Information Security Manager
10 hours ago
Nottingham
Information Security Manager Location: Remote. Glasgow and Manchester office availability Contract: Full-time, permanent Compensation: Details below Reports to: Chief Product Officer Start date: ASAP About Willo Willo is a candidate assessment platform that allows companies to assess candidates anytime, from anywhere. Over the past five years we've been dismantling talent barriers and helping businesses in 195+ countries recruit top talent connecting people with opportunities worldwide in a simple, scalable way. We're a fast-growing, product-led team scaling globally after rapid growth, and we care deeply about delighting every customer and candidate. The role We're hiring a Security Manager to own day-to-day operation of the ISMS and drive continuous improvement of ISO27001 controls. The Security Manager will act as the operational backbone for security governance, compliance, vendor reviews, training, and customer queries. Your responsibilities: ISMS Operation & Compliance • Maintain policies, procedures, evidence, and control operation across all ISO27001 Annex A areas., • Coordinate internal audits, surveillance audits, and support external auditors., • Maintain the risk register, perform routine risk assessments, and execute treatment plans. Customer & Sales Support • Respond to customer security questionnaires., • Conduct DPIAs on new customer projects or unique deployments., • Provide security context for enterprise deals (without acting as DPO or CISO). Supplier & Third-Party Management • Conduct supplier due diligence, • Monitor sub-processors and ensure evidence of ongoing compliance. Incident & Vulnerability Management • Ensure phishing simulations, vulnerability scans, monitoring activities, and alert reviews are conducted in line with policy and schedule., • Track remediation actions and follow up to closure., • Maintain incident logs and ensure lessons learned are documented., • Escalate significant risks or incidents to senior leadership and retained CISO/DPO where required. Training & Awareness • Maintain the security awareness programme, onboarding training, and periodic refreshers Documentation & Administration • Keep ISMS documentation up to date, run quarterly governance meetings, record evidence, file audit documents. What success looks like • The ISMS runs smoothly and evolves with the business – All ISO27001 controls are actively managed. Policies, evidence, and risk registers are current, and audits pass with minimal findings., • Audit-ready always – Surveillance and internal audits are planned, prepped, and delivered confidently. You track actions to closure and collaborate with our retained security partners to ensure compliance momentum., • Security enables revenue – Enterprise customer queries are answered accurately and efficiently. Security no longer blocks deals - it helps close them faster., • Risks are tracked and treated, not hidden – The risk register is maintained and actionable. You regularly review and update assessments and drive treatment plans across departments., • Vulnerabilities are spotted early – Phishing simulations, SOC alerts, and vulnerability scans are run on schedule. You help the business prevent rather than react., • Security awareness – From onboarding to quarterly updates, our team understands how to work securely - without being overwhelmed by policy., • Suppliers and subprocessors stay in check – You oversee due diligence, ensure contracts contain appropriate clauses, and maintain evidence of third-party compliance. What you'll bring Must-haves • 2–6 years’ experience in security operations, compliance, or GRC (governance, risk, compliance)., • Practical familiarity with ISO27001 frameworks - especially managing or maintaining controls across Annex A., • Confident working with auditors, handling evidence, and preparing for external assessments., • Able to interpret and complete customer security questionnaires and due diligence forms., • Experience with risk assessment and treatment planning., • Strong documentation discipline and attention to detail. Nice-to-haves • Exposure to SOC2, NIST, or similar frameworks., • Familiarity with DPIAs, vendor risk management, or security elements of commercial deals., • Experience in SaaS or B2B tech environments., • Understanding of security incident response lifecycle - even if not leading it directly. Compensation & benefits • Base salary: Depending on Experience., • Benefits: Flexibility for remote working, monthly wellness allowance, cycle-to-work scheme, Headspace subscription, quarterly "life admin" days, and standard benefits (pension, holiday, learning budget). The team & ways of working You’ll join the Operations function, working closely with our CEO, CPO (who also acts as TISO), and retained specialists (Head of Security, CISO, DPO, and Audit roles) who support our ISO27001 controls on a quarterly basis. We run a lightweight but high-impact cadence: • Quarterly Governance Meetings – Runbook-driven meetings to review controls, risk register, supplier list, and evidence artefacts., • Monthly Risk or Incident Reviews – Prioritise mitigations, log events, or assess any new vectors., • Always-on Audit Readiness – We maintain our evidence centrally with version control, and file notes after reviews., • Coverage Model – You’re the single in-house security operator but have support from our CPO, CFO and Engineering leads for technical controls. External advisors provide strategic direction and second-line assurance. You’re not alone, but you’ll be the first line of defence. Interview process • Willo interview - asynchronous video interview with assessments., • Hiring manager interview (30 min) - deep dive into experience., • Practical task., • Panel interview (values & cross-functional)., • Offer (subject to references). Equal opportunities Willo is an equal-opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. If you need any adjustments during the interview process, please let us know.