Information Security Manager

2 weeks ago


London, Greater London, United Kingdom Autologyx Limited Full time

We are looking for a hands-on Information Security Professional with extensive practical experience in information security best practices and application in an enterprise cloud SaaS environment. The ideal candidate will have a strong background in AWS, experience with ISO 27001, SOC 2, and the ability to communicate the importance of information security across all business levels.

Who are we and what we do

Autologyx is a leading enterprise in cloud software-as-a-service (SaaS), leveraging cutting-edge technology to deliver exceptional solutions hosted on Amazon AWS. We are committed to maintaining the highest standards of information security to protect our clients and uphold our reputation in the industry. We are seeking a dedicated and experienced Information Security Professional to join our team and lead our information security initiatives.

Autologyx is a data driven workflow and process automation platform that enables businesses to orchestrate, automate, integrate and scale, complex non-linear processes. We allow customers to build and design solutions to automate complex processes. This is achieved by providing the tools to create relational data models, a canvas for designing your workflows and processes, managing task allocation and events which automate actions via an intuitive interface, and integrating 3rd party technology or data sources at any point. All process data at any point in time is captured and made available for analytics on a BI solution of your choice. The Autologyx platform works in real time, managing non-linear, simultaneous processes that reflect the complexity of real-world interactions. Processing over 1 billion process transactions last year, all of this is delivered via enterprise-grade infrastructure with state-of-the-art data security and ability to handle large scale complex processes.

Key ResponsibilitiesInformation Security Management:
  • Lead the implementation and management of the company's Information Security Management System (ISMS) in line with ISO 27001 standards.
  • Migrate the company from ISO 27001:2013 to ISO 27001:2017 standards early in the role.
  • Develop, write, and maintain security policies, procedures, and controls to protect company data and systems.
  • Drive and develop information security processes, ensuring they align with industry best practices and secure-by-design principles.
AWS and Cloud Security:
  • Ensure robust security measures are in place for AWS-hosted applications and services, including S3, EC2, Route53, EBS, RDS, and EKS, as well as Microsoft Azure and Office 365.
  • Conduct regular security assessments, vulnerability management, and penetration testing to identify and mitigate risks.
Security in Development Pipeline:
  • Collaborate closely with Engineering and Product teams to integrate security into the development lifecycle using techniques such as STRIDE threat modeling and security testing (SCA and SAST) in CI/CD pipelines.
  • Promote secure-by-design principles and best practices within the company culture.
Risk Management:
  • Facilitate risk workshops and document information security risks and treatments using tools like Eramba GRC.
  • Monitor the threat landscape and perform regular risk assessments to ensure appropriate controls are in place.
Incident Management:
  • Manage information security incidents and conduct in-depth technical investigations, including log analysis using AWS GuardDuty, AWS CloudWatch, and manual log searches.
  • Coordinate with external vendors for annual penetration tests and ensure timely resolution of identified issues.
Communication and Training:
  • Communicate information security concepts and practices to all levels of the business, including C-Level executives.
  • Conduct security awareness training for employees and promote a culture of security within the organization.
Day-to-Day Auditing and Data Protection:
  • Perform day-to-day auditing of security practices to ensure compliance with internal and external standards.
  • Serve as the company's Data Protection Officer, ensuring compliance with relevant data protection regulations.
Compliance Management:
  • Manage and maintain compliance with SOC 2 standards.
  • Experience with HIPAA and similar standards is a bonus but not required.
Customer Information Security Requests:
  • Respond to customer information security requests, providing accurate and comprehensive information about the company's security posture and practices.
Third-Party Security Assessment:
  • Evaluate and assess the security posture of third-party suppliers and integrations to manage associated risks.
Skills and Experience RequiredTechnical Skills:
Cloud Services:
  • AWS services (S3, EC2, Route53, EBS, RDS, EKS)
  • Kubernetes
  • Microsoft Azure
  • Office 365
Security Tools:
  • AWS GuardDuty
  • AWS CloudWatch
  • Prometheus
  • Grafana
  • HashiCorp Vault
Qualifications
Experience:
  • Minimum of 5 years of experience in Information/Cyber Security, with a focus on AWS services and enterprise cloud environments.
  • Proven track record of migrating from ISO 27001:2013 to ISO 27001:2017 standards.
  • Hands-on practical experience with SOC 2 standards.
  • Experience with HIPAA or similar standards is a bonus but not required.
Certifications:
  • Systems Security Certified Practitioner (SSCP) - (ISC)²
  • Certified DevSecOps Professional (CDP) - Practical DevSecOps
  • Certified ScrumMaster (CSM) - Scrum Alliance
Education:
  • BSc Hons Degree in Computer Science or related field.
#J-18808-Ljbffr

  • London, Greater London, United Kingdom Concept Information Technology Full time

    Social network you want to login/join with:Information Security and Assurance Advisor, Warwickshirecol-narrow-leftLocation:Warwickshire, United KingdomJob Category:Information TechnologyEU work permit required:Yescol-narrow-rightJob Reference:BBBH75954_1745571910Job Views:6Posted:25.04.2025Expiry Date:09.06.2025col-wideJob Description:Information Security...


  • London, Greater London, United Kingdom Silver Birch Rec Ltd TA Etech Partners Full time

    My client is a leading organisation in the renewables sector seeking an experienced Information Security Manager.For this opportunity, you must have experience maintaining information security frameworks, e.g., ISO27001, within a medium/large-sized organisation.Hybrid/Flexible working including a 4-day working week.What you will do:Develop Information...


  • London, Greater London, United Kingdom Jas Gujral Full time

    Information Security ManagerRole DescriptionThis is a full-time role as an Information Security Manager for a bank in Central London. The Information Security Manager will be responsible for day-to-day tasks related to information security management, including implementing and maintaining Information Security Management Systems (ISMS), ensuring...


  • London, Greater London, United Kingdom Lorien Full time

    Information Security Manager (Inside IR35)Are you an experienced Information Security professional looking for a new long term contract? We are partnered with a government organisation looking for an Information Security Manager to join on a long term contract. This would require the successful candidate to undergo DV clearance before starting, which can...


  • London, Greater London, United Kingdom JAM IT Consultancy Ltd Full time

    Information Security Manager (SOC Manager), Berkshire, Information Security, CCIE, Degree Educated. £90-100k, Berkshire, Cloud, SaaS, UcaaS, Contact Center. Degree and Professional Qualifications.Overview: The Information Security Manager leads the Security Operations Centre (SOC) function and provides support to the CISO on technical security. Proposes and...


  • London, Greater London, United Kingdom Robert Walters UK Full time

    Information Security Manager (must come from start up/FinTech)My client, an international FS client of mine based in London, are looking for an Information Security Manager to join their growing team. The must skillset to have is come from a start up/fintech background and hold a CISSP. This role is hybrid, 3 days per week in the office - Tuesdays being...


  • London, Greater London, United Kingdom Robert Walters UK Full time

    Information Security Manager (must come from start up/FinTech)My client, an international FS client of mine based in London, are looking for an Information Security Manager to join their growing team. The must skillset to have is come from a start up/fintech background and hold a CISSP. This role is hybrid, 3 days per week in the office - Tuesdays being...


  • London, Greater London, United Kingdom TN United Kingdom Full time

    Social network you want to login/join with:Are you an immediately available IT Security Manager who can support Honda's global security team on IT security governance and operation initiatives?This initial 6 month contract will be based at Bracknell, Berkshire with occasional travel to Europe.Main Responsibilities:Coordinate IT security operational...


  • London, Greater London, United Kingdom Insight Global Full time

    The Information Security Manager is responsible for designing, implementing, and enhancing a comprehensive technology compliance and risk management program to bolster the organization's security posture. This role involves continuous assessment, reporting, and improvement of technology risks and compliance activities across global operations. You will serve...


  • London, Greater London, United Kingdom Ventula Consulting Full time

    Information Security Operations Manager – UK Wide (3 Days per Week) - Up to £65,000paOne of the UK's leading providers of critical UK logistics infrastructure requires an experienced Information Security Operations Manager to join a dynamic, group-wide technology team.This is a key role responsible for leading security operations and ensuring the...