Enable job alerts via email!

Information Security Assurance Manager

BAM UK & Ireland

Hemel Hempstead

Hybrid

GBP 60,000 - 80,000

Full time

Today
Be an early applicant

Job summary

A leading construction and engineering firm in the UK is seeking an Information Security Assurance Manager to oversee security frameworks and risk management. The role offers flexible, hybrid working with occasional travel. Ideal candidates have relevant certifications (e.g., CISSP, CISM) and proven experience in risk assurance functions. The position includes a competitive salary and benefits package that supports personal and professional development.

Benefits

Company car
Matched pension contributions
Private healthcare
Life assurance
26 days holiday
Overtime
On-call and sick pay

Qualifications

  • Professional certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Auditor/Implementer, or equivalent.
  • Strong knowledge of information security frameworks and standards (ISO 27001, NIST, COBIT, CIS Controls).
  • Ability to work independently and deliver high-quality assurance outputs.

Responsibilities

  • Work with key stakeholders in the business and IT.
  • Identify new and emerging risks in information security.
  • Develop and maintain security risk frameworks and policies.
  • Manage and document the Information Security Management System.
  • Perform third-party risk assessments of external suppliers.

Skills

CISSP
CISM
CRISC
ISO 27001 Lead Auditor/Implementer
Risk management
Information security frameworks
Third-party risk management
Excellent communication skills
Organizational skills
Job description

BAM UK & Ireland are recruiting an Information Security Assurance Manager to join the team. This role can be based out of any of our UK office locations. There may be a requirement for occasional travel to other BAM offices, which may involve overnight stays. BAM supports flexible working and operates a hybrid working model between home and office for this role.

Responsibilities
  • Work with key stakeholders in the business, IT team and externally where required.
  • Identifying and registering new and emerging risks and trends in the field of information security and developing appropriate measures.
  • Develop and maintain security risk frameworks, policies, and standards, aligned with regulatory and industry best practices (e.g., ISO 27001, NIST CSF).
  • Taking care of management and documentation of Information Security Management System.
  • Managing external audits like CE+, ISO27001 as per the Group requirements of maintaining security certifications.
  • Partner with internal audit, compliance, and enterprise risk functions to ensure a coordinated approach to risk management.
  • Support in answering appropriate information issues in tenders and various other government projects.
  • Performing third‑party risk assessments of external suppliers to make sure they are compliant.
  • Managing and promoting security awareness programme Group Wide.
  • Executing phishing campaigns, communications and remedial actions.
  • Drawing up reports and dashboards based on approved KPIs and KRIs.
Qualifications
  • Professional certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Auditor/Implementer, or equivalent.
  • Strong knowledge of information security frameworks and standards (ISO 27001, NIST, COBIT, CIS Controls).
  • Third‑party risk management experience.
  • Proven experience in second line of defence, risk management, assurance, or audit functions.
  • A professional and mature attitude to deal with a range of internal and external stakeholders.
  • Understanding and practical experience in the application of data protection and other related legislation, standards and codes of practice.
  • Ability to work independently, manage competing priorities, and deliver high‑quality assurance outputs.
  • Team‑oriented and able to collaborate with different departments.
  • Excellent organisational and communication skills.
Benefits
  • Competitive salary and benefits package, which includes a company car, matched pension contributions, private healthcare, life assurance, 26 days holiday, overtime, travel time, on‑call and sick pay. Support for further personal, professional, technical and leadership development.
Our Culture

People are at the heart of what we do at BAM. We recognise that creating a diverse and inclusive environment that nurtures our employees and encourages them to bring their best and whole selves to work is crucial. We proudly promote an inclusive culture that welcomes talent regardless of race, colour, religion, nationality, gender identity, sexual orientation, age, disability or other characteristics.

Be you! Join us today, so we can achieve amazing things together and build a sustainable tomorrow. We’re on an exciting journey to lead the way towards a sustainable future for us, our communities and future generations.

We are committed to an inclusive recruitment and onboarding process and welcome you to speak with us about making the experience as accessible as possible.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.