including audit preparation, evidence management and remediation. You'll understand information security governance, risk and compliance and be confident working with both technical and non-technical teams. You'll be organised, pragmatic and comfortable taking ownership. Just as importantly, you'll be able to explain security requirements clearly and build relationships with the people responsible for implementing them.

Experience with PCI DSS, security audits, ISO 27017/27018/22301 or working within a regulated technology environment would be a bonus. Qualifications such as ISO 27001 Lead Implementer/Auditor, CISA, CRISC or CISSP are welcome, but they're not essential.

Why Vix?

You'll work on security that has genuine real-world impact, protecting technology behind public transport and payment systems used by millions of passengers. You'll join an international security organisation, work with colleagues around the world and build your experience across GRC, ISO 27001, PCI DSS, risk, audit and assurance. If you're looking for a role where you can take ownership, continue developing and make a visible difference to how security is managed, we'd love to hear from you.

Location: This is a full-time, hybrid role based in our Manchester office. Candidates must already have unrestricted rights to work in the UK; unfortunately, sponsorship isn't available for this position.

Information Security & GRC Specialist in Manchester employer: Vix Technology

VIX Technology is an exceptional employer that fosters a collaborative and innovative work culture, perfect for those passionate about shaping the future of public transport technology. Located in the UK, we offer competitive benefits, opportunities for professional growth, and a chance to work on cutting-edge projects that make a real difference in people's lives. Join us to be part of a dynamic team where your contributions are valued and your career can thrive.

V

Contact Details:

Vix Technology Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Security & GRC Specialist in Manchester

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Vix Technology, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Vix Technology

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Vix Technology. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Information Security & GRC Specialist in Manchester

Information Security Management System (ISMS)
ISO 27001
Audit Preparation
Evidence Management
Remediation Actions
PCI DSS
Security Compliance

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Vix Technology insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Vix Technology that you’re committed to staying ahead in the game.

How to prepare for a job interview at Vix Technology

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Vix Technology to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Vix Technology.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.