Cyber Security Manager
IT Security Manager- Cyber Security Manager – PCI-DSS
Location: Luton, 2 days per week on-site.
Our client, a national organisation with offices near Luton, are seeking an experienced IT Security Manager to lead and enhance their security landscape while owning their Tier 1 PCI-DSS compliance programme. This is a fantastic opportunity for a hands-on security specialist who enjoys operating at both strategic and technical levels, working closely with senior stakeholders to drive security best practice across the organisation.
Reporting to the Head of Technical Delivery, you will be the go-to expert for all aspects of cyber security, governance, risk, and compliance. This is a standalone role offering significant ownership and influence, making it ideal for someone who enjoys autonomy and genuinely shaping an organisation's security strategy.
Key Responsibilities
Cyber Security:
- Develop and continuously improve the organisation's cyber security strategy, controls, and policies.
- Monitor emerging threats and ensure effective protection across endpoint, network, cloud, and identity environments.
- Lead security incident response activities, investigations, and remediation efforts.
- Drive vulnerability management and penetration testing programmes through to successful resolution.
- Act as the internal cyber security subject matter expert.
PCI-DSS Compliance & Audit:
- Take ownership of end-to-end PCI-DSS compliance activities.
- Lead annual audit and attestation processes, working closely with external assessors.
- Manage compliance documentation, evidence gathering, and control frameworks.
- Coordinate with technical and business teams to embed compliance requirements into day-to-day operations.
- Provide compliance reporting and updates to senior stakeholders.
Governance, Risk & Compliance:
- Support wider compliance initiatives including ISO 27001, Cyber Essentials, and GDPR.
- Maintain security policies, standards, and procedures.
- Conduct risk assessments and manage the security risk register.
- Deliver security awareness initiatives across the business.
- Manage relationships with third-party suppliers, security vendors, and auditors.
Essential Skills & Experience
- Proven experience within IT or Cyber Security with ownership of PCI-DSS compliance in a Tier 1 environment.
- Strong understanding of security frameworks, controls, and governance practices.
- Experience managing security incidents, vulnerability remediation, and audit activities.
- Ability to engage confidently with senior stakeholders and external auditors.
- Comfortable working independently and taking ownership of a broad security remit.
Desirable
- CISSP, CISM, CISA, PCI ISA, or similar industry certifications.
- Experience within retail, hospitality, payments, or other highly regulated environments.
- Knowledge of Azure, AWS, and modern SOC/SIEM technologies.
If you're an experienced IT Security Manager, Cyber Security Manager, Information Security Manager, or PCI Compliance Specialist looking for your next challenge, we'd love to hear from you.