Infosec Risk and Compliance Manager
il y a 16 heures
Bournemouth
We have a fantastic opportunity for a strategic and proactive individual to join us as an Information Security Risk and Compliance Manager. You will lead in shaping and enhancing our security risk and compliance strategy. You'll drive key certifications, ensure regulatory alignment, and embed a strong security culture while enabling business success through effective information risk management. We support hybrid working, with a regular presence required at our Bournemouth office. Key Responsibilities -Lead and continuously improve the Information Security Risk Management program, including policies and processes for identifying and assessing risks at tactical and strategic levels. -Manage the delivery of risk assessments, maturity evaluations, gap analyses, and mitigation planning to support business goals and strengthen security posture. -Collaborate with tech, data, and resilience teams to ensure compliance with Cyber Essentials, ISO 27001, NCSC CAF, and other regulatory standards. -Implement and enhance security governance frameworks (e.g., ISO/IEC 27001, NIST CSF) aligned with business and regulatory needs. -Support training and awareness initiatives to foster a strong, security-conscious culture across the organisation. -Contribute to supplier risk assessments and due diligence to ensure third-party compliance with security standards and contractual obligations. -Build strong relationships with internal and external stakeholders, including tech teams, senior business leaders, regulators, and peers. -Deliver clear, data-driven reports on risk, compliance, and control effectiveness to inform senior decision-making and drive improvement. About You -Demonstrated experience in information security, with a strong focus on risk management. -In-depth understanding of risk assessment methodologies and security frameworks, including ISO 27001, NCSC CAF, and NIST CSF. -Proven ability to design and implement security risk management processes that align with broader business risk objectives. -Skilled in drafting, maintaining, and evolving risk management policies and procedures. -Capable of identifying, evaluating, and articulating security risks based on technical data and threat intelligence. -Adept at translating complex technical risks into clear business impacts for non-technical stakeholders. -Strong grasp of evolving threat landscapes and the ability to convert threat data into actionable risk insights. -Experienced in supporting internal and external audits, including managing remediation activities. -Strategic and proactive problem-solver with a hands-on, analytical mindset; committed to continuous improvement and staying current with industry trends. -Effective communicator and collaborator, skilled at engaging stakeholders across technical and non-technical teams, with a strong focus on risk mitigation and innovation. Desirable Skills & Experience -Experience implementing cybersecurity risk management practices within regulated industries (e.g., finance, healthcare, government). -Professional certifications such as CRISC, CISSP, CISM, or ISO 27001 Lead Implementer. -Proven track record in implementing and/or achieving certifications such as NIST CSF, Cyber Essentials Plus, or ISO 27001. -Familiarity with Security Risk Management frameworks and their practical application. -Expertise in managing Information Security Management Systems (ISMS), audit processes, policy lifecycle, and compliance monitoring. -Skilled in developing and maintaining security policies, standards, and guidelines. Rewards & Benefits This role is a Band C in the LV= Structure. At LV= Life and Pensions, you’ll go above and beyond to do the right thing for our customers. We’ll reward your hard work with an attractive, competitive salary and benefits package, which includes: -30 days' holiday. -The opportunity to buy or sell up to two days of holiday. -An annual bonus scheme based on company and personal performance. -Flexible benefits, including a cycle to work scheme, personal accident insurance, critical illness cover, private medical insurance, and dental insurance. -Competitive pension scheme - LV= Life and Pensions will double-match the amount you pay, up to 14% (subject to National Minimum Wage requirements). -Group Life Assurance of four times your basic pay to your dependents (you’ll have the option to increase this to 8 x cover). -Group Income Protection, if you enrol into the pension scheme and reach 5 years of service. -Employee Assistance Programme (EAP) service for support when you need it. -Virtual GP service. -Shared parental leave. -Up to 20% discount on our life products for you and your immediate family. We’re proud of our inclusive culture at LV= and, as an equal-opportunity employer, we continually work to remove unconscious bias from our recruitment process. We value our colleagues for what they bring to our team regardless of any protected status or characteristics they may have. Talk to us about flexible working as part of your application; if it’s right for you, our members and customers, and our business, then we’ll do everything we can to make it happen. Please note that we are unable to offer Skilled Worker Visa Sponsorship for this role. Therefore, you must ensure that you are eligible to work in the UK without our sponsorship for your application to be considered.