Information Security & Data Protection Manager
Based: Remote (UK)/High Wycombe/London (N7)/Hybrid
Term: Permanent, Full time
Reporting to: Chief Information Officer (CIO)
Salary: £60k - £85k pa + excellent benefits
Role
We’re looking for an Information Security Compliance Specialist to take ownership of our Information Security, Data Protection, and AI Governance programmes across the Focusrite Group. You will be the operational owner of our Information Security and Data Protection (ISDP) framework informed by ISO 27001 (ISMS), ISO 27701 (PIMS), Cyber Essentials and NIST CSF keeping us aligned to those standards and ready for certification and audit.
Working alongside development, IT, and business teams, you will advise on security and privacy requirements for new and changing systems, ensuring appropriate controls are designed in, evidenced, and verified after implementation. You will also own the Group’s response to emerging risks in AI, translating evolving regulation (EU AI Act, UK AI principles, ICO guidance) into practical governance.
About You
Several years’ experience in Information Security and Data Protection, with a good understanding of IT systems, web operations, cloud platforms, and secure coding practices (including OWASP).
Comfortable engaging at all levels of the organisation and externally, with the gravitas to influence security and privacy outcomes and reduce the impact of change.
The position requires providing support and advice to all parts of the Group on Information Security and Data Protection.
Responsibilities
* Own the Information Security and Data Protection Framework and its documentation, and advise IT, development, and business teams on security requirements.
* Run the Business Approved Tools process (including assessment of AI tools, vendors, and use cases), own designated Information Security tools, and conduct supplier audit assessments.
* Own certification readiness for Cyber Essentials and lead new certification efforts as the business requires.
* Monitor cyber threats and translate them for the business, own the incident management process (including phishing response and simulation exercises), and manage vulnerability scans and penetration testing (including external Red/Purple/Blue Team engagements).
* Conduct risk assessments across products, systems, and processes; own the Information Security and Data Protection risk register, contributing to the Group Risk Management process; and maintain and test the Business Continuity Plan (BCP).
* Own the AI Governance framework, AI system inventory, and alignment with ISO 42001, NIST AI RMF, and the EU AI Act where appropriate.
Data Protection Compliance
* Handle Data Subject Rights requests (Subject Access, erasure, rectification, restriction, objection, portability, and rights relating to automated decision‑making) and run Data Protection Impact Assessments (DPIAs).
* Maintain the Records of Processing Activities (RoPA) under Article 30 for controller and processor activities, the lawful basis register, consent records, and Legitimate Interest Assessments (LIAs).
* Operate Privacy Notices and Cookie Tools (OneTrust), and advise on PECR and e‑privacy compliance including direct marketing and electronic communications.
* Help product managers and developers embed Privacy by Design, and design and deliver Data Protection training and awareness across the Group.
* Own the retention schedule and deletion/anonymisation processes, and own personal data breach handling (including detection triage, 72‑hour ICO/EU supervisory authority notification, data subject notification where required, and the breach register).
* Manage processor and sub‑processor governance (Article 28 due diligence, Data Processing Agreements, processor register) and international data transfers (SCCs, the UK IDTA/Addendum, and Transfer Risk Assessments).
Change Management
* Review and provide security and data protection sign‑off on changes to systems, products, and processes.
* Participate in the Change Advisory Board (CAB) and ensure security and privacy risks are assessed before changes are approved.
* Own change management procedures relating to Information Security and Data Protection, ensuring evidence is captured for audit.
* Ensure security and privacy requirements are embedded in the SDLC and release processes, working with development and operational teams.
* Track and report on the security impact of significant business, technology, and organisational change initiatives.
Compliance and Audits
* Generate monthly compliance and activity reports and other reports as required by senior management.
* Review Financial System compliance activities; perform internal Information Security audits; perform internal Data Protection audits.
* Be the key contact for any IT / Data Protection related audits by external bodies, ensuring requested data is supplied, complete, and accurate; take ownership of any related audit issues; generate audit support documents.
You will be expected to keep up to date with developments in the security, privacy, and AI regulatory landscape, translating these into practical actions for the Group.
We understand that not all candidates will have in depth experience of all these elements, so we welcome applications from candidates who meet most of the criteria and have a desire to learn the rest. Please provide details in your covering letter of additional training requirements / certifications in progress etc.
Benefits
Flexible/hybrid working, company pension, life insurance, private healthcare, Health Cash Plan, enhanced Maternity and Paternity pay, employee purchase scheme, group bonus scheme, company music events, off‑site company parties and free lunch in the canteen. Company training sessions and personal development are encouraged.
Equal Opportunity Statement
As an equal opportunity employer, the Focusrite Group is committed to Diversity and Inclusion. The group mission is to cultivate an equitable culture, internally and externally, where all people feel they are welcome, safe and positively represented.
#J-18808-Ljbffr