Information Security Assurance Manager

2 weeks ago


London, United Kingdom POD People Full time

My client, a UK insurer and innovator in Data, are recruiting an Information Security Assurance Manager. This person must have experience in a similar role and come from an insurance or banking industry background. This role is home based and can be basedanywhere in the UK.

**Purpose of the role**:
Responsible for the formation, management, and delivery of the annual Information Security 2LOD testing plan, reporting and corrective actions oversight. Along with management of the InfoSec documentation this is an essential factor in managing our GroupInformation Security risk. The purpose of this role is to own and develop the underlying Information Security assurance testing processes, documentation, and work streams, thus demonstrating assurance that our controls are effectively mitigating risks. Therole also includes managing and supporting the day-to-day work, via dotted line, of the Information Security Assurance Analyst(s). The role will also provide support to the operational areas of the business in the form of guidance and consultancy on Information& Cyber Security controls, ensuring they are fit for purpose, whilst providing advice and oversight to enable proportionate risk management.

**Responsibilities**
- Responsible for planning, execution, and reporting of the 2LOD assurance reviews of controls, processes, and procedures across group companies, in line with our standards, control frameworks and best practice.
- Responsible for continuous improvement of the information assurance processes.
- Responsible for managing, via dotted line, the day-to-day workload of the

Information Security Assurance Team, ensuring quality of deliverables.
- Responsible for managing the Annual Technical Testing regime, and ad-hoc testing

when required. Liaising with 3rd parties and 1LOD teams as needed.
- Responsible for other testing activities, for instance Phishing Testing, in line with the agreed 2LOD Plan
- Monitor, advise and report on 1LOD remediation actions relating to Penetration

Testing, Vulnerability scanning and other corrective actions.
- Manage regular spot checks to ensure compliance with Group policies & standards.
- Gather and maintain required evidence and assist in the facilitation of external &
internal InfoSec reviews and audits.
- Performing information security risk assessments for projects, processes, software and infrastructure as required. Contribute to the running of the Information Security

risk processes.
- Ongoing management of emerging security threats and identified risks through

regular engagement with control and risk owners.
- Assist in developing suitable frameworks and governance processes to keep FCG

alignment with best practice, including PCI-DSS, ISO27001 and CIS.
- Support the maintenance of the Information Security Management System (ISMS) documentation and records to ensure compliance with chosen frameworks. Ensure that documented internal Information Security standards align with framework requirements.
- Create regular Information Security KPIs, metrics and reporting.
- Assist in the management of Security Incidents as required.
- Raise awareness across the Group regarding Information Security and its

developments, working with the Group Information Security Officer to ensure the

Group companies are protected.
- Contribute to and deliver appropriate security awareness activities as required and

promote good security practice in order to improve InfoSec culture within the Business
- Provide guidance, support, and assistance to the business on Information Security

compliance requirements & related workstreams as required. Ac as a SME on

Information Security compliance.
- Be involved in the development of new systems and promote the benefits of a

robust and secure IT environment ensuring a pragmatic approach to deliver solutions

within short timeframes.
- Identify and communicate any improvements or gaps in InfoSec position across

group
- Comply with the requirements, and act in accordance with, the Group Code of Conduct and Fitness and Propriety policies at all times.
- Ensure compliance with Company Policies, Values and guidelines and other relevant standards/ regulations at all times.
- Any other reasonable duties as required.

**Experience & Knowledge**
- Extensive Information and Cyber Security frameworks and compliance experience.
- Extensive experience with Information Security Control Assessment.
- Experience in undertaking methodical tasks and documenting outcomes in a concise

manner.
- Experience in writing and maintaining documentation.

**Skills & Qualifications**
- Ability to plan, perform, document and report on reviews.
- Suitable qualification, e.g., ISO27001 Lead Implementor and Auditor.
- Strong communication and interpersonal skills, both verbal and written.
- Strong analytical and problem-solving skills
- Strong organisational skills.

**Behaviors**
- Able to demonstrate 2nd Line of Defence thinking and behaviours.
- Willingness to continually develop and learn new Information Security skills.
- Self-motivated and enthusiastic with the desire to meet or exceed targets.
- An organised and pro-active approach to Information Security.
- A flexible approach and positive attitude.
- Emphasis on attention to detail and accuracy.
- Strives to drive business improvements to contribute to the success of the business.



  • London, United Kingdom PIC Full time

    The Information Security Assurance Manager will implement and maintain the information security management system. You will engage with internal and external personnel and drive effective control implementation. You will liaise with 2LOD/3LOD functions to ensure that the information security management system is aligned with the Enterprise Risk Management...


  • London, United Kingdom DAOLaunch Full time

    Information Security Assurance Specialist Copper is looking to hire an Information Security Assurance Specialist to join their team. This is a full-time position that is based in London. Copper - Custody, prime services and collateral management for digital assets. Please let Copper know you found this position on Cryptocurrency Jobs as a way to support...


  • London, United Kingdom Alan Turing Institute Full time

    Named in honour of Alan Turing, the Institute is a place for inspiring, exciting work and we need passionate, sharp, and innovative people who want to use their skills to contribute to our mission to make great leaps in data science and AI research to change the world for the better. Please find more information about us here **Position**: This role works...


  • London, United Kingdom Ministry of Justice Full time

    **Regional Information Security and Assurance Lead - 68904** **£30,812 - £38,289 + London weighting allowance of £4,006** **London**: **Overview of the job** The Regional Information Security and Assurance Officer (RISAL) sits within the Corporate Service function in the Probation Service region and reports directly to the Head of Corporate...


  • London, United Kingdom amber labs Full time

    Job Title: Information Assurance Security Manager About Us: Amber Labs is a dynamic and innovative tech company that is at the forefront of the cloud computing revolution. We specialize in leveraging AWS technologies to create scalable and efficient solutions for our clients. We are seeking a highly skilled Technical Lead to join our team and contribute...


  • London, United Kingdom Information Security Solutions Full time

    Title: Head of Operational Security Reference No: 2181 Company: Online Location: London, UK Reports to CISO Day Rate: TBC Duration 5 months The Role This role reports to the CISO and is part of the security leadership team. The Person: An analytical problem solver with demonstrable long-term experience leading and improving operational security...


  • London, United Kingdom HM Prison & Probation Service Full time

    **Details**: **Reference number**: - 264343**Salary**: - £30,812 - £38,289- (plus a London Weighting Allowance of £4,006)**Job grade**: - Other- NPS Pay Band 4 London**Contract type**: - Permanent**Type of role**: - Administration / Corporate Support**Working pattern**: - Full-time**Number of jobs available**: - 1Contents Location About the...


  • London, United Kingdom Henderson Scott Full time

    **Security Assurance Manager - Remote based - 90k + Bonus - 112k OTE** Global Technology Service Provider are recruiting for an additional Security Assurance Manager to join a well established and successful Security team. The Security Assurance Managers (SAM) are dedicated Information Security resources assigned to large enterprise customers and function...


  • London, United Kingdom LGBT Great Full time

    Job Profile Summary: Join our Information Security team, composed of four specialized teams - Identity and Access Management, Operations, Assurance, and Engineering - dedicated to safeguarding Man Group. Partner with the business and tech departments to construct and refine security measures, employing a data-centric approach to ensure efficacy. Our...


  • City of London, United Kingdom Carrington Recruitment Solutions Ltd Full time

    **Information Security Assurance Analyst, CISM, CISSP, CCSP, Mainly Remote** Information Security Assurance Analyst required to work for a Professional Services organisation based in the City of London. However, due to Covid-19, this will mainly be remote and you will only be required to be in the office a couple of times a month. We need someone who is...


  • London, United Kingdom Robert Walters UK Full time

    My client, a well known Insurance firm are looking for an IT Security Customer Assurance Manager to join their growing team in London About the IT Security Customer Assurance Manager Role: The purpose of this role is to assist in the operation of Technology External Assurance function's focus on Customer Information Security Assurance by the execution...


  • London, Greater London, United Kingdom JR United Kingdom Full time

    Information Assurance Specialist Fully Remote £400 - £500 Outside IR35Summary: The Information Assurance Specialist plays a critical role in safeguarding the confidentiality, integrity, and availability of sensitive information and IT systems within the university environment. This role involves collaborating with various stakeholders to assess risks,...


  • London, United Kingdom Via Resource Full time

    We are working with a global Law Firm looking to bring an experienced Information Security Manager into their organisation to take charge of their Information Security division and help drive change throughout the business. The Information Security Manager will be required to have knowledge of managing the ISMS and be able to develop policies, put controls...


  • London, United Kingdom MARKJAMES SEARCH LTD Full time

    Cyber Security Risk and Assurance Manager £75k-£80k DOE, Plus Bonus & Benefits London - 3 days on site, 2 remote working Our client is currently hiring for a Cyber Security Risk and Assurance Manager to deliver the Information and Cyber Security Risk and Assurance function to enable them to operate effectively and contribute towards...


  • London, United Kingdom MARKJAMES SEARCH LTD Full time

    Cyber Security Risk and Assurance Manager £75k-£80k DOE, Plus Bonus & Benefits London - 3 days on site, 2 remote working Our client is currently hiring for a Cyber Security Risk and Assurance Manager to deliver the Information and Cyber Security Risk and Assurance function to enable them to operate effectively and contribute towards understanding of...


  • London, United Kingdom Office for Nuclear Regulation Full time

    **Details**: **Reference number**: - 348087**Salary**: - £87,659 - £95,620- Plus an additional £8,500 market rate allowance. (Plus, an additional £4,052 London Weighting Allowance if applicable)**Job grade**: - Senior Executive Officer**Contract type**: - Permanent**Business area**: - ONR -Civil Nuclear Security and Safeguards**Type of role**: -...


  • London, United Kingdom AXA Group Full time

    Information Security Assessor Paris, France or London, UK As an information security assessor, your responsibilities will include ensuring the effectiveness of Information Security controls throughout AXA XL, aligning with AXA XL assurance methodologies and frameworks. You will lead end-to-end assurance engagements, contribute to scoping and scheduling...

  • Information Security

    4 weeks ago


    London, United Kingdom amber labs Full time

    Job Title: Information Assurance Security Manager Amber Labs is a dynamic and innovative tech company that is at the forefront of the cloud computing revolution. We specialize in leveraging AWS technologies to create scalable and efficient solutions for our clients. We are seeking a highly skilled Technical Lead to join our team and contribute to the...


  • London, United Kingdom Pontoon Full time

    **Information Security Analyst Financial Services Hybrid in London: 2 days per week onsite average £37,000 - £39,000 per annum** The Information Security Analyst role supports the Information Security Manager to enable business processes and innovative technology to deliver key business objectives in a secure manner which protects our reputation,...


  • London, United Kingdom Department for Transport Full time

    **Details**: **Reference number**: - 307923**Salary**: - £39,428- London Salary: £43,316**Job grade**: - Senior Executive Officer**Contract type**: - Permanent**Business area**: - DFT - Corporate Delivery Group (CDG) - Digital, Information & Security Directorate**Type of role**: - Digital - Risk Management - Security**Working pattern**: - Flexible...