Information Security and Integrity Manager in Birmingham

Information Security and Integrity Manager in Birmingham

Birmingham Full-Time 50000 - 60000 £ / year (est.) No working from home possible
West Midlands Combined Authority

At a Glance

  • Tasks: Lead the development of information security strategies and ensure data integrity across the organisation.
  • Company: Join the West Midlands Combined Authority, a forward-thinking organisation committed to innovation.
  • Benefits: Enjoy 28 days annual leave, a generous pension scheme, and discounts on shopping and gym memberships.
  • Other info: Flexible working arrangements available; we value diversity and encourage all to apply.
  • Why this job: Make a real impact on regional transformation while shaping a culture of security and accountability.
  • Qualifications: Experience in information security governance and risk management is essential.

The predicted salary is between 50000 - 60000 £ per year.

We are seeking an experienced and forward-thinking Information Security & Integrity Manager for a period of 12 months, to play a critical role in strengthening how the West Midlands Combined Authority (WMCA) protects, governs, and assures the use of its information assets and data. This is a high-profile opportunity to lead the development and continuous improvement of the WMCA’s Information Security Management System (ISMS), ensuring the organisation has clear, evidence-based assurance over how information is handled, secured, governed, and retained.

Working closely with senior leadership, audit, cyber security, data, and technology teams, you will help shape a robust security and governance framework that supports organisational transformation while ensuring compliance with ISO standards, UK GDPR, and best practice. As the WMCA continues to evolve through ambitious regional programmes and increasingly complex digital services, this role will be central to embedding a culture of security, integrity, and accountability across the organisation. You will provide trusted assurance to leadership on information security risks, controls, compliance, and data integrity, while driving continuous improvement and ensuring security is embedded into operational and strategic decision-making.

What you will be doing:

  • Establish and maintain the organisation’s Cyber and Resilience Strategy
  • Translate organisational needs into a coherent data security and lifecycle governance model
  • Define security requirements for Business Continuity and Disaster Recovery
  • Work with data owners and engineering teams to embed a culture of data literacy
  • Ensure CAB/change includes security readiness criteria
  • Maintain evidence packs and ISO/QMS artefacts with the Business Management Unit
  • Maintain visibility of organisational data assets through evidence-based mapping
  • Implement data quality assurance checkpoints in collaboration with Data Engineering
  • Build strong working relationships across Technology and Insight service areas, Corporate PMO, Service Desk, suppliers, and operational teams and technical teams
  • Act as a coordinator for the WMCA’s formal liaison with national and regional authorities
  • Drive continuous improvement in operational processes

What’s essential:

  • Running an ISMS and aligning to ISO 27001 in a complex, multi-supplier environment
  • Establishing policies, MSBs, risk registers, DPIAs, and supplier security
  • CISSP/CISM or ISO 27001 Lead Implementer/Lead Auditor (or equivalent)
  • Training or certification in data governance, data quality management, or metadata management (e.g., DCAM, CDMP, DAMA DMBoK-aligned training)
  • Experience of working in Agile, Lean or DevOps-aligned delivery practices (e.g., Kanban, flow metrics, sprint planning, CI/CD awareness)
  • Experience of working with CABs, release cycles or readiness reviews
  • Experience assuring or governing data pipelines, data flows, integrations or data processing environments
  • Experience implementing or overseeing data lifecycle governance, including classification, retention, minimisation and defensible deletion
  • Experience working with Microsoft Purview, M365 compliance tooling or equivalent enterprise governance platforms
  • Strong knowledge of UK GDPR/DPA 2018, ISO 27001, NCSC guidance
  • Strong risk and assurance capability

Location: The location for this role is 16 Summer Lane with at least 2 days a week spent in the office.

How to apply:

  • Create your Careers Account. Register with your name, email address, and a password.
  • Build your Profile. Upload your CV to help populate your career and education details.
  • Write your Supporting Statement. Make sure to address each of the required essential criteria.
  • Submit your application. Do one final check and once complete, click submit.

Anonymised Applications: Your uploaded CV won’t be visible after submission. Our process is anonymised, and only the information in your profile is used for shortlisting. Be thorough in each section. It’s your chance to showcase your skills and experience.

Using Artificial Intelligence (AI): We cannot stop anyone from using AI to help write application content. Used right, it can be a great tool. If you choose to use AI, then use it as a helper rather than relying on it wholly to write your application. Applications that rely too heavily on AI may be rejected during shortlisting.

Reasonable adjustments: If you have an accessibility need, disability, or condition that means you might require changes to the application or recruitment process, please get in touch with our Recruitment Team.

Salary and benefits: We advertise salary ranges, with new appointments typically starting at the lowest salary point. In exceptional cases, the salary point may be adjusted to secure the best candidate. This approach allows for potential year-on-year salary increases, offering progression and appropriate rewards to employees. Requests for salaries above the maximum advertised range will not be considered.

Benefits include:

  • Local Government Pension Scheme (one of the most generous pension schemes in the UK).
  • Shared Cost Additional Voluntary Contribution scheme.
  • 28 days paid annual leave (with an option to purchase more) + Statutory days.
  • Discounted gym membership, will writing, and mortgage advice.
  • An option to buy a bicycle, including e-bikes and adapted pedal cycles, at a discounted rate.
  • 3 days of paid leave each year to volunteer.
  • Interest-free financing through SmartTech to buy the latest technology.
  • Discounted shopping with over 2,000 big-name retailers.
  • Costco membership through the WMCA.
  • Boundless unlocks unlimited entry to top-rated UK attractions.
  • Eye Care Scheme, offering a free eye test and a financial contribution towards your glasses.

Our Values and Behaviours:

  • Collaborative – We work as one organisation, building trust, connection and shared purpose across teams, partners and customers to create the biggest impact for our region.
  • Driven – Focused on impact - leading with clarity, care and courage to deliver meaningful results for the West Midlands.
  • Inclusive – Every voice matters - we create belonging, fairness and psychological safety so everyone can thrive.
  • Innovative – We think future and act smarter - embracing curiosity, creativity and continuous improvement to shape the future.

Creating an inclusive workplace: WMCA holds diversity accreditations, such as the RACE Code Quality Mark, Armed Forces Covenant (Gold status) and has been recognised as one of the Inclusive Top 50 Employers and The Times Top 50 Employers for Women. We’re a Disability Confident Employer with ‘Leader’ status, committed to interviewing applicants with disabilities who meet all the essential role criteria. We are also proud to be a Ban the Box employer, which means we do not ask about criminal convictions at the initial application stage.

Right to Work in the UK: Proof of Right to Work in the UK will be required for all applicants in accordance with UK Home Office requirements, before any employment offer can be confirmed.

Information Security and Integrity Manager in Birmingham employer: West Midlands Combined Authority

The West Midlands Combined Authority (WMCA) is an exceptional employer, offering a dynamic work environment that prioritises collaboration, innovation, and inclusivity. With a strong commitment to employee growth, WMCA provides extensive benefits including a generous pension scheme, paid volunteer days, and opportunities for professional development, all while fostering a culture that values every voice and encourages meaningful contributions to the region's transformation. Located in the heart of Birmingham, employees enjoy a vibrant city atmosphere with access to numerous amenities and attractions.

West Midlands Combined Authority

Contact Details:

West Midlands Combined Authority Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Security and Integrity Manager in Birmingham

Tip Number 1

Network like a pro! Reach out to folks in your industry on LinkedIn or at local events. A friendly chat can lead to opportunities you might not find on job boards.

Tip Number 2

Prepare for interviews by researching the company and its culture. Tailor your answers to show how your skills align with their needs, especially around information security and governance.

Tip Number 3

Practice makes perfect! Do mock interviews with friends or use online platforms. The more comfortable you are speaking about your experience, the better you'll perform.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you’re serious about joining the team at WMCA.

We think you need these skills to ace Information Security and Integrity Manager in Birmingham

Information Security Management System (ISMS)
ISO 27001
Data Governance
Risk Management
Data Assurance
Cyber Security
UK GDPR

Some tips for your application 🫡

Craft a Compelling Supporting Statement:Your supporting statement is your chance to shine! Make sure you address each of the essential criteria mentioned in the job description. Use specific examples from your experience to demonstrate how you meet these requirements and show us why you're the perfect fit for the role.

Tailor Your CV:Don’t just send a generic CV! Tailor it to highlight your relevant skills and experiences that align with the Information Security and Integrity Manager role. We want to see how your background fits into our needs, so make it easy for us to connect the dots.

Be Thorough and Clear:Take your time to fill out every section of the application. Clarity is key! Ensure your writing is concise and free of jargon, making it easy for us to understand your qualifications and experiences. A well-structured application speaks volumes!

Apply Through Our Website:We encourage you to apply through our website for a smooth application process. It’s straightforward and ensures your application gets to the right place. Plus, you’ll be able to create a profile that helps us get to know you better!

How to prepare for a job interview at West Midlands Combined Authority

Know Your Stuff

Make sure you’re well-versed in information security governance, risk management, and data assurance. Brush up on ISO 27001 and UK GDPR regulations, as these will likely come up during your interview. Being able to discuss these topics confidently will show that you’re the right fit for the role.

Showcase Your Experience

Prepare specific examples from your past work that demonstrate your ability to lead improvements in information security. Think about times when you’ve successfully implemented policies or managed risks in a complex environment. This will help you illustrate your expertise and how it aligns with the WMCA’s needs.

Build Relationships

Since this role involves working closely with various teams, be ready to discuss how you’ve built strong working relationships in previous positions. Highlight your collaborative skills and how you’ve influenced senior leadership in the past. This will show that you can effectively communicate and work across departments.

Ask Insightful Questions

Prepare thoughtful questions about the WMCA’s current information security challenges and future goals. This not only shows your interest in the role but also demonstrates your proactive approach to understanding the organisation's needs. It’s a great way to engage with the interviewers and leave a lasting impression.