Salary: £55,000 - 65,000 per year Requirements: Degree in Cyber Security, Computer Science, IT or equivalent experience Certifications such as CISSP, CISM, or ISO 27001 Lead Implementer/Auditor are beneficial Strong experience in senior information security or cybersecurity roles Proven track record in building or owning security governance frameworks Knowledge of cloud security and SaaS environments Understanding of cyber risk, GDPR, and data protection principles Experience working with regulated partners or in regulated industries Strong communication skills with the ability to influence senior stakeholders Experience leading or maturing ISO 27001 programmes (desirable) Exposure to operational resilience or outsourced service provider requirements (desirable) Familiarity with SOC 2 and cyber assurance testing (desirable) Strategic and analytical mindset Confident working with senior leadership Able to make pragmatic, risk-based decisions Comfortable balancing commercial and security considerations Responsibilities: Lead the organisations security roadmap and long-term strategy Develop and embed policies, standards and procedures aligned with industry best practice Maintain and evolve the Information Security Management Framework (ISMF) Produce clear risk reporting and updates for senior leadership Oversee enterprise-wide security risk assessments Identify, evaluate, and manage risks across systems, products, and processes Support assurance requests and respond to partner security reviews Ensure compliance with UK GDPR, DPA 2018, and internal control frameworks Lead security audits, manage remediation, and track follow-up actions Manage vulnerability scanning programmes, penetration testing, and remediation Oversee incident management processes and escalation procedures Maintain incident response, disaster recovery, and business continuity plans Ensure high standards for access control, monitoring, encryption, and logging Coordinate with external cyber security providers Own the third-party security risk programme Conduct due diligence and ongoing assessments of suppliers Advise stakeholders on vendor risk and control requirements Work closely with the Data Protection lead on DPIAs, data flows, and breach readiness Ensure protection of sensitive, customer, and financial data Act as the primary senior contact for security matters across the business Support security considerations for new services, platforms, and product development Communicate risks in a clear and business-focused manner Oversee the companys security awareness and training initiatives Promote secure-by-design principles Mentor team members involved in security responsibilities Technologies: Cloud Support Security More: We are a rapidly growing tech organisation in the heart of the City of London, committed to building a secure, resilient, and compliant environment as we scale. We specialize in developing modern lending and insurance solutions and are excited to expand our technology function. Our team is forward-thinking, and we are looking for a skilled Information Security Manager to play a pivotal role in shaping our security practices from the ground up. We offer a competitive salary ranging from £55,000 to £65,000 for this full-time, office-based position. last updated 12 week of 2026