organization's informationsecurity policies, standards, and procedures in alignment with business objectives, while considering operational needs. Direct the management and continuous improvement of the InformationSecurityManagementSystem (ISMS). Oversee and manage Ravelin's PCI DSS and PCI 3DS compliance program, ensuring requirements are fulfilled, maintained, and areas for enhancement are identified. Conduct routine risk assessments to determine More ❯
Altrincham, England, United Kingdom Hybrid / WFH Options
Heywood
as developing supporting policies and procedures required to meet the strategy Develop, maintain, and expand the Cyber Risk Management Framework as part of the overall InformationSecurityManagementSystem (“ISMS”) Responsible for the Company’s informationsecurity capabilities, including the technical training and awareness of colleagues, ensuring it remains prepared against an ever-changing threat landscape Work with the other More ❯
the future of InfoSec in a scaling B2B SaaS business that takes its security responsibilities seriously. What You'll Do InformationSecurity Leadership Own and evolve our ISMS (InformationSecurityManagementSystem), ensuring it remains fit for purpose as we scale. Maintain and advance compliance across ISO 27001, SOC2, Cyber Essentials, GDPR, and any emerging frameworks (e.g. PCI DSS, AI More ❯
The opportunity We're looking for an InformationSecurity Manager to take ownership of Attest's security posture as we scale. Our consumer research platform helps brands make better decisions,keeping our data, people, and customers secure is critical to More ❯
website Role Overview We're looking for a pragmatic, risk focussed InformationSecurity Manager to work within Nest and maintain our ISO 27001 certified corporation InformationSecurityManagementSystem (ISMS). We sit in the second line of defence and advise the business on security risks, incidents, audits, assurance and the implementation and monitoring of security controls that protects Nest. … as part of the second line of defence in the Risk and Compliance directorate. It is accountable for the development, implementation and on-going maintenance of the ISMS (InformationSecurityManagementSystem) processes across Nest Corporation and the Scheme Arrangement outsourced providers in alignment with ISO27001. The InformationSecurity Manager - Corporation reports into the Head of InformationSecurity and is … responsible for ensuring that Nest's InformationSecurityManagementSystem is operated for the Corporation, enabling the first line business teams to deliver business objectives in line with the agreed risk appetite. This role will work across all internal Nest departments, programmes, projects and initiatives, providing oversight, support and challenge. Organisational Overview Nest is an award-winning workplace pension scheme More ❯
bank in Central London. The InformationSecurity Manager will be responsible for day-to-day tasks related to informationsecuritymanagement, including implementing and maintaining InformationSecurityManagement Systems (ISMS), ensuring cybersecurity and network security, and protecting sensitive information. This is a hybrid role, based in London with the flexibility for some remote work. Qualifications InformationSecurityManagement, ISMS, and … Cybersecurity skills Network Security and InformationSecurity knowledge Experience in implementing and maintaining ISMS Proficient in identifying and addressing informationsecurity vulnerabilities Strong analytical and problem-solving skills Excellent communication and interpersonal skills Certifications such as CISSP, CISM, or equivalent are preferred Bachelor's degree in InformationSecurity, Computer Science, or related field Additional Skills Strong hands-on network and More ❯
the development and implementation of securitymanagement processes for a new, high-profile service. This role will be instrumental in establishing and integrating a comprehensive InformationSecurityManagementSystem (ISMS) aligned with multiple industry standards and frameworks. This is a fully remote position, offering flexibility while working on a critical and impactful programme. As the role involves working with sensitive … clearance or holding active SC clearance is essential. Key Responsibilities: Lead the design and implementation of securitymanagement processes for a new service offering. Develop and maintain a unified ISMS aligned with ISO/IEC 27001, NIST, PRISMA, and CoBIT frameworks. Conduct gap analyses and risk assessments to ensure compliance with relevant security standards and regulatory requirements. Collaborate with stakeholders … Proven experience in information assurance, cyber security, or risk management roles. Strong knowledge and practical experience with ISO27001, NIST, PRISMA, and CoBIT frameworks. Demonstrated ability to design and implement ISMS in complex, multi-stakeholder environments. Excellent communication and stakeholder engagement skills. Relevant certifications such as CISSP, CISM, ISO27001 Lead Implementer/Auditor, or equivalent. Eligibility for SC clearance or active More ❯
Cambridge, Cambridgeshire, United Kingdom Hybrid / WFH Options
Futureshaper.com
defend against cyberattacks Proactive maintenance and continuous improvement of the Cyber SecurityManagementSystem to ensure effective protection and resilience is maintained Management and continuous improvement of the InformationSecurityManagementSystem that is in place. Proactive assessment of informationsecurity risks and resolution of issues as required in collaboration with Data Privacy Counsel and the Legal team. This will More ❯
Bristol, England, United Kingdom Hybrid / WFH Options
Alexander Mae (Bristol) Ltd
IEC 27001 , ISO/IEC 42001 and Cyber Essentials PLUS standards. In this role you will be responsible for maintaining, auditing, and continuously improving their InformationSecurityManagementSystem (ISMS), overseeing compliance initiatives, coordinating with internal teams, and ensuring the organization remains audit-ready. Additionally you will be implementing (alongside the technical and sales team) a Compliance as a Service … maintain their ISO Certifications. Key Responsibilities: Instrumental in the building of a new Team to deliver CaaS and supporting services. Develop, implement, and maintain the InformationSecurityManagementSystem (ISMS) aligned with ISO/IEC 27001 and Cyber Essentials PLUS standards. Lead internal audits, gap assessments, and risk assessments for ISO 27001 and Cyber Essentials PLUS. Coordinate and manage external … Statement of Applicability (SoA) , Risk Treatment Plans , and supporting documentation. Identify compliance gaps and lead remediation activities. Oversee incident management, business continuity, and data protection processes as part of ISMS requirements. Stay current on changes to ISO 27001 and Cyber Essentials PLUS frameworks, regulatory expectations, and cybersecurity threats. Develop and deliver security and compliance awareness training across the organisation. Collaborate More ❯
Bristol, Avon, South West, United Kingdom Hybrid / WFH Options
Alexander Mae (Bristol) Ltd
IEC 27001 , ISO/IEC 42001 and Cyber Essentials PLUS standards. In this role you will be responsible for maintaining, auditing, and continuously improving their InformationSecurityManagementSystem (ISMS), overseeing compliance initiatives, coordinating with internal teams, and ensuring the organization remains audit-ready. Additionally you will be implementing (alongside the technical and sales team) a Compliance as a Service … maintain their ISO Certifications. Key Responsibilities: Instrumental in the building of a new Team to deliver CaaS and supporting services. Develop, implement, and maintain the InformationSecurityManagementSystem (ISMS) aligned with ISO/IEC 27001 and Cyber Essentials PLUS standards. Lead internal audits, gap assessments, and risk assessments for ISO 27001 and Cyber Essentials PLUS. Coordinate and manage external … Statement of Applicability (SoA) , Risk Treatment Plans , and supporting documentation. Identify compliance gaps and lead remediation activities. Oversee incident management, business continuity, and data protection processes as part of ISMS requirements. Stay current on changes to ISO 27001 and Cyber Essentials PLUS frameworks, regulatory expectations, and cybersecurity threats. Develop and deliver security and compliance awareness training across the organisation. Collaborate More ❯
Southampton, England, United Kingdom Hybrid / WFH Options
Ventula Consulting
recognised security qualification (e.g., CISMP, GSEC, Level 4+ apprenticeship) Strong communication skills and the ability to work independently Comfortable working across multiple sites (occasional UK travel required) Familiarity with ISMS, GDPR, NIS, and ITIL frameworks This role is hybrid with 3 days per week onsite in Southampton . If you're an experienced SOC Analyst ready to join a Microsoft More ❯
recognised security qualification (e.g., CISMP, GSEC, Level 4+ apprenticeship) Strong communication skills and the ability to work independently Comfortable working across multiple sites (occasional UK travel required) Familiarity with ISMS, GDPR, NIS, and ITIL frameworks This role is hybrid with 3 days per week onsite in London. If you're an experienced SOC Analyst ready to join a Microsoft-centric More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Ventula Consulting
recognised security qualification (e.g., CISMP, GSEC, Level 4+ apprenticeship) Strong communication skills and the ability to work independently Comfortable working across multiple sites (occasional UK travel required) Familiarity with ISMS, GDPR, NIS, and ITIL frameworks This role is hybrid with 3 days per week onsite in London. If you're an experienced SOC Analyst ready to join a Microsoft-centric More ❯
Kingston upon Hull, England Metropolitan Area, United Kingdom Hybrid / WFH Options
Ventula Consulting
recognised security qualification (e.g., CISMP, GSEC, Level 4+ apprenticeship) Strong communication skills and the ability to work independently Comfortable working across multiple sites (occasional UK travel required) Familiarity with ISMS, GDPR, NIS, and ITIL frameworks This role is hybrid with 3 days per week onsite in Hull. If you're an experienced SOC Analyst ready to join a Microsoft-centric More ❯
Cheltenham, Gloucestershire, United Kingdom Hybrid / WFH Options
Spirax-Sarco Engineering
a key ambassador for IT assurance and controls, sharing best practices and ensuring delivery of actions. Supporting the maintenance and development of the Group's InformationSecurityManagementSystem (ISMS). Leading compliance assessments and maintaining a central repository of security and compliance documentation. Coaching team members and colleagues on IT General Controls and assurance practices. Your previous experience is … likely to include . Proven experience leading IT assurance programmes. Substantial experience in security assessments and compliance oversight. Familiarity with ISMS and frameworks such as ISO 27001, NIST CSF, CIS Controls, or SCF. Understanding of cloud security, third-party risk, and regulatory standards (e.g., GDPR, UK DPA2018). Experience using GRC tools for internal and third-party risk management. Desirable More ❯
Ripponden, Yorkshire, United Kingdom Hybrid / WFH Options
JLA Limited
Location Hybrid/3 days in the office (Ripponden) Salary £55,000 - £65,000 depending on experience Vacancy Type Permanent/Full Time Job Profile Job Profile document Job Description Job title Data Protection Manager Function Legal Location Ripponden Reports More ❯
development of service features and the Framework used by thousands of organisations, including developing a relationship between the controls framework and contemporary contextual cybersecurity risks. Developing and operating our ISMS, and all that this entails: You will also be responsible for maintaining our ISO 27001 and Cyber Essentials certifications-and other security-related compliance accreditations as may be required. We More ❯
development of service features and the Framework used by thousands of organisations, including developing a relationship between the controls framework and contemporary contextual cybersecurity risks. Developing and operating our ISMS, and all that this entails: You will also be responsible for maintaining our ISO 27001 and Cyber Essentials certifications-and other security-related compliance accreditations as may be required. We More ❯
Havant, Hampshire, United Kingdom Hybrid / WFH Options
Reed Technology
FTC (with likely extension to permanent) Salary: 50 - 53K plus benefits We are seeking a Cyber Security Specialist to lead the implementation of a new InformationSecurityManagementSystem (ISMS) and ensure compliance with security standards. This role is crucial in driving security improvements, managing risks, and maintaining regulatory compliance within a dynamic IT environment of circa 500 IT users. … Key Accountabilities: * Lead the implementation of a new ISMS, ensuring alignment with industry security standards. * Develop and maintain cyber security policies, procedures, and risk management frameworks. * Manage compliance with cyber security regulations, standards, and frameworks (ISO27001, CAF/eCAF, Cyber Essentials Plus). * Implement and manage security monitoring tools to detect and respond to security events. * Identify and assess securityMore ❯
Havant, Hampshire, South East, United Kingdom Hybrid / WFH Options
Reed Technology
FTC (with likely extension to permanent) Salary: 50 - 53K plus benefits We are seeking a Cyber Security Specialist to lead the implementation of a new InformationSecurityManagementSystem (ISMS) and ensure compliance with security standards. This role is crucial in driving security improvements, managing risks, and maintaining regulatory compliance within a dynamic IT environment of circa 500 IT users. … Key Accountabilities: * Lead the implementation of a new ISMS, ensuring alignment with industry security standards. * Develop and maintain cyber security policies, procedures, and risk management frameworks. * Manage compliance with cyber security regulations, standards, and frameworks (ISO27001, CAF/eCAF, Cyber Essentials Plus). * Implement and manage security monitoring tools to detect and respond to security events. * Identify and assess securityMore ❯
Milton Keynes, Buckinghamshire, United Kingdom Hybrid / WFH Options
Allica Bank
providers. Department Description Allica's security team plays a crucial role in maintaining the integrity and security of the company's information systems. They ensure that the ISMS (InformationSecurityManagementSystem) controls are not only up to date but also effectively embedded across all departments. This requires a proactive approach and close collaboration with various teams, such as Engineering More ❯
Worthing, Sussex, United Kingdom Hybrid / WFH Options
NHS
proactive response to network errors and performance issues Provide and maintain evidence to support informationsecurity reviews and best practice including the information governance toolkit and the ISO27001 InformationSecurityManagementSystem Communication Required to explain complex IT issues to non-IT staff ensuring that understanding is gained. May be required to run training or lead presentations for non IM More ❯
Brighton, Sussex, United Kingdom Hybrid / WFH Options
NHS
proactive response to network errors and performance issues Provide and maintain evidence to support informationsecurity reviews and best practice including the information governance toolkit and the ISO27001 InformationSecurityManagementSystem Communication Required to explain complex IT issues to non-IT staff ensuring that understanding is gained. May be required to run training or lead presentations for non IM More ❯
Act as the primary InfoSec lead, partnering with senior stakeholders across the business Drive cyber risk awareness, governance, and strategic security improvements Lead the design and maintenance of the ISMS in alignment with ISO27001 Support compliance with regulatory frameworks, including NIST and NIS2 Embed security into enterprise and cloud architecture (AWS/Azure) Maintain security policies, resilience plans, and data More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Cititec
Act as the primary InfoSec lead, partnering with senior stakeholders across the business Drive cyber risk awareness, governance, and strategic security improvements Lead the design and maintenance of the ISMS in alignment with ISO27001 Support compliance with regulatory frameworks, including NIST and NIS2 Embed security into enterprise and cloud architecture (AWS/Azure) Maintain security policies, resilience plans, and data More ❯