- Maintain and continuously improve the ISO 27001:2022 Information Security Management System, including policies, standards, procedures, documentation and Statement of Applicability.
- Provide security and data protection assurance for new initiatives, changes and projects, embedding security-by-design and privacy-by-design.
- Conduct information security risk assessments, prioritise threats and control gaps, track remediation and maintain the risk register.
- Define, document and drive adoption of security controls across internal systems, third parties and public networks.
- Provide governance and oversight to cyber security operations and liaise with specialist technical teams.
- Coordinate threat intelligence and vulnerability management, remediation SLAs and external providers.
- Support incident response, crisis management, operational resilience, business continuity and IT disaster recovery, including AWS cloud environments.
- Support the Data Protection Officer with UK GDPR governance, ROPA, data retention, DSARs, DPIAs and personal data breach assessments.
- Perform and govern security and data protection due diligence for suppliers, processors and critical third parties.
- Partner with auditors, regulators and payment schemes; prepare evidence and support audits, certifications and reviews including ISO 27001, CHAPS, FPS, Bacs and SWIFT CSP.
- Produce management reporting, metrics, KRIs, dashboards and committee packs on security posture, incidents, vulnerabilities, data protection and compliance.
- Act as a first point of contact for security and data protection queries, alerts and events; maintain records and documentation.
- Support security control reviews, vulnerability assessments, security awareness and data protection training.
Requirements
- Bachelor’s degree in Information / Cyber Security, Computer Science or a related discipline; equivalent professional experience may be considered.
- Relevant professional certifications are strongly preferred, for example CISM, CISSP, ISO 27001 Lead Implementer / Lead Auditor.
- Technology-centric training and certification is an advantage.
- 5+ years’ experience in information and cyber security implementation, management and governance, ideally within UK financial services, covering ISMS management, risk management, and management reporting.
- Working knowledge of information security and data protection frameworks and regulation, including ISO 27001:2022, NIST CSF, UK GDPR, and awareness of FCA / PRA and payment scheme expectations.
- Sound understanding of the cyber threat landscape, threat intelligence, vulnerability management and incident / breach management, with the ability to interpret events and drive effective remediation.
- Working knowledge with security technologies and controls, including perimeter/edge security controls, data protection controls, SIEM / monitoring controls and cloud security.
- Exposure to operational resilience, business continuity (ISO 22301) and IT disaster recovery, with awareness of FCA / PRA operational resilience expectations (SYSC 15A / SS1/21).
- Excellent analytical, written and stakeholder-engagement skills, with the ability to produce audit-ready documentation and influence decision-making across technical and non-technical audiences.
- Committed to continuous learning and keeping up to date with evolving threats, technologies and regulatory requirements.
Core Competencies
Demonstrates expertise in maintaining and improving ISO 27001:2022 Information Security Management Systems, conducting risk assessments, and ensuring compliance with UK GDPR and other regulatory frameworks. Proficient in incident response, vulnerability management, and producing audit-ready documentation for stakeholders.
Highest-signal resume keywords
- ISO 27001:2022 Management
- Information Security Risk Assessment
- UK GDPR Compliance
- Vulnerability Management
- Incident Response
Hard Skills
- Information Security Management
- Risk Management
- Data Protection Governance
- Security Control Implementation
- Threat Intelligence Analysis
- Vulnerability Assessment
- Business Continuity Planning
- IT Disaster Recovery
- Audit Documentation
- Operational Resilience
Soft Skills
- Analytical Skills
- Stakeholder Engagement
- Written Communication
- Decision-Making InfluenceContinuous Learning
Certifications & Qualifications
- CISM
- CISSP
- ISO 27001 Lead Implementer
- ISO 27001 Lead Auditor
Industry Keywords
- UK Financial Services
- NIST CSF
- FCA
- PRA
- CHAPS
- FPS
- Bacs
- SWIFT CSP
- ROPA
- DPIA
Tools & Technologies
- SIEM
- Cloud Security
- Perimeter Security Controls
- Data Protection Controls
- Monitoring Controls