Assistant Manager – Information Security

Jobtailor

Greater London

Hybrid

GBP 70,000 - 95,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Jobtailor is seeking an experienced information security professional to lead ISMS management, risk assessments and compliance efforts across UK regulations. The role emphasizes security-by-design, governance oversight and remediation tracking.

The candidate will coordinate with security operations, auditors and external providers, producing audit-ready documentation and management reporting to support continuous improvement.

Qualifications

  • Bachelor’s degree in Information / Cyber Security or related discipline; equivalent professional experience may be considered.
  • Relevant professional certifications (e.g., CISM, CISSP, ISO 27001 Lead Implementer/Auditor) preferred.
  • 5+ years’ experience in information and cyber security implementation, management and governance, ideally within UK financial services.

Responsibilities

  • Maintain and continuously improve the ISO 27001:2022 ISMS including policies, standards, procedures, documentation and Statement of Applicability.
  • Provide security and data protection assurance for new initiatives, changes and projects; embed security-by-design and privacy-by-design.
  • Conduct information security risk assessments, prioritise threats and control gaps, track remediation and maintain risk register.

Skills

ISO 27001:2022 Management
Information Security Risk Assessment
UK GDPR Compliance
Vulnerability Management
Incident Response

Education

Bachelor’s degree in Information/Cyber Security

Tools

SIEM
Cloud Security
Data Protection Controls

Job description

  • Maintain and continuously improve the ISO 27001:2022 Information Security Management System, including policies, standards, procedures, documentation and Statement of Applicability.
  • Provide security and data protection assurance for new initiatives, changes and projects, embedding security-by-design and privacy-by-design.
  • Conduct information security risk assessments, prioritise threats and control gaps, track remediation and maintain the risk register.
  • Define, document and drive adoption of security controls across internal systems, third parties and public networks.
  • Provide governance and oversight to cyber security operations and liaise with specialist technical teams.
  • Coordinate threat intelligence and vulnerability management, remediation SLAs and external providers.
  • Support incident response, crisis management, operational resilience, business continuity and IT disaster recovery, including AWS cloud environments.
  • Support the Data Protection Officer with UK GDPR governance, ROPA, data retention, DSARs, DPIAs and personal data breach assessments.
  • Perform and govern security and data protection due diligence for suppliers, processors and critical third parties.
  • Partner with auditors, regulators and payment schemes; prepare evidence and support audits, certifications and reviews including ISO 27001, CHAPS, FPS, Bacs and SWIFT CSP.
  • Produce management reporting, metrics, KRIs, dashboards and committee packs on security posture, incidents, vulnerabilities, data protection and compliance.
  • Act as a first point of contact for security and data protection queries, alerts and events; maintain records and documentation.
  • Support security control reviews, vulnerability assessments, security awareness and data protection training.
Requirements
  • Bachelor’s degree in Information / Cyber Security, Computer Science or a related discipline; equivalent professional experience may be considered.
  • Relevant professional certifications are strongly preferred, for example CISM, CISSP, ISO 27001 Lead Implementer / Lead Auditor.
  • Technology-centric training and certification is an advantage.
  • 5+ years’ experience in information and cyber security implementation, management and governance, ideally within UK financial services, covering ISMS management, risk management, and management reporting.
  • Working knowledge of information security and data protection frameworks and regulation, including ISO 27001:2022, NIST CSF, UK GDPR, and awareness of FCA / PRA and payment scheme expectations.
  • Sound understanding of the cyber threat landscape, threat intelligence, vulnerability management and incident / breach management, with the ability to interpret events and drive effective remediation.
  • Working knowledge with security technologies and controls, including perimeter/edge security controls, data protection controls, SIEM / monitoring controls and cloud security.
  • Exposure to operational resilience, business continuity (ISO 22301) and IT disaster recovery, with awareness of FCA / PRA operational resilience expectations (SYSC 15A / SS1/21).
  • Excellent analytical, written and stakeholder-engagement skills, with the ability to produce audit-ready documentation and influence decision-making across technical and non-technical audiences.
  • Committed to continuous learning and keeping up to date with evolving threats, technologies and regulatory requirements.
Core Competencies

Demonstrates expertise in maintaining and improving ISO 27001:2022 Information Security Management Systems, conducting risk assessments, and ensuring compliance with UK GDPR and other regulatory frameworks. Proficient in incident response, vulnerability management, and producing audit-ready documentation for stakeholders.

Highest-signal resume keywords
  • ISO 27001:2022 Management
  • Information Security Risk Assessment
  • UK GDPR Compliance
  • Vulnerability Management
  • Incident Response
Hard Skills
  • Information Security Management
  • Risk Management
  • Data Protection Governance
  • Security Control Implementation
  • Threat Intelligence Analysis
  • Vulnerability Assessment
  • Business Continuity Planning
  • IT Disaster Recovery
  • Audit Documentation
  • Operational Resilience
Soft Skills
  • Analytical Skills
  • Stakeholder Engagement
  • Written Communication
  • Decision-Making InfluenceContinuous Learning
Certifications & Qualifications
  • CISM
  • CISSP
  • ISO 27001 Lead Implementer
  • ISO 27001 Lead Auditor
Industry Keywords
  • UK Financial Services
  • NIST CSF
  • FCA
  • PRA
  • CHAPS
  • FPS
  • Bacs
  • SWIFT CSP
  • ROPA
  • DPIA
Tools & Technologies
  • SIEM
  • Cloud Security
  • Perimeter Security Controls
  • Data Protection Controls
  • Monitoring Controls
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Analyst
Cyber Security Analyst

Novia Financial plc • Bath

On-site
GBP 55,000 - 75,000
Assistant Manager Information Security
Assistant Manager Information Security

iFAST Global Bank Ltd • Greater London

On-site
GBP 70,000 - 120,000
Information Security and Data Protection Analyst
Information Security and Data Protection Analyst

Interact Software • Manchester

On-site
GBP 45,000 - 65,000
Information Security Manager
Information Security Manager

Jobtailor • Greater London

On-site
GBP 100,000 - 150,000
Information Security Analyst
Information Security Analyst

Herbert Smith Freehills Kramer • City Of London

On-site
GBP 40,000 - 60,000
Information Security Analyst
Information Security Analyst

Herbert Smith Freehills Kramer • City Of London

On-site
GBP 60,000 - 80,000
Information Security Executive
Information Security Executive

iFAST Global Bank Limited • Greater London

Hybrid
GBP 50,000 - 70,000
Competitive salary
25 days annual leave plus bank holidays
Performance-based bonus
+4
IT Information Security Analyst - Compliance
IT Information Security Analyst - Compliance

Adecco • West Midlands

Hybrid
GBP 45,000 - 55,000
Information Security GRC Specialist
Information Security GRC Specialist

Janus Henderson • Greater London

Hybrid
GBP 80,000 - 83,000
Hybrid work environment
Cyber Security Lead
Cyber Security Lead

Chambers & Partners • Greater London

Hybrid
GBP 90,000 - 130,000