Assistant Manager Information Security

iFAST Global Bank Limited

Greater London

Hybrid

GBP 60,000 - 69,000

Full time

46 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

25 days annual leave entitlement plus
Pension scheme, 4% employer conribtion
Private Medical Insurance
60-40 Hybrid working after probation
Training and development
Free gym access in the building

Job summary

iFAST Global Bank Limited seeks an experienced Information Security & Risk Manager to lead ISO 27001 ISMS development and governance. You will drive risk assessments, implement security controls, and oversee threat intelligence, vulnerability management, and incident response across complex architectures.

The role requires strong regulatory knowledge (UK GDPR, FCA/PRA) and experience in data protection, resilience, and third-party risk.

Qualifications

  • Bachelor's degree in Information / Cyber Security, Computer Science or a related discipline; equivalent professional experience may be considered.
  • Relevant professional certifications are strongly preferred, for example CISM, CISSP, ISO 27001 Lead Implementer / Lead Auditor. Technology‑centric training and certification is an advantage.

Responsibilities

  • Maintain and continuously improve the ISO 27001:2022 ISMS, including the Statement of Applicability, information security policies, standards and procedures, and the supporting documentation register, ensuring they remain current, mapped to control frameworks and audit-ready.
  • Provide proactive security and data protection assurance for new initiatives, change and ongoing projects, ensuring security-by-design and privacy-by-design requirements are embedded from design through implementation.
  • Conduct information security risk assessments to identify, evaluate and prioritise threats and control gaps, ensuring effective controls are agreed, implemented, tracked to closure and reflected in the risk register.
  • Define, document and drive adoption of security controls that protect information flows across internal systems, third parties and public networks, in line with the ISMS and regulatory requirements.
  • Act as the governance and oversight interface to the bank's cyber security operations, liaising with the specialist technical teams that run day‑to‑day security monitoring, detection and remediation, rather than performing these activities hands‑on.
  • Conduct and coordinate threat intelligence and vulnerability management interpreting relevant intelligence, tracking identified vulnerabilities against remediation SLAs, coordinating timely remediation with technology teams and external providers, and keeping abreast of the evolving threat landscape.
  • Support the maintenance and testing of incident response and crisis management procedures, contributing to the effective triage, coordination and post‑incident review of security and data protection events while minimising business disruption.
  • Act as support for the bank's operational resilience and business continuity arrangements, and working closely relevant stakeholders and IT on disaster recovery.
  • Conduct and contribute to business impact analyses, business continuity and IT disaster recovery plans and their testing (including the AWS cloud environment), helping ensure recovery objectives (RTO / RPO) are documented, achievable and evidenced, with lessons learned fed into improvements.

Skills

ISO 27001
Risk management
Threat intelligence
Incident management
Vulnerability management
Regulatory compliance
Cloud security
Governance reporting
Stakeholder engagement
Business continuity

Education

Bachelor's degree in Information / Cyber Security
CISM
CISSP
ISO 27001 Lead Implementer / Lead Auditor

Tools

SIEM
AWS

Job description

MAIN DUTIES
Information Security & Risk Management
  • Maintain and continuously improve the ISO 27001:2022 ISMS, including the Statement of Applicability, information security policies, standards and procedures, and the supporting documentation register, ensuring they remain current, mapped to control frameworks and audit-ready.
  • Provide proactive security and data protection assurance for new initiatives, change and ongoing projects, ensuring security-by-design and privacy-by-design requirements are embedded from design through implementation.
  • Conduct information security risk assessments to identify, evaluate and prioritise threats and control gaps, ensuring effective controls are agreed, implemented, tracked to closure and reflected in the risk register.
  • Define, document and drive adoption of security controls that protect information flows across internal systems, third parties and public networks, in line with the ISMS and regulatory requirements.
  • Act as the governance and oversight interface to the bank's cyber security operations, liaising with the specialist technical teams that run day‑to‑day security monitoring, detection and remediation, rather than performing these activities hands‑on.
  • Conduct and coordinate threat intelligence and vulnerability management interpreting relevant intelligence, tracking identified vulnerabilities against remediation SLAs, coordinating timely remediation with technology teams and external providers, and keeping abreast of the evolving threat landscape.
  • Support the maintenance and testing of incident response and crisis management procedures, contributing to the effective triage, coordination and post‑incident review of security and data protection events while minimising business disruption.
  • Act as support for the bank's operational resilience and business continuity arrangements, and working closely relevant stakeholders and IT on disaster recovery.
  • Conduct and contribute to business impact analyses, business continuity and IT disaster recovery plans and their testing (including the AWS cloud environment), helping ensure recovery objectives (RTO / RPO) are documented, achievable and evidenced, with lessons learned fed into improvements.
Data Protection Governance
  • Support the Data Protection Officer in operating the bank's data protection framework under UK GDPR and applicable regulations.
  • Maintain the Record of Processing Activities (ROPA) and support data retention, data minimisation and records‑management governance across the bank.
  • Support the handling of Data Subject Access Requests (DSARs) and other data subject rights, and the completion of Data Protection Impact Assessments (DPIAs) for new or changed processing.
  • Assess personal data breaches, contributing to containment, root‑cause analysis and the assessment of notification obligations to the ICO and affected individuals within regulatory timeframes.
  • Contribute to data protection and processor due diligence within third‑party and outsourcing arrangements.
Third-Party & Supply Chain Security
  • Perform and govern security and data protection due diligence and ongoing assurance of suppliers, processors and critical third parties, in line with supplier controls and regulatory expectations on outsourcing and third‑party risk.
  • Track third‑party findings, remediation actions and assurance evidence (e.g. certifications, attestations, control reports), escalating material risks as appropriate. Assurance, Compliance & Reporting
  • Partner with auditors, regulators and payment schemes by preparing evidence, providing subject‑matter expertise, and supporting internal and external audits, certifications and reviews (including ISO 27001 surveillance and scheme assurance such as CHAPS, FPS, Bacs and SWIFT CSP).
  • Advise stakeholders on information security and data protection regulatory obligations including breach assessment and notification helping the bank meet its regulatory and applicable payment scheme assurance expectations.
  • Evaluate and enhance the effectiveness of the bank's information security and data protection policies, procedures and controls, driving continuous improvement and closure of audit and assessment findings.
  • Produce timely, accurate and risk‑focused management reporting including metrics, key risk indicators (KRIs), dashboards and committee packs on security posture, incidents, vulnerabilities, data protection and compliance activities.
GENERAL
  • Act as a first point of contact for information security and data protection queries, alerts and events, coordinating responses via the bank's incident management protocols and escalating to the Head of Information Security & Resilience as appropriate.
  • Undertake day‑to‑day administrative tasks, reporting and communication with relevant departments across the organisation
  • Maintain security and data protection records, control documentation, dashboards and reports.
  • Assist in conducting reviews and assessments to identify and report potential vulnerabilities, weaknesses and threats.
  • Support the implementation, monitoring and governance of security controls that protect the bank's data, systems and networks.
  • Support the delivery of security awareness and data protection training to foster a strong risk awareness culture across the bank.
Requirements
EDUCATION & TRAINING
  • Bachelor's degree in Information / Cyber Security, Computer Science or a related discipline; equivalent professional experience may be considered.
  • Relevant professional certifications are strongly preferred, for example CISM, CISSP, ISO 27001 Lead Implementer / Lead Auditor. Technology‑centric training and certification is an advantage.
Experience And Skills
  • 5+ years' experience in information and cyber security implementation, management and governance, ideally within UK financial services, covering ISMS management, risk management, and management reporting.
  • Working knowledge of information security and data protection frameworks and regulation, including ISO 27001:2022, NIST CSF, UK GDPR, and awareness of FCA / PRA and payment scheme expectations.
  • Sound understanding of the cyber threat landscape, threat intelligence, vulnerability management and incident / breach management, with the ability to interpret events and drive effective remediation.
  • Working knowledge with security technologies and controls (e.g., Perimeter/edge security controls, data protection controls, SIEM / monitoring controls) and cloud security.
  • Exposure to operational resilience, business continuity (ISO 22301) and IT disaster recovery, with awareness of FCA / PRA operational resilience expectations (SYSC 15A / SS1/21).
  • Excellent analytical, written and stakeholder‑engagement skills, with the ability to produce audit‑ready documentation and influence decision‑making across technical and non‑technical audiences.
  • Committed to continuous learning, keeping up to date with evolving threats, technologies and regulatory requirements.
Benefits
  • 25 days annual leave entitlement plus 8 bank holidays
  • Pension scheme, 4% employer contribution
  • Private Medical Insurance
  • 60-40 Hybrid working after successful probation period
  • Training and development
  • Free gym access in the building
Salary: £60K Annual (Negotiable)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Assistant Manager – Information Security
Assistant Manager – Information Security

Jobtailor • Greater London

Hybrid
GBP 70,000 - 95,000
Assistant Manager Information Security
Assistant Manager Information Security

iFAST Global Bank Ltd • Greater London

On-site
GBP 70,000 - 120,000
Information Security Executive
Information Security Executive

iFAST Global Bank Limited • Greater London

Hybrid
GBP 50,000 - 70,000
Competitive salary
25 days annual leave plus bank holidays
Performance-based bonus
+4
Information Security Officer
Information Security Officer

Recognise Bank • Greater London

Hybrid
GBP 70,000 - 100,000
Competitive Time Off
Work From Anywhere (up to 6 weeks/year
Learning & Development
+5
Cyber Security Analyst
Cyber Security Analyst

Novia Financial plc • Bath

On-site
GBP 55,000 - 75,000
Information Security and Data Protection Analyst
Information Security and Data Protection Analyst

Sideways 6 • Manchester

On-site
GBP 42,000 - 62,000
25 days annual leave
Cycle to work scheme
Learning & Development platform
+5
Engineering Manager, Security
Engineering Manager, Security

Insignis Cash • Greater London

Hybrid
GBP 120,000 - 180,000
25 days holiday
5% Pension contributions
Private medical insurance with Vitaliy
+5
Security Design Consultant
Security Design Consultant

Lloyds Banking Group • Manchester

Hybrid
GBP 65,000 - 110,000
Generous pension
Annual bonus
Share schemes
+2
Security Design Consultant
Security Design Consultant

Lloyds Banking Group • West of England

Hybrid
GBP 70,000 - 90,000
Up to 15% pension contribution
Annual performance bonus
Share schemes
+2
Security Design Consultant
Security Design Consultant

Lloyds Banking Group • Leeds

Hybrid
GBP 65,000 - 90,000
Generous pension up to 15%
Annual bonus
Share schemes including free shares
+1