Information Security Manager
Information Security Manager - Liverpool - £55,000-£65,000 The Information Security Manager is responsible for the operational delivery, maintenance, and continuous improvement of the organisation's information security framework.The role ensures that information assets, systems, and services are appropriately protected against internal and external threats, while maintaining compliance with regulatory, legal, and internal policy requirements.Reporting to the Head of Information Security & Continuity, the role plays a key part in embedding a strong security culture, managing security risk, and ensuring effective response to cyber incidents. The Information Security Manager works closely with Technology, Risk, Compliance, and business teams to ensure that security controls are proportionate, effective, and aligned to business objectives.Core Responsibilities Support the development, implementation, and ongoing maintenance of the Information Security Management System (ISMS) aligned to ISO 27001Implement and enforce information security policies, standards, and procedures across the organisationConduct security risk assessments, ensuring risks are identified, assessed, and managed through appropriate controlsMaintain and track remediation of vulnerabilities and audit findingsMonitor the threat landscape and coordinate responses to emerging risks and vulnerabilitiesLead the investigation and response to information security incidents, ensuring lessons learned and improvements are implementedSupport internal and external audits, including ISO 27001 certification and surveillance activitiesManage third-party and supplier security risk assessments and assurance processesWork with IT and project teams to ensure security is embedded into system design, development, and change management processesDeliver and continuously improve the organisation's security awareness and training programmeEnsure compliance with regulatory requirements, including FCA expectations and data protection legislation (GDPR)Provide regular reporting on security risk, incidents, control effectiveness, and compliance status
Essential Experience Demonstrable experience in an Information Security or Cyber Security role within a corporate environmentStrong working knowledge of information security frameworks and standards (e.g. ISO 27001, NIST Cyber Security Framework)Experience in conducting risk assessments and implementing effective security controlsHands-on experience in incident response, investigation, and resolutionExperience supporting internal and external audits and compliance activitiesExperience managing third-party security risk or supplier assurance processesAbility to translate technical risks into clear business impact for stakeholdersStrong communication, stakeholder engagement, and organisational skillsUnderstanding of fundamentals of IT Infrastructure Desirable Experience Experience working within financial services or regulated environmentsExperience with cloud security (e.g. Azure, AWS)Familiarity with SIEM, vulnerability management, and endpoint security toolsUnderstanding of data protection and GDPR requirementsEssential QualificationsDegree or equivalent professional experience in a relevant fieldIndustry certifications such as CISSP, CISM, or equivalent (desirable)ISO 27001 Lead Implementer or Auditor (desirable)