IT Systems Security Manager

Onyx-Conseil

Greater London

On-site

GBP 75,000 - 85,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Onyx-Conseil is seeking an IT Security Manager in Central London with 5–8 years of proven expertise. You will provide guidance to corporate functions to enhance information security maturity, lead risk governance, and collaborate with business units on security roadmaps.

The role involves chairing security groups, engaging third parties, and championing security by design. The position requires frequent in-office presence (3 days per week) in London, with a salary package described as £75K–£85K

Qualifications

  • Experience in an information security risk leadership role within a large organisation.
  • Confident in presenting, discussing and championing ideas and concepts with senior stakeholders.
  • Experience of running information security risk governance processes and structures.
  • Familiarity with relevant industry standards for information security (e.g. ISO27001, NIST CSF).
  • Experience of creating, implementing and assessing against information security policies and standards.
  • Ability to analyse complex, ambiguous problems and summarise clearly with a view to establishing practical solutions.
  • Able to bridge the gap between technologists and business-people, bringing information security risks to the business with pragmatic outlook.
  • Ability to prioritise security risks and controls, differentiating essential from nice-to-have.
  • Able to communicate messages to maximise buy-in and understanding.
  • Ability to manage budgets and understand business risks.

Responsibilities

  • Provide advice, support and guidance to all Company Corporate functions to assist them to maintain and improve information security maturity.
  • Work collaboratively with all areas of the Company Corporate and build networks to promote Information Security.
  • Act as subject matter expert on IT Security, including legal and regulatory compliance.
  • Advise Company Corporate functions on how to achieve the required controls and assist with solutions.
  • Participate in Company BU’s Projects providing support, guidance, control validation and security assurance.
  • Support and encourage security by design ethos; aid GRC to build mechanisms to assess compliance.
  • Drive the development of BU/Divisional security roadmaps and oversee non-conformities feeding into the CISO roadmap.
  • Coach, train and educate the Company IT and Functions to upskill and increase security maturity in BU’s.
  • Be an active member of the IS Security community, sharing lessons learned from other BU’s.
  • Produce, implement and standardise protocol and guidance material to support BU activities.
  • Facilitate and chair security working group meetings; engage third party relationships; assist in procurement and tendering.
  • Raising the security baseline controls and standardising where appropriate; understand different business requirements and align to objectives.
  • Support Security operations to improve information security awareness across the group (phishing campaigns and reporting).
  • Oversee information security incident management and security assessments and assurance activities.
  • Manage third-party relationships and ensure regulatory/compliance reporting.

Job description

IT Security Manager

Our Client is a large international organisation who are looking to recruit an IT Security Manager with at least 5 to 8 years proven expertise.

Provide advice, support and guidance to all Company Corporate functions to assist them to maintain and improve their information security maturity.

To work collaboratively with all areas of the Company Corporate and build networks and relationships to promote Information Security.

  • Act as subject matter expert on for IT Security, including legal and regulatory compliance
  • Advise Company Corporate functions on how to achieve the required controls and assist with solutions to support them. Eg Support in the development of standards and their application in line with Group security policies.
  • Participate in Company BU’s Projects giving support, guidance, control validation and overall security assurance. This could also involve sitting on major project steering committees.
  • Support and encourage the ethos and methodology of security by design.
  • Aid GRC to build, implement and facilitate a mechanism to aid BU’s to assess and measure their security compliance to policies.
  • Drive the development of BU/Divisional security roadmaps. Giving oversight of key non-conformities to feed into the CISO roadmap.
  • Coach, train and educate the Company IT and Functions to up skill and increase the security maturity in BU’s.

    Be an active member of the Company’s IS Security community, contributing to and leveraging the experience and lessons learned from other BU’s

  • Produce, implement and standardise protocol and guidance material to support Business unit activities – examples – Asset register templates, third party due-diligence.
  • Facilitate and chair the security working group meetings
  • Engage and manage third party relationships to support the Company and its affiliates
  • Aid Procurement and the tendering process
  • Raising the security baseline controls and standardising where it makes sense to do so.
  • Understanding the different business requirements and aligning to their objectives

Support Security operations to continuously improve information security awareness across the group, including phishing campaigns and associated reporting

Experience

  • Experience in an information security risk leadership role within a large organisation.
  • Confident in presenting, discussing and championing ideas and concepts with senior stakeholders.
  • Experience of running information security risk governance processes and structures
  • Familiarity with relevant industry standards for information security (e.g. ISO27001, NIST CSF)
  • Experience of creating, implementing and assessing against information security policies and standards

    Creativity

  • Able to analyse complex, ambiguous problems and summarise clearly with a view to establishing practical solutions
  • Able to “bridge the gap” between technologists and business-people, bringing to life information security risks to the business, while maintaining a pragmatic outlook on likelihood and impact of the risk and cost/complexity of the mitigation.
  • Ensuring initiatives/programmes are anchored in best practice whilst still being highly practical/pragmatic.
  • Ability to defuse situations and resolve conflict to a win‑win outcome
  • Influence others understand their views and agree ways of working that are acceptable to all parties.

    Business acumen to understand business risks and the information security implications

  • Able to identify when information security risks need to be escalated to achieve the right level of management visibility.
  • Able to prioritise security risks and controls, differentiating the essential from the “nice to have”.
  • Able to judge how to communicate messages to people to maximise buy‑in and/or understanding.
  • Able to analyse data with rigour & reach sound conclusions
  • Can assess when further data gathering, or analysis will bring diminishing returns. Can place appropriate weight on prevailing (sometimes conflicting) evidence.
  • Support and manage budget

    Responsibility

  • Responsibility of information security incident management
  • Responsibility for security assessments and assurance activities (e.g. penetration testing) and when to use them.
  • Oversee and management of security compliance management and reporting in relation to any relevant regulatory or legal requirements Operational responsibility of management of third parties

    Responsibility for managing change management around project and change leadership.

    Able to judge the political and other people aspects of a situation, and tailor messages and approach to bring people along.

  • Able to work with others, setting challenging but realistic targets for team members, and through coaching and appropriate guidance, securing a successful outcome.
  • A positive collegiate approach to developing relationships and networks at all levels across the Company and the gravitas to work persuasively with senior stakeholders.

Is aware of different styles of stakeholders and can adjust own leadership style successfully to bridge any gaps.

The Client and the role is based in Central London – and you will be required to be in the office at least 3 days week.

The salary for this position will be £75K + £85K plus Benefits.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Manager
IT Security Manager

Onyx-Conseil • Greater London

Hybrid
GBP 75,000 - 85,000
Information Security Architect / Manager
Information Security Architect / Manager

Onyx-Conseil • Greater London

Hybrid
GBP 78,000 - 106,000
Information Security Manager
Information Security Manager

British Land • Greater London

Hybrid
GBP 90,000 - 130,000
ICT Cyber and Information Security Manager
ICT Cyber and Information Security Manager

ISR RECRUITMENT LIMITED • Tees Valley

On-site
GBP 90,000 - 130,000
Information Security Manager
Information Security Manager

Coba IT Consultants • United Kingdom

Hybrid
GBP 90,000 - 120,000
Hybrid working arrangement
15% performance-related bonus
Enhanced pension contribution
+4
Information Security Manager
Information Security Manager

Intec Select • Basingstoke

Hybrid
GBP 51,000 - 85,000
IT Security Manager
IT Security Manager

Surrey Satellite Technology Ltd. • Guildford

On-site
GBP 70,000 - 90,000
Information Security Manager
Information Security Manager

SSA Digital Recruitment • Bedford

Hybrid
GBP 75,000 - 95,000
Information Security Manager
Information Security Manager

itecopeople • Greater London

Hybrid
GBP 68,000
30 days annual leave
Generous pension
Flexible hybrid working
Information Security Manager – 11768AW
Information Security Manager – 11768AW

Proactive.IT Appointments Limited • Bristol

Hybrid
GBP 90,000 - 100,000