At a Glance
- Tasks: Lead a technical security team and shape our security strategy.
- Company: Join Which?, the UK's consumer champion, promoting fairness and safety.
- Benefits: Enjoy 28 days holiday, hybrid working, and a fantastic pension scheme.
- Other info: Flexible working options and a commitment to diversity and inclusion.
- Why this job: Make a real impact on digital security while developing your career.
- Qualifications: Strong knowledge of cloud security and relevant certifications required.
The predicted salary is between 73000 - 80000 £ per year.
This role offers a competitive salary, hybrid working (London with 2 days in the office, Thursdays mandatory), 28 days holiday a year plus Bank Holidays and a fantastic pension scheme offering 6% in year one and 11% after this. Salary £73,000 - £80,000 per annum.
About the role
Are you a technical security expert who thrives at the intersection of strategy and hands‑on execution? We are looking for a Cyber Security Manager to lead our operational technical security domain. You will be the go‑to authority for infrastructure and cloud security, managing a focused team and partnering with the wider business to ensure our digital ecosystem remains resilient against emerging threats. In this role, you won’t just be monitoring dashboards; you will be shaping our security strategy, driving vulnerability management, and embedding a “security by design” culture across our product development life cycle. This is a pivotal role where you will have direct influence over our security posture. You’ll report directly to the Head of Information Security & Technology Risk, giving you a high‑visibility platform to drive change.
Key responsibilities include:
- Technical Leadership: Manage and mentor a small technical security team (currently 1 direct report), overseeing all technical aspects of security from Infrastructure to DevSecOps.
- Cloud & Infrastructure Custodian: Lead security initiatives across AWS, Google Workspace, Microsoft, and Salesforce. You will ensure our cloud environments and architecture meet the highest standards.
- Vulnerability Management: Serve as the primary point of contact for penetration testing, vulnerability and patch management. You’ll coordinate with technical teams to ensure vulnerabilities are identified, negotiated, and remediated swiftly.
- Strategic Partnership: Work hand‑in‑hand with our Managed Service Provider (MSP) for 24/7 monitoring, incident response, and threat resolution.
- Risk & Evolution: Conduct cyber risk evaluations for all new technologies and service changes, ensuring security scales with our innovation.
- Tool Ownership: Act as the internal expert and administrator for our Varonis and Wiz security platforms.
- Product Security: Partner directly with a specific Product Area to provide expert advice during all stages of development.
About you
- Expertise: Strong technical knowledge of AWS, Microsoft 365, Azure, and Salesforce (or a strong willingness to master the latter).
- Certifications: CISM, CISSP, or equivalent professional qualifications.
- Strategic Mindset: Proven experience in security strategy, incident management, and infrastructure security.
- Communication: The ability to translate complex technical risks into “plain English” for non‑technical stakeholders. You are friendly, approachable, and a natural collaborator.
- Drive: You are a self‑starter who can manage your own workload and lead a team with minimal supervision.
- Practical experience with PCI DSS compliance.
- Background in Data Protection/Management.
Interview process:
- 30‑minute screening call with members of the Security Team via MS Teams.
- 60‑90 minute competency‑based and scenario‑based interview via MS Teams.
Benefits:
- 35 hour working week.
- Generous 28 days holiday a year plus bank holidays and the option to buy additional holiday days.
- Excellent pension scheme – when you pay in 3%, which pays in 6% (rising to 11% after one year of service).
- Annual Award (depending on employee and company performance).
- Healthcare insurance & private medical insurance and opportunity to participate in Vitality rewards programme (at 6 months).
- A discretionary death in service benefit provision equivalent to six times your annual salary.
- Free access to Which member content and free access to Which money & legal helplines.
- Free wills for all Which employees, plus partners of employees can make their will at cost price.
- Discount site Pluxee which offers large off everyday shopping and holidays.
- Work from (almost) anywhere for 4 weeks of the year policy.
- A great work‑life balance (all our roles are now hybrid), offering flexible working options e.g. part time or job shares where possible.
About Which? Which? is the UK's consumer champion, here to make life simpler, fairer and safer for everyone. We welcome applications from everyone, because we value diversity, and are committed to maintaining an inclusive culture where all can thrive and reach their full potential—because diverse perspectives help us better understand and positively impact consumers.
Cyber Security Manager employer: Which?
Which? is an exceptional employer that prioritises employee well-being and professional growth, offering a competitive salary, generous holiday allowance, and a robust pension scheme. With a hybrid working model and a strong commitment to inclusivity, employees are encouraged to collaborate and innovate within a supportive environment, making it an ideal place for those looking to make a meaningful impact in user research while enjoying a healthy work-life balance.
StudySmarter Expert Advice🤫
We think this is how you could land Cyber Security Manager
✨Tip Number 1
Get to know the company inside out! Research their values, recent projects, and any news related to their security initiatives. This will help you tailor your conversations during interviews and show that you're genuinely interested in being part of their team.
✨Tip Number 2
Network like a pro! Connect with current employees on LinkedIn or attend industry events. Having someone on the inside can give you valuable insights and even a referral, which can significantly boost your chances of landing that Cyber Security Manager role.
✨Tip Number 3
Prepare for those tricky interview questions! Think about how you would handle specific scenarios related to vulnerability management or incident response. Practising your responses will help you feel more confident and articulate during the actual interview.
✨Tip Number 4
Don’t forget to showcase your soft skills! As a Cyber Security Manager, you'll need to communicate complex ideas clearly. Be ready to demonstrate your ability to collaborate with non-technical stakeholders and lead your team effectively. Remember, we want to see the real you!
We think you need these skills to ace Cyber Security Manager
Some tips for your application 🫡
Be Yourself:When you're putting together your CV and statement of suitability, make sure it truly reflects who you are. We want to hear your voice and experiences, so don’t hold back!
Tailor Your Application:Take a good look at the job description and highlight how your skills and experiences align with what we're looking for. This shows us that you understand the role and are genuinely interested in joining our team.
Showcase Your Expertise:As a Cyber Security Manager, we’re keen to see your technical knowledge. Make sure to include relevant certifications and practical experience that demonstrate your capabilities in security strategy and incident management.
Apply Through Our Website:Remember, we only accept applications through our careers site. So, head over there to submit your application and ensure you’re considered for this exciting opportunity!
How to prepare for a job interview at Which?
✨Know Your Stuff
Make sure you brush up on your technical knowledge of AWS, Microsoft 365, Azure, and Salesforce. Be ready to discuss how you've applied this knowledge in past roles, especially in relation to security strategy and incident management.
✨Showcase Your Leadership Skills
As a Cyber Security Manager, you'll be leading a team. Prepare examples of how you've managed or mentored others in the past. Highlight your ability to translate complex technical risks into plain English for non-technical stakeholders.
✨Prepare for Scenario Questions
Expect competency-based and scenario-based questions during the interview. Think about real-life situations where you've had to manage vulnerabilities or lead security initiatives, and be ready to explain your thought process and outcomes.
✨Emphasise Your Strategic Mindset
This role requires a strategic approach to security. Be prepared to discuss how you've conducted cyber risk evaluations and how you plan to embed a 'security by design' culture in product development. Show them you're not just a doer, but a thinker!