Information Security and Compliance Risk Manager

Bupa

Salford

On-site

GBP 54,000 - 74,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Annual performance bonus
Private medical insurance
Generous pension contribution
25 days holiday
Viva wellbeing programme
Flexible and hybrid working
Discounts and wellbeing support
Enhanced family friendly benefits

Job summary

Bupa is seeking an Information Security Risk & Compliance Manager to lead the ISMS and oversee ISO27001 audits, governance, risk and compliance activities across the organisation. You will work with senior stakeholders to strengthen security maturity and regulatory readiness while embedding risk management into decision-making.

The role involves producing governance reporting, tracking remediation, and ensuring regulatory outcomes are central to business decisions.

Qualifications

  • Experience managing an Information Security Management System (ISMS), ideally including ISO27001 certification and audit activities.
  • Strong knowledge of information security governance, risk and compliance practices.
  • Experience delivering information security audits, assurance programmes or IT control reviews.

Responsibilities

  • Lead the management and continuous improvement of Bupa's ISO27001 ISMS.
  • Coordinate and oversee information security compliance and control reviews.
  • Monitor remediation plans, control effectiveness and regulatory obligations.
  • Produce reporting for governance forums and risk committees.
  • Engage stakeholders to drive effective security governance.

Skills

ISMS management
ISO27001 audits
Governance & risk
Regulatory awareness
Stakeholder engagement

Job description

Information Security Risk & Compliance Manager

Salary: from £64,000 (Negotiable depending on experience)

Location: London (EC2R 7HJ), Leeds (LS5 3BF), Salford (M50 3SP)

Permanent

Shift pattern: Full time, 37.5 hours per week

Role specific benefits: 10% Bonus

We make health happen

At Bupa, our purpose is simple: helping people live longer, healthier, happier lives and making a better world. As an organisation focused on health and care, information security plays a vital role in protecting our customers, colleagues and business operations.

We're looking for an Information Security Risk & Compliance Manager to join our Technology Governance, Risk & Control team. This is an exciting opportunity to influence how information security risk is managed across the organisation, helping to strengthen security maturity, maintain compliance with recognised industry standards, and support regulatory requirements.

Working closely with senior stakeholders across the business, you'll be at the centre of driving effective governance, risk management and compliance activities. You'll help ensure our Information Security Management System (ISMS) remains aligned to best practice, support regulatory readiness, and contribute to a culture where security risk management is embedded into everyday decision-making.

How you'll help us make health happen:
  • Lead the management and continuous improvement of Bupa's ISO27001 Information Security Management System (ISMS).
  • Act as the primary liaison for external ISO27001 audits and certification activities.
  • Coordinate and oversee information security compliance, assurance and control review activities.
  • Monitor and report on remediation plans, control effectiveness and compliance obligations.
  • Support risk management activities across technology and information security programmes and strategic initiatives.
  • Produce high-quality reporting and management information for governance forums, executive committees and risk committees.
  • Build strong relationships with stakeholders across the business to drive effective security governance.
  • Challenge and support the identification, prioritisation and escalation of information security risks.
  • Contribute to integrated assurance activities and track risk remediation commitments.
  • Support responses to regulatory requirements and external standards, including engagement with bodies such as the FCA and PRA.
  • Promote a customer-focused approach, ensuring good customer and regulatory outcomes remain central to decision-making.
Key Skills & Experience

To be successful as an Information Security Risk & Compliance Manager, you'll bring:

  • Experience managing an Information Security Management System (ISMS), ideally including ISO27001 certification and audit activities.
  • Strong knowledge of information security governance, risk and compliance practices.
  • Experience delivering information security audits, assurance programmes or IT control reviews.
  • A solid understanding of recognised security frameworks and standards, including ISO27001, ISO27002, NIST, CIS Controls and PCI DSS.
  • Knowledge of UK regulatory environments, including organisations such as the FCA, PRA and ICO.
  • The ability to build credibility and influence stakeholders at all levels.
  • Strong analytical, reporting and communication skills, with the ability to explain complex security concepts clearly to both technical and non-technical audiences.
  • Experience developing management information, dashboards and committee reporting.
  • High levels of integrity, professionalism and sound judgement when handling sensitive information.
  • Experience within a regulated industry, particularly financial services, would be beneficial but is not essential.
  • An understanding of cloud security risks and controls.
  • The ability to manage competing priorities and deliver against deadlines in a fast-paced environment.
Benefits

Our benefits are designed to make health happen for our people. Viva is our global wellbeing programme and includes all aspects of our health - from mental and physical, to financial, social and environmental wellbeing. We support flexible working and have a range of family friendly benefits.

Joining Bupa in this role you will receive the following benefits and more:

  • Annual performance bonus
  • Private medical insurance
  • Generous pension contribution
  • 25 days holiday, increasing with service
  • Access to our Viva wellbeing programme
  • Flexible and hybrid working opportunities
  • Access to discounts and wellbeing support services
  • Enhanced family friendly benefits
Why Bupa

We're a health insurer and provider. With no shareholders, our customers are our focus. Our people are all driven by the same purpose - helping people live longer, healthier, happier lives and making a better world. We make health happen by being brave, caring and responsible in everything we do.

We encourage all of our people to "Be you at Bupa". We champion diversity and understand the importance of our people representing the communities and customers we serve. That's why we especially encourage applications from people with diverse backgrounds and experiences.

Bupa is a Level 2 Disability Confident Employer. This means we aim to offer an interview/assessment to every disabled applicant who meets the minimum criteria for the role. We'll make sure you are treated fairly and offer reasonable adjustments as part of our recruitment process to anyone who needs them.

If you require information regarding this role in an alternative format, please email: careers@bupa.com

Time Type: Full time

Job Area: Legal, Risk & Audit

Locations: Angel Court, London, Bupa Place, Kirkstall Forge

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

BISO, Internal Platforms
BISO, Internal Platforms

Bupa UK • Staines-upon-Thames

Hybrid
GBP 90,000 - 130,000
25 days holiday
Enhanced pension
Private medical insurance
+2
Security Engineer
Security Engineer

Bupa • City Of London

Hybrid
GBP 55,000 - 68,000
25 days holiday (pro rata)
Employee assistance programme
Workplace pension
+3
Security Engineer
Security Engineer

Bupa • Greater London

On-site
GBP 55,000 - 68,000
25 days holiday pro rata
Wellbeing services
Fixed term benefits allowance
+3
Cyber Security Engineer
Cyber Security Engineer

Bupa UK • Staines-upon-Thames, Manchester

Hybrid
GBP 50,000 - 70,000
25 days holiday
Bupa health insurance
Enhanced pension plan
+1
Business Information Security Officer, Dental & Care Services
Business Information Security Officer, Dental & Care Services

Bupa UK • Staines-upon-Thames

Hybrid
GBP 60,000 - 80,000
25 days holiday
Enhanced pension and life insurance
Private medical insurance
+1
Head of Cyber Culture and Awareness
Head of Cyber Culture and Awareness

Cyber UK • Greater London

Hybrid
GBP 80,000 - 100,000
25 days’ holiday
Enhanced pension and life insurance
Private medical insurance
+2
Risk & Governance Inspector
Risk & Governance Inspector

Bupa UK • Staines-upon-Thames

Hybrid
GBP 42,000 - 60,000
25 days holiday (pro rata)
Management bonus scheme 10%
Employee wellbeing program
Group Head of AI Security Architecture
Group Head of AI Security Architecture

BUPA • City Of London

Hybrid
GBP 150,000 - 190,000
25 days holiday
Car allowance
Management bonus
+5
Group Legal Advisor, Privacy
Group Legal Advisor, Privacy

Bupa UK • Leeds

On-site
GBP 70,000 - 90,000
25 days annual leave
Private medical care
Enhanced pension plan
+2
Senior Property Manager
Senior Property Manager

BUPA • Horsforth

On-site
GBP 56,000 - 70,000
25 days holiday pro rata
Private Medical Health Insurance
Enhanced pension plan