Information Security & Data Protection Manager

Information Security & Data Protection Manager

Full-Time 60000 - 85000 £ / year (est.) Home office (partial)
W

At a Glance

  • Tasks: Lead our Information Security and Data Protection initiatives while ensuring compliance with industry standards.
  • Company: Join Focusrite, a leading music technology company with a vibrant culture.
  • Benefits: Enjoy flexible working, private healthcare, and opportunities for personal development.
  • Other info: Be part of a diverse team dedicated to innovation and sustainability.
  • Why this job: Make a real impact in the exciting world of music technology and data protection.
  • Qualifications: Experience in Information Security and Data Protection, with a passion for learning.

The predicted salary is between 60000 - 85000 £ per year.

Based: Remote (UK)/High Wycombe/London (N7)/Hybrid

Term: Permanent, Full time

Reporting to: Chief Information Officer (CIO)

Salary: £60000 - £85000 pa + excellent benefits

The Role: We're looking for an Information Security Compliance Specialist to take ownership of our Information Security, Data Protection, and AI Governance programmes across the Focusrite Group. You will be the operational owner of our Information Security and Data Protection (ISDP) framework informed by ISO 27001 (ISMS), ISO 27701 (PIMS), Cyber Essentials and NIST CSF keeping us aligned to those standards and ready for certification and audit. Working alongside development, IT, and business teams, you will advise on security and privacy requirements for new and changing systems, ensuring appropriate controls are designed in, evidenced, and verified after implementation. You will also own the Group's response to emerging risks in AI, translating evolving regulation (EU AI Act, UK AI principles, ICO guidance) into practical governance.

About you: Several years' experience in Information Security and Data Protection, with a good understanding of IT systems, web operations, cloud platforms, and secure coding practices (including OWASP). Comfortable engaging at all levels of the organisation and externally, with the gravitas to influence security and privacy outcomes and reduce the impact of change. The position requires providing support and advice to all parts of the Group on Information Security and Data Protection.

You will be responsible for:

  • Information Security Systems:
    • Framework & advisory: own the Information Security and Data Protection Framework and its documentation, and advise IT, development, and business teams on security requirements
    • Tools & supplier assurance: run the Business Approved Tools process (including assessment of AI tools, vendors, and use cases), own designated Information Security tools, and conduct supplier audit assessments
    • Certification & standards: own certification readiness for Cyber Essentials and lead new certification efforts as the business requires
    • Threats, incidents & testing: monitor cyber threats and translate them for the business, own the incident management process (including phishing response and simulation exercises), and manage vulnerability scans and penetration testing (including external Red/Purple/Blue Team engagements)
    • Risk & resilience: conduct risk assessments across products, systems, and processes; own the Information Security and Data Protection risk register, contributing to the Group Risk Management process; and maintain and test the Business Continuity Plan (BCP)
    • AI Governance: own the AI Governance framework, AI system inventory, and alignment with ISO 42001, NIST AI RMF, and the EU AI Act where appropriate
  • Data Protection compliance:
    • Data subject rights & assessments: handle Data Subject Rights requests (Subject Access, erasure, rectification, restriction, objection, portability, and rights relating to automated decision-making) and run Data Protection Impact Assessments (DPIAs)
    • Records & registers: maintain the Records of Processing Activities (RoPA) under Article 30 for controller and processor activities, the lawful basis register, consent records, and Legitimate Interest Assessments (LIAs)
    • Notices, cookies & marketing: operate Privacy Notices and Cookie Tools (OneTrust), and advise on PECR and e-privacy compliance including direct marketing and electronic communications
    • Privacy by Design & training: help product managers and developers embed Privacy by Design, and design and deliver Data Protection training and awareness across the Group
    • Retention & breach management: own the retention schedule and deletion/anonymisation processes, and own personal data breach handling (including detection triage, 72-hour ICO/EU supervisory authority notification, data subject notification where required, and the breach register)
    • Third parties & international transfers: manage processor and sub-processor governance (Article 28 due diligence, Data Processing Agreements, processor register) and international data transfers (SCCs, the UK IDTA/Addendum, and Transfer Risk Assessments)
  • Change Management:
    • Review and provide security and data protection sign-off on changes to systems, products, and processes
    • Participate in the Change Advisory Board (CAB) and ensure security and privacy risks are assessed before changes are approved
    • Own change management procedures relating to Information Security and Data Protection, ensuring evidence is captured for audit
    • Ensure security and privacy requirements are embedded in the SDLC and release processes, working with development and operational teams
    • Track and report on the security impact of significant business, technology, and organisational change initiatives
  • Compliance:
    • Generate monthly compliance and activity reports and other reports as required by senior management
    • Internal Audit:
      • Reviewing Financial System compliance activities
      • Performing Internal Information Security Audits
      • Performing Internal Data Protection Audits
    • External audit:
      • Be the key contact for any IT / Data Protection related audits by external bodies, ensuring requested data is supplied, complete, and accurate
      • Take ownership of any related audit issues
      • Generate audit support documents

    You will be expected to keep up to date with developments in the security, privacy, and AI regulatory landscape, translating these into practical actions for the Group. We understand that not all candidates will have in depth experience of all these elements, so we welcome applications from candidates who meet most of the criteria and have a desire to learn the rest. Please provide details in your covering letter of additional training requirements / certifications in progress etc.

    About Us: Focusrite plc is a global music and audio group that develops and markets music technology products. Used by audio professionals and amateur musicians alike, our solutions facilitate the high-quality production of recorded and live sound. Our audio technology brands stand together, seeking to enrich lives through music by removing barriers to creativity – ‘we make music easy to make’. The Focusrite Group trades under thirteen established and rapidly growing brands: Focusrite, Focusrite Pro, Novation, ADAM Audio, Sequential, Oberheim, Martin Audio, Optimal Audio, Ampify Music, Linea Research, Sonnox, OutBoard and TiMax. With a high-quality reputation and a rich heritage spanning decades, its brands are category leaders in the music-making industry. Music technology is an enriching space to work in and we enjoy a Group-wide open-door culture which encourages innovation. This culture, combined with a passion for the inspirational solutions we create, has led to the group winning numerous accolades, including six Queen's Awards, the AIM Company of the Year Award 2021 and regular appearances in 'The Sunday Times 100 Best Small Companies to Work For’. The Focusrite Group is dedicated to building a great place to work and as an equal opportunity employer we are committed to Diversity and Inclusion. The group mission is to cultivate an equitable culture, internally and externally, where all people feel they are welcome, safe and positively represented, because at Focusrite they truly are. Equally, we recognise the major impact that climate change is having on our world and work every day towards being industry leaders in a carbon neutral future.

    Benefits include flexible/hybrid working, company pension, life insurance, private healthcare, Health Cash Plan, enhanced Maternity and Paternity pay, employee purchase scheme, group bonus scheme, company music events, offsite company parties and free lunch in the canteen. We arrange company training sessions and encourage personal development.

Information Security & Data Protection Manager employer: Workable

At Focusrite, we pride ourselves on being an exceptional employer, offering a vibrant work culture that fosters creativity and innovation in the music technology industry. With flexible hybrid working options, comprehensive benefits including private healthcare and enhanced parental leave, and a strong commitment to employee growth through training and development opportunities, we ensure our team members feel valued and supported. Join us in a dynamic environment where your contributions directly impact our mission to make music easy to create, all while being part of a diverse and inclusive community.

W

Contact Details:

Workable Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Security & Data Protection Manager

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Workable, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Workable

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Workable. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Information Security & Data Protection Manager

Information Security Management
Data Protection Compliance
ISO 27001
ISO 27701
Cyber Essentials
NIST CSF
Risk Assessment

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Workable insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Workable that you’re committed to staying ahead in the game.

How to prepare for a job interview at Workable

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Workable to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Workable.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.