Information Security Manager

British Red Cross

Greater London

Hybrid

GBP 54,000 - 59,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible working
36 days holidays + 5 extra days
Pension up to 6%
Learning & Development
Discounts
Cycle2Work

Job summary

British Red Cross seeks an Information Security GRC Manager to lead governance, risk, and compliance for information security across the organisation. The role combines policy development, risk assessment, and third-party cyber risk management in a flexible UK-based hybrid setting.

You will own risk identification, treatment, and reporting, drive ISO/IEC 27001 certification, and interact with auditors and senior stakeholders to ensure continuous improvement.

Qualifications

  • Strong emotional intelligence and inclusive leadership to support the team.
  • Excellent knowledge of cyber and information security compliance requirements (PCI DSS, Cyber Essentials, NHS Toolkit).
  • Experience implementing or maintaining an ISO/IEC 27001 ISMS, including audits.

Responsibilities

  • Develop and maintain the information security governance framework (policies, standards, processes).
  • Oversee and improve the information security risk management framework across the organisation.
  • Own the management of information security risks with mitigation plans and reporting to leadership.
  • Lead the ISO 27001 certification programme and audits with external bodies.
  • Coordinate certification and surveillance audits with auditors and certification bodies.

Skills

Emotional intelligence
Inclusive leadership
ISO 27001
Risk management
Auditing & governance

Job description

Information Security GRC (Governance, Risk, and Compliance) Manager

Location: UK flexible location (Hybrid, home, and office)

Salary: £54,143 to £58,572 per annum, pro rata, (plus ILW, if residing & working in London)

Contract: Permanent

Could you lead a team responsible information security risk management for the British Red Cross, including the identification, assessment, and treatment, well as third-party and supply chain cyber security risk management?

What will a day in the life of an Information Security GRC Manager involve?

  • Develop and maintain the information security governance framework for the British Red Cross, including policies, standards, and processes, ensuring they align with organisational objectives, legal, contractual, regulatory requirements, and best practices.
  • Oversee and continuously improve the information security risk management framework, ensuring robust processes for identifying, assessing, recording, and managing information security risks across the British Red Cross.
  • Own the management of information security risks, including developing appropriate risk mitigation and treatment plans when risk levels exceed acceptable thresholds, providing regular reporting and insight on key risks, risk trends, and control effectiveness.
  • Lead the ISO 27001 certification programme and ongoing compliance with the ISO/IEC 27001 standard.
  • Act as the primary point of contact for external auditors and certification bodies, planning and coordinating certification (and surveillance) audits, ensuring that all necessary evidence, documentation, and corrective actions are managed effectively.
  • Work in partnership with other stakeholders, departments, and functions to ensure a cohesive approach to information security across the organisation.

To be a successful Information Security GRC Manager, what will you need?

  • Strong emotional intelligence, and a commitment to inclusive leadership, creating an environment where team members can grow and excel.
  • Excellent knowledge of common cyber and information security compliance requirements, including PCI DSS (Payment Card Industry Data Security Standard), Cyber Essentials, and the NHS Data Security & Protection Toolkit.
  • Proven experience implementing or maintaining an ISO/IEC 27001 certified ISMS, including managing certification audits and continual improvement cycles.
  • Strong understanding of enterprise risk management methodologies and tools, particularly as they apply to information security risk identification, assessment (quantitative and qualitative), mitigation, and monitoring.
  • Demonstrable experience in information security risk management, including establishing risk assessment processes, running risk workshops, managing risk registers, and presenting risk statuses to senior management or governance boards.

Interested?

The closing date for applications is 23.59 on Thursday the 13th of August 2027 with interviews to follow.

In return for your commitment and expertise, you’ll get:

  • Flexible working: Remote and hybrid working, flexitime, compressed hours, and job sharing.
  • Holidays: 36 days annual leave (including bank holidays) + option to buy 5 extra days.
  • Pension scheme: Up to 6% contributory pension.
  • Learning & Development: A range of career & learning opportunities.
  • Discounts: Blue Light Discount Card, Tickets For Good & employee benefits platform..
  • Cycle2Work: Lease a bicycle through the scheme.

We are proud to champion inclusion as a Disability Confident employer across our UK-based roles and as a Carers Confident employer.

We are dedicated to building an inclusive, equitable and wellbeing-focused culture where everyone feels safe, valued and can thrive. Guided by our Equity, Diversity, Inclusion and Wellbeing Strategy, we foster belonging, psychological and physical wellbeing, and work to remove barriers to fair opportunities. Grounded in compassion and anti-racist practice, we listen to diverse voices, value lived experience and create environments where staff and volunteers can succeed. Join us and be part of an organisation that leads with care, celebrates difference and helps everyone succeed.

Together, we are the world's emergency responders

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Team Manager
Cyber Security Team Manager

British Red Cross • United Kingdom

Hybrid
GBP 54,000 - 59,000
Flexible working
Holidays
Pension scheme
+4
InfoSec GRC Manager - ISO27001 & Risk Leader
InfoSec GRC Manager - ISO27001 & Risk Leader

British Red Cross • Greater London

Hybrid
GBP 54,000 - 59,000
Flexible working
36 days holidays + 5 extra days
Pension up to 6%
+3
Information Security GRC Manager
Information Security GRC Manager

AJ Bell • Manchester

Hybrid
GBP 65,000 - 85,000
27 days’ holiday
Pension with matched contributions up to 8%
Discretionary bonus and share awards
+3
Senior Information Security (GRC) Specialist
Senior Information Security (GRC) Specialist

BMS Group • Greater London

Hybrid
GBP 90,000 - 130,000
comprehensive private medical cover
annual health checks
virtual 24hr GP
+3
Cyber Security Manager - Governance, Risk and Compliance (GRC)
Cyber Security Manager - Governance, Risk and Compliance (GRC)

Essex Partnership University NHS Foundation Trust • Grays

On-site
GBP 49,000 - 57,000
£8,000 relocation package
NHS benefits
Season ticket loans
Information Security GRC Lead
Information Security GRC Lead

RAC • West of England

Hybrid
GBP 70,000 - 95,000
Colleague Share Scheme (Owning It.Tog)
RAC Ultimate Breakdown Service
Car salary sacrifice scheme
+7
Information Security GRC Specialist
Information Security GRC Specialist

Motor Insurers' Bureau (MIB) • Milton Keynes

Hybrid
GBP 55,000 - 70,000
Contributory Group Pension scheme
Life Assurance
Employee Incentive Scheme
+5
IT Senior Procurement Specialist
IT Senior Procurement Specialist

British Red Cross • Paisley

Hybrid
GBP 37,000 - 44,000
36 days annual leave
Pension scheme with up to 6% contribution
Flexible working
+3
Information Security Governance, Risk and Compliance Specialist
Information Security Governance, Risk and Compliance Specialist

GWI • Greater London

Hybrid
GBP 70,000 - 100,000
25 days annual leave
Health cash plan
4% pension matching
+6
Head of Government Relations
Head of Government Relations

The British Red Cross Society • City Of London

Hybrid
GBP 68,000 - 74,000
36 days annual leave
Pension up to 6%
Flexible working
+6