Jobs
My ads
My job alerts
Sign in
Find a job Career Tips Companies
Find

Information security manager

Glasgow (Glasgow City)
City Facilities Management Holdings Ltd
Information security manager
Posted: 9 October
Offer description

This role sits within the 2nd Line of defence, where you will lead and support the business, managing cyber risk and information protection positions effectively. Protecting the business from security threats, by identifying risks and developing appropriate risk migration plans. Providing senior leadership with independent assurance of their cyber risk and information protection posture.

The role will work collaboratively with 1st Line cyber team to ensure business assurance plans are shared and the requirements of 2nd Line are understood.

You will also take the lead in delivering a defined list of cyber assurance reviews, projects, and initiatives as well as achieving the cyber assurance and compliance related objectives. You will also help shape the City cyber security strategy for data security, monitoring and reporting, risk and threat assessment, incident response, business continuity and disaster recovery.


PRINCIPAL TASKS AND RESPONSIBILITIES

Monitor & Review

* Contribute and maintain the current information security risk management framework, articulate risk in business terms, identify appropriate mitigation measures and drive their delivery to ensure the security of our information and services
* Liaise with key stakeholders to prioritise technology, process and people-based security initiatives to mitigate risks identified and use continuous improvement principles to ensure the evolution of our information security delivery framework.
* Contribute to the annual information security business plan including audits, tests, risk assessment activities and additions to the information security delivery framework, e.g. policy updates.
* Identify relevant information security activities in response to changes in standards and regulations.
* Liaise with key stakeholders to prioritise information security and compliance initiatives.
* Perform security risk assessments and adversarial testing to establish proportionate risk advising of any relevant enhancements to the information security delivery framework.
* Accountable for data security measures being in place to meet our policies. This includes accountability for City’s data governance platform Microsoft Purview

Respond & Remediate

* Responding to information security incidents in line with the appropriate standards and processes, meeting or exceeding agreed KPIs.
* Following a regular timetable of security and data protection compliance audits and tests, taking appropriate steps to mitigate any risks discovered.
* Assist with the development of City’s disaster recovery and business continuity plan.
* Liaise with internal departments and external suppliers to identify and address Information Security related risks.
* Initiate, facilitate and promote activities to foster information security and data protection awareness throughout City and its suppliers.
* Advise on, and maintain data protection impact assessments
* Be the first point of contact for supervisory authorities and for individuals whose data is processed (colleagues, customers etc).
* Perform any activities relating to information security and compliance such as awareness-raising, training needs analysis, data migrations, security hardening, breach management and data protection based RFI.
* Provide assistance in business development bids, PQQs and ITT responses.
* Other duties deemed appropriate for the role and skillset.

Team Management

* Input to and fulfil the development hiring plan for the team, including sourcing, screening, and interviewing
* Hold regular 1-1s with all direct reports
* Set team goals and technical direction while ensuring that they align with the goals of the Technology and Information Security roadmaps
* Set personal goals for each team member as well as direction while ensuring they are aligned with team goals
* Implement effective engineering processes and policies that emphasize quality and forward progress
* Deputise for the Head of Information Security


SKILLS/EXPERIENCE

* Degree level qualification or equivalent experience in Cyber risk management and information protection
* Cyber security essentials
* ISO 27001
* NIST CSF
* Strong Technical Background in Data Classification and Data Loss Prevention
* Experience in information security governance, policy and procedure definition
* Experience of implementing and operating Microsoft’s unified data governance platform Purview
* Strong risk-based analysis and decision making skills
* CISSP, CRISC or CISM certified
* EU GDPR
* PCI-DSS
* Cloud, Hybrid & Global Enterprise networks
* Audit and risk assessment processes
* Managing 3rd parties


Seniority level

Mid-Senior level


Employment type

Full-time


Job function

Information Technology

Facilities Services

#J-18808-Ljbffr

Apply
Create E-mail Alert
Job alert activated
Saved
Save
Similar job
Information security manager
Glasgow (Glasgow City)
City Facilities Management
Information security manager
Similar job
Information security manager
Glasgow (Glasgow City)
City Facilities Management Holdings Ltd
Information security manager
Similar job
Information security manager
Glasgow (Glasgow City)
Information security manager
£70,000 a year
See more jobs
Similar jobs
It jobs in Glasgow (Glasgow City)
jobs Glasgow (Glasgow City)
jobs Glasgow City
jobs Scotland
Home > Jobs > It jobs > Information security manager jobs > Information security manager jobs in Glasgow (Glasgow City) > Information Security Manager

About Jobijoba

  • Career Advice
  • Company Reviews

Search for jobs

  • Jobs by Job Title
  • Jobs by Industry
  • Jobs by Company
  • Jobs by Location
  • Jobs by Keywords

Contact / Partnership

  • Contact
  • Publish your job offers on Jobijoba

Legal notice - Terms of Service - Privacy Policy - Manage my cookies - Accessibility: Not compliant

© 2025 Jobijoba - All Rights Reserved

Apply
Create E-mail Alert
Job alert activated
Saved
Save