Security Manager
9 days ago
London
Information Security Manager Location: City of LondonSalary: £55,000 - £65,000Hours: Full-time, Office-basedDepartment: Technology / Security About the Company A rapidly growing tech organisation is expanding its technology function and looking for a skilled Information Security Manager to strengthen its security posture. The business develops modern lending and insurance solutions and is committed to building a secure, resilient, and compliant environment as it scales. This is an exciting opportunity to join a forward-thinking company where you will play a pivotal role in shaping security practices from the ground up. The Role The Information Security Manager will take full ownership of the organisation's security framework, driving the development of policies, governance structures, and risk management processes. This position involves partnering closely with senior leaders, supporting operational resilience, and ensuring the organisation meets regulatory expectations through strong controls, robust documentation, and security-by-design thinking. Rather than a purely technical position, this is a strategic and advisory role, offering influence across the entire business. Key Responsibilities Security Strategy & Governance • Lead the organisation's security roadmap and long-term strategy, • Develop and embed policies, standards and procedures aligned with industry best practice, • Maintain and evolve the Information Security Management Framework (ISMF), • Oversee enterprise-wide security risk assessments, • Identify, evaluate, and manage risks across systems, products, and processes, • Support assurance requests and respond to partner security reviews, • Ensure compliance with UK GDPR, DPA 2018, and internal control frameworks, • Manage vulnerability scanning programmes, penetration testing, and remediation, • Oversee incident management processes and escalation procedures, • Maintain incident response, disaster recovery, and business continuity plans, • Ensure high standards for access control, monitoring, encryption, and logging, • Own the third-party security risk programme, • Conduct due diligence and ongoing assessments of suppliers, • Work closely with the Data Protection lead on DPIAs, data flows, and breach readiness, • Act as the primary senior contact for security matters across the business, • Support security considerations for new services, platforms, and product development, • Oversee the company's security awareness and training initiatives, • Promote secure-by-design principles Qualifications • Degree in Cyber Security, Computer Science, IT or equivalent experience Essential: • Strong experience in senior information security or cybersecurity roles, • Proven track record in building or owning security governance frameworks, • Knowledge of cloud security and SaaS environments, • Understanding of cyber risk, GDPR, and data protection principles, • Experience working with regulated partners or in regulated industries, • Experience leading or maturing ISO 27001 programmes, • Exposure to operational resilience or outsourced service provider requirements, • Strategic and analytical mindset, • Confident working with senior leadership, • Able to make pragmatic, risk-based decisions By applying for this role your details will be submitted to Adecco. Our Candidate Privacy Information Statement explaining how we will use your information is available on our website.