IT Security Manager
Sanderson · Wiltshire, England, United Kingdom
Apply & track with Apply EdgeIT Security ManagerSalary: £74,466 – £80,504
You will be responsible for shaping the security roadmap, developing the security elements of the wider technology strategy and ensuring information security is embedded across technology, projects, suppliers and operational processes.Working within a small security function and a largely outsourced technology environment, you will need to be comfortable setting direction while personally driving security improvements through to completion.This isn't a traditional hands-on Security Engineering or SOC position. However, you will need strong technical security knowledge, with the ability to understand technical risks, challenge proposed solutions and ensure appropriate controls are implemented.Key ResponsibilitiesOwn, develop and maintain information security policies, standards and controls across the organisation.Shape the Information Security strategy and develop and drive the Cyber Security roadmap.Lead Information Security Governance, Risk and Compliance activities.Define, implement, test and continually improve security controls aligned to recognised frameworks including ISO 27001.Lead the Information Security risk management programme, ensuring risks are identified, assessed, owned and actively managed through to mitigation or formal acceptance.Provide security assurance across technology projects and architecture, reviewing designs, identifying risks and ensuring appropriate controls are implemented.Lead third-party security assurance throughout the supplier lifecycle, challenging controls and ensuring remediation actions are completed.Monitor security and compliance metrics, control effectiveness and overall security maturity, using these insights to drive improvements.Lead security assurance activity including control testing, evidence gathering, compliance reviews and gap analysis.Provide guidance and challenge around security frameworks including ISO 27001, PCI DSS, CIS Controls and Cyber Essentials.Maintain oversight of security incidents, helping assess impact, coordinate activity and ensure lessons learned are reflected in future controls and processes.Own and continually improve the organisation's security awareness programme, including phishing campaigns, training and targeted guidance.Ensure information security requirements are appropriately considered within business continuity and disaster recovery planning and testing.Work closely with project teams from early discovery through to delivery, embedding security-by-design and ensuring agreed actions are completed before go-live.Provide clear security reporting, risk summaries and recommendations to senior leadership and governance forums.Work closely with outsourced technology and security suppliers, constructively challenging delivery and holding third parties accountable for agreed actions.Provide leadership, coaching and development to an IT Security Officer.Skills & ExperienceWe are looking for an experienced Information or Cyber Security professional with strong expertise across governance, risk, compliance and security assurance.You will ideally have:Strong experience within Information Security, Cyber Security or Technology Risk.Deep knowledge of Information Security and compliance frameworks such as ISO 27001, PCI DSS, CIS Controls and Cyber Essentials.Previous experience within an Information Security risk management role.Strong technical understanding with the ability to assess technical risks, challenge proposed solutions and ensure appropriate security controls are implemented.Experience developing and delivering Information or Cyber Security strategies and improvement roadmaps.Experience managing security assurance activity, including control testing, evidence gathering, gap analysis and remediation.Strong third-party risk management and supplier assurance experience.Experience providing security assurance across technology projects, solutions or architecture.Experience working within an organisation undergoing significant business or technology change.Strong stakeholder management skills with the confidence to influence and constructively challenge at all levels.Experience presenting security risks, progress and recommendations to Executive or senior governance forums.Understanding of Data Protection and the relationship between Information Security Governance and Data Protection obligations.Experience coordinating teams and stakeholders to deliver security, risk or compliance improvements.Previous leadership or line management experience.QualificationsRelevant Information Security qualifications such as CISSP, CISA, CISM or CRISC would be highly beneficial.Experience or qualifications relating to recognised project management methodologies would also be advantageous.