Information Security Manager

Mace Construct

Birmingham

On-site

GBP 90,000 - 120,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Mace Construct in the United Kingdom seeks an Information Security Lead to maintain and continuously improve the ISMS across two major public infrastructure programmes in Birmingham and London. The role ensures compliance with client security requirements and regulatory obligations.

You will own the information security strategy, lead the ICT Security team, manage incident response, audits and training, and maintain ISO 27001 and Cyber Essentials Plus certifications while embedding security

Qualifications

  • Minimum 5 years in information security management.
  • Strong knowledge of IS principles, frameworks and risk management.
  • Ability to develop and enforce IS policies.
  • Experience in IT security infrastructure, including access controls, network security, endpoint protection, and secure communications.
  • Cyber Essentials auditing.
  • Hold a recognised information security qualification such as CISSP, CISM or ISO/IEC 27001 Lead Implementer / Lead Auditor, with relevant professional membership (e.g. CIISec) desirable.
  • Compliance for BPSS clearance.
  • Confident presenting to senior leadership, clients and non-technical audiences.
  • Line management experience.

Responsibilities

  • Develop and own our organisation-wide information security strategy, aligning it with client, parent company and regulatory requirements.
  • Ensure compliance with the client's contractual information security and cyber security obligations, as detailed in the project's Information Security and Cyber Security Management Plan.
  • Maintain the disaster recovery plan and incident management response aligned to parent company and client requirements.
  • Lead the ICT Security team in implementing and maintaining secure IT systems.
  • Lead on Data Protection Compliance through digital / project systems, maintaining / auditing systems and coordinating breach handling.
  • Manage data retention systems across the project.
  • Own the ISMS suite of policies, including the IS Policy Statement, Acceptable Use Policy, Remote Working Policy, Information Classification and Handling Policy, and Clear Desk Policy, ensuring they remain current and embedded across the project.
  • Provide IS performance reporting to Senior Leadership and the client.
  • Maintain the ISO 27001, PAS1192-5 and Cyber Essentials Plus certifications through ongoing compliance and surveillance audits.
  • Monitor and enforce information security requirements across the supply chain, including compliance checks and delivering supply chain audits for information security.
  • Lead incident response efforts-investigating, containing, and remediating security events with precision and speed.
  • Oversee security awareness training, empowering every employee to be a first line of defence.
  • Collaborate with other discipline and IT teams to embed security into procurement, design, construction delivery and Handover.
  • Undertake system access reviews and conduct regular risk assessments to identify and address weaknesses.
  • Manage relationships with external auditors, regulators, and security vendors.
  • Keep ahead of evolving threats, tools, and compliance frameworks (ISO 27001, NIST, GDPR, etc.).
  • Manage Contractor Assessment, onboarding and IT exit Plans.
  • Training and developing the project team and contractors around ICSC awareness.

Skills

IS concepts
Risk management
Policy enforcement
IT security infra
BPSS clearance
CISSP/CISM
ISO/IEC 27001 lead
Presentation to leadership
Line management

Education

Bachelor's degree or equivalent

Job description

About the company

At Mace Construct, our purpose is to redefine the boundaries of ambition. We are innovators, trusted partners, construction experts. Founded on a belief that the built environment sector could be more efficient, innovative and responsible. We've built a reputation and track record for delivering projects better than ever before: safer, faster and greener. Transforming industries, supporting communities and leaving legacies.

About the project

This role will support the Mace Dragados Joint Venture (MDJV) is the construction partner for the new HS2 Euston and Curzon Street Stations, working with HS2 Ltd and design partners to deliver new platforms, concourse structures, and interchange rail links.

About the role

The Information Security Lead is responsible for maintaining and continuously improving the Information Security Management System (ISMS), including supporting processes, across two major UK public infrastructure programmes delivered under a joint venture in Birmingham and London. The role ensures compliance with the client's contractual information and cyber security requirements, as well as parent-company and regulatory obligations. The postholder is also accountable for retaining ISO 27001 and Cyber Essentials Plus certifications, and for meeting the security obligations associated with nationally significant infrastructure projects.

What you'll be doing
  • Develop and own our organisation-wide information security strategy, aligning it with client, parent company and regulatory requirements.
  • Ensure compliance with the client's contractual information security and cyber security obligations, as detailed in the project's Information Security and Cyber Security Management Plan.
  • Maintain the disaster recovery plan and incident management response aligned to parent company and client requirements.
  • Lead the ICT Security team in implementing and maintaining secure IT systems.
  • Lead on Data Protection Compliance through digital / project systems, maintaining / auditing systems and coordinating breach handling,
  • Manage data retention systems across the project.
  • Own the ISMS suite of policies, including the IS Policy Statement, Acceptable Use Policy, Remote Working Policy, Information Classification and Handling Policy, and Clear Desk Policy, ensuring they remain current and embedded across the project.
  • Provide IS performance reporting to Senior Leadership and the client.
  • Maintain the ISO 27001, PAS1192-5 and Cyber Essentials Plus certifications through ongoing compliance and surveillance audits.
  • Monitor and enforce information security requirements across the supply chain, including compliance checks and delivering supply chain audits for information security.
  • Lead incident response efforts-investigating, containing, and remediating security events with precision and speed.
  • Oversee security awareness training, empowering every employee to be a first line of defence.
  • Collaborate with other discipline and IT teams to embed security into procurement, design, construction delivery and Handover.
  • Undertake system access reviews and conduct regular risk assessments to identify and address weaknesses.
  • Manage relationships with external auditors, regulators, and security vendors.
  • Keep ahead of evolving threats, tools, and compliance frameworks (ISO 27001, NIST, GDPR, etc.).
  • Manage Contractor Assessment, onboarding and IT exit Plans.
  • Training and developing the project team and contractors around ICSC awareness.
What you'll bring
  • Minimum 5 years' experience in an information security management role.
  • Strong knowledge of IS principles, frameworks and risk management.
  • Ability to develop and enforce IS policies.
  • Experience in IT security infrastructure, including access controls, network security, endpoint protection, and secure communications.
  • Cyber Essentials auditing.
  • Hold a recognised information security qualification such as CISSP, CISM or ISO/IEC 27001 Lead Implementer / Lead Auditor, with relevant professional membership (e.g. CIISec) desirable.
  • Compliance for BPSS clearance.
  • Confident presenting to senior leadership, clients and non-technical audiences.
  • Line management experience.
Nice to have
  • Strong understanding of UK data protection legislation (UK GDPR, Data Protection Act 2018) and NIS Regulations.
  • Competence in leading internal and external information security audits.
  • Experience in creating and delivering training.
  • Bachelor's degree or equivalent professional experience.

You can find more information about our culture, values, and how we reward our people here .

Mace is an inclusive employer and welcomes interest from a diverse range of candidates.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Information Security Manager - Infrastructure Projects
Senior Information Security Manager - Infrastructure Projects

Mace Construct • Birmingham

On-site
GBP 90,000 - 120,000
Information Security Manager
Information Security Manager

context recruitment • Birmingham

Hybrid
GBP 111,000 - 120,000
ICT Cyber and Information Security Manager
ICT Cyber and Information Security Manager

ISR RECRUITMENT LIMITED • North East

On-site
GBP 80,000 - 100,000
Information Security Manager
Information Security Manager

context recruitment • Greater London

Hybrid
GBP 96,000 - 126,000
Information Security Manager
Information Security Manager

Intec Select • Basingstoke

Hybrid
GBP 51,000 - 85,000
ICT Cyber and Information Security Manager
ICT Cyber and Information Security Manager

ISR RECRUITMENT LIMITED • Tees Valley

On-site
GBP 90,000 - 130,000
Senior Project Manager - Infrastructure
Senior Project Manager - Infrastructure

Mace • Addlestone

Hybrid
GBP 60,000 - 80,000
Information Security Manager
Information Security Manager

Frontpoint Partners Ltd • Greater London

On-site
GBP 85,000 - 110,000
ICT Cyber and Information Security Manager
ICT Cyber and Information Security Manager

ISR Recruitment • Tees Valley

Hybrid
GBP 70,000 - 75,000
Annual bonus (~10%)
Excellent benefits package
Senior Health and Safety Manager
Senior Health and Safety Manager

Mace • Greater London

On-site
GBP 60,000 - 80,000