Information Security Manager
We're looking for an Information Security / Governance, Risk & Compliance (GRC) Manager to lead enterprise-wide risk, governance, and assurance across a fast-growing B2B technology business.
This is a senior strategic position with responsibility spanning information security, governance, compliance, quality management, and corporate risk. You'll define how governance is embedded throughout the organisation, ensuring risk is understood, owned, and managed effectively while supporting continued business growth.
Working closely with executive leadership, you'll own the GRC roadmap, oversee certification programmes, strengthen security and compliance frameworks, and advise on emerging areas such as AI governance and sustainability.
Key Responsibilities Governance, Assurance & Compliance- Own major certification and assurance programmes including ISO 27001, ISO 9001, SOC 2 and other recognised frameworks.
- Lead audit planning and execution across multiple standards.
- Manage cyber insurance, regulatory compliance and third-party assurance activities.
- Ensure governance supports enterprise procurement, customer due diligence and contractual security obligations.
- Oversee wider organisational compliance initiatives including sustainability and corporate governance.
- Act as the senior subject matter expert for information security, governance and compliance during enterprise sales opportunities.
- Support customer meetings, executive briefings and strategic partnerships.
- Provide governance and security guidance to Product and Engineering teams to ensure enterprise customer requirements are reflected in product development.
- Build confidence with customers through a strong, commercially focused security and compliance approach.
- Define and continuously improve the organisation's Governance, Risk & Compliance strategy and roadmap.
- Partner with executive leadership to establish and maintain the company's risk appetite.
- Drive a governance-first culture where policies become part of everyday decision making rather than a compliance exercise.
- Own data protection governance across UK GDPR, EU GDPR and other applicable regulations.
- Maintain privacy frameworks including DPIAs, records of processing and international data transfer controls.
- Help shape AI governance, ensuring the responsible, secure and compliant adoption of AI technologies.
- Monitor changes in legislation, regulation and industry standards, translating them into practical business controls.
- Maintain compliance tooling, risk registers and governance reporting across the organisation.
- Partner with Sales, Legal, Finance, HR, Engineering, Product and Operations teams.
- Work directly with auditors, regulators, insurers and enterprise customers.
- Present governance, risk and compliance updates to senior leadership and board-level stakeholders.
- Translate complex security and risk topics into clear, commercially relevant guidance.
Successful candidates will bring strong experience across both security and governance disciplines, including:
Security- Strong understanding of cloud and SaaS security models.
- Experience managing security incidents and post-incident governance.
- Practical implementation of ISO 27001 and SOC 2 within engineering environments.
- Deep understanding of UK GDPR, EU GDPR and wider privacy regulations.
- Knowledge of AI governance, ethics and regulatory considerations.
- Enterprise customer assurance and due diligence.
- Supplier governance and third-party risk management.
- ISO 9001 quality management systems.
- Corporate governance and organisational compliance.
- Risk management frameworks and policy development.
You'll ideally have:
- 5+ years' experience leading Information Security, GRC, Risk or Assurance functions.
- Experience working within a SaaS, software or technology business.
- The ability to influence at executive and board level.
- Relevant certifications such as CISM, CISSP or ISO 27001 Lead Auditor/Lead Implementer (or be working towards them).
- Strong commercial awareness alongside excellent judgement.
- Outstanding communication skills with the ability to influence both technical and non-technical stakeholders.
This is an opportunity to shape the governance strategy of a scaling technology business where security, compliance and trust are viewed as strategic differentiators rather than simply regulatory requirements. You'll work closely with senior leadership, influence company-wide decisions and play a key role in supporting future growth.