Enable job alerts via email!

Information Security Manager

Crown Agents Bank

City of Westminster

Hybrid

GBP 125,000 - 150,000

Full time

Today
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading financial services firm in the City of Westminster seeks an Information Security Manager to protect system integrity and data confidentiality. The role involves advising project teams, managing security assessments, and leading security incident responses. Required qualifications include a Bachelor's degree in Computer Science and CISSP certification. The position offers competitive salary, hybrid working arrangements, and comprehensive benefits including private medical insurance.

Benefits

Competitive salary and benefits
Training and development support
Hybrid working arrangements
Contributory personal pension plan
Life assurance
Private medical insurance
Discretionary bonus
Competitive annual leave
Volunteering days

Qualifications

  • Extensive experience in information security roles, ideally in a regulated environment.
  • Strong understanding of security in software development and application security.
  • Experience using security tools like Tenable and Mimecast.

Responsibilities

  • Advise project teams on security best practices throughout the lifecycle.
  • Manage remediation of penetration testing and vulnerability assessments.
  • Lead or support response to security incidents.

Skills

Information security experience
Communication skills
Technical hands-on skills
Innovative mindset

Education

Bachelor's degree in Computer Science
CISSP certification

Tools

AWS
Tenable
Mimecast
Akamai
Sophos
Job description

from, and across often hard-to-reach markets. Job Description About the Role The Information Security Manager will play a crucial role in protecting the confidentiality, integrity, and availability of our systems and data. You'll work across the business to support secure delivery of projects, conduct thorough risk assessments, oversee third‑party security engagements, and contribute to shaping our evolving security posture. This is a technically hands‑on role ideal for someone who enjoys both strategic thinking and rolling up their sleeves to get things done.

Key Responsibilities
  • Advise and support project teams to embed security best practices throughout the project lifecycle.
  • Scope, manage, and track remediation of penetration testing and vulnerability assessments.
  • Maintain application security processes, standards, and guidelines.
  • Translate application security policies into security requirements and work closely with engineers.
  • Conduct and document security risk assessments on changes, threats, vulnerabilities, and new initiatives.
  • Perform third‑party vendor risk assessments and ongoing security reviews.
  • Assist in identifying and assessing new security technologies and vendors.
  • Lead or support response to security incidents, including investigation, containment, root cause analysis, and reporting.
  • Work with internal teams to continuously improve incident response processes.
  • Support compliance and alignment with ISO 27001, Cyber Essentials, SWIFT, NIST CSF and other relevant frameworks.
  • Communicate effectively with various stakeholders, including engineers, product managers, operations teams, senior management, and auditors regarding the information security posture, risks, and mitigation strategies.
Qualifications
  • Extensive experience in information security roles, ideally in a regulated environment.
  • Bachelor's degree or higher in Computer Science.
  • CISSP certification is essential; additional certifications (e.g., CEH, OSCP, AWS Security) are a plus.
  • Experience working with ISO 27001, Cyber Essentials, NIST CSF and preferably SOC 2, or SWIFT frameworks.
  • Strong understanding of security in the context of software development and application security (OWASP, SDLC, DevSecOps).
  • Technically hands‑on in AWS, DevSecOps pipelines, configuration of security vendor solutions, and basic scripting language for automation.
  • Experience using tools like Tenable, Mimecast, Akamai, Sophos, and MDR tools.
  • Excellent communication skills, with the ability to engage both technical and non‑technical stakeholders.
  • Innovative mindset with a passion for staying current in the ever‑evolving cyber landscape.
  • Experience working in or with regulated financial institutions is desirable.
Benefits
  • Competitive salary and benefits.
  • Training and development support.
  • Hybrid working arrangements.
  • Contributory personal pension plan.
  • Life assurance: 4 times annual salary.
  • Group income protection.
  • Private medical insurance (including cover for partner or children at company cost).
  • Optical, dental and audiology coverage.
  • Discretionary bonus.
  • Competitive annual leave.
  • Volunteering days.
  • Benefit Hub.
  • Opportunity to work on cutting‑edge financial services and security projects.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.