Information Security and Risk Manager
4 days ago
Role:
Information Security and Risk Manager
Location:
Aberford Leeds
Contract:
Permanent
Working:
Hybrid 3 days in the office
As MICHELIN Connected Fleet, a division of the Michelin Group, leader in sustainable mobility for 130 years, we specialise in connected fleet management services and solutions. We are a market leader with over 30 years expertise in a high-growth, competitive mobility technology industry. Today we serve 70,000 customers and over 600,000 vehicles globally, growing more than 10% per year, and entering at the rate of 3 new markets a year. Backed by Michelin Group and operating under the Michelin Connected Fleet name, we intend to be a major player in this market in the coming years.
OUR DREAM
We know our planet is at risk and we urgently need to find innovative ways to protect it. At Michelin, pioneering is what we do: We are innovating constantly, to explore new opportunities, with, around and beyond tires to lead the way in sustainable mobility. Our people act for change, with respect, and as leaders. We care about giving people a better way forward. Our dream is rooted in a single purpose: by 2050, Michelin will be recognised as a critical innovation leader that helped humanity conquer new frontiers. And we all work hard every day to realise this dream.
OUR PEOPLE & WAYS OF WORKING
At MICHELIN Connected Fleet, agility is not a word - it's a lifestyle. We gather entrepreneurial minds who are not afraid to fail fast and learn quickly, every day. We think long term and act short term, we grow fast and love what we do. We believe in an inclusive working environment, building teams with a variety of backgrounds, skills, views and opinions. Among our 400 employees in Europe, we proudly benefit from around 30 nationalities. We thrive because of the diverse background and talent of our people. We nurture our team's growth with several company wide development programs - including our Diversity, Mentoring and Sustainability programs.
THE ROLE IN SHORT:
As the Information Security and Risk Manager, you are the central leader responsible for the company's overall security and compliance posture. You will manage the entire Information Security Management System (ISMS), ensuring the continuous maintenance of the ISO 27001 standard and leading the comprehensive risk management program.
Your duties include coordinating internal and external audits, ensuring effective tracking of strategic security objectives and KPIs, and overseeing all security incident response and resolution efforts.
WHAT WILL I BE DOING:
- Lead and manage the end-to-end Information Security Management System (ISMS), ensuring continued ISO 27001 compliance.
- Drive information risk management across the organisation, including identification, assessment, treatment, and ongoing tracking of risks, non-compliances, and associated action plans.
- Coordinate Information Asset Owners (IAOs) to review the ISMS, maintain up-to-date asset profiles, and ensure all major risks have defined treatment plans.
- Manage security incidents, taking responsibility for investigation, resolution, post-incident reporting, and leading ad-hoc response teams during critical situations.
- Develop and implement strategies for raising information security awareness, including creating and disseminating training materials (in-person, e-learning, and intranet).
- Organise and coordinate security audits (internal, external, customer, and penetration tests), manage the collection of evidence, and track findings through to resolution.
- Animate "Security by Design" meetings and review proposed architectures with engineering teams from a security perspective.
- Provide expert advice to senior management on the organisation's information risk profile and the status of risk treatments.
- Manage and update all essential ISMS documentation, including translation (French), and ensure maintenance of the ISMS and related projects (e.g., Jira).
- Regularly audit information systems and business processes, assessing risks, internal controls, and compliance with relevant laws and statutes to drive continuous improvement.
TO BE SUCCESSFUL YOU WILL LIKELY HAVE:
- A spirit of analysis and being proactive in solving problems or internal dysfunction.
- Have good communication skills and be a good teacher
- Ability to work independently and with ad hoc teams
- Rigour, precision and attention to details
- Writing skills
- Ensuring technological and regulatory watch
- IT tools skills (Microsoft Office/Google Workspace/Jira)
- Policies and procedures related to information security, in particular ISO 27001
- Project management techniques
- Control of the audit activity: procedure, implementation, management and control missions
- Specific experience with Quantitative Risk Analysis methodologies
- Knowledge of core security controls and technologies across domains (network, cloud, application)
- Experience defining, collecting, and visualizing Key Performance Indicators (KPIs)
- Fluent and technical English, French is a plus
Work life balance is important to us at Michelin Connected Fleet, so we offer our teams as much flexibility as possible in line with the needs of their role. We trust our teams to know how they work best, combining remote and collaborative working, with a flexible approach to hours. This allows our people the time and space for life outside of work.
-
Information Security Risk Officer
2 weeks ago
Leeds, United Kingdom La Fosse Associates Full time**Information Security Risk Officer - Permanent - Leeds** Reporting into the Senior Security Manager, this role will play a key role in the development of my client's security posture / journey. This is a fantastic opportunity to join a financially secure and growing business, in which you will have the autonomy to shape their Security function. **Skill...
-
Chief Information Security Officer
2 weeks ago
London Area, United Kingdom Department for Energy Security and Net Zero Full time £90,000 - £120,000 per yearJob summaryThe Chief Information Security Officer will create an environment and culture that ensures security of information and technology for ICS and DSIT and DESNZ, our partner departments. You will enable the organisations to achieve their objectives and drive innovation in services and leverage new technologies in a safe and secure way. The chief...
-
Senior Cyber Security Risk Manager
2 weeks ago
Leeds, United Kingdom Page Personnel Full timeOpportunity to be a part of the MHRA's Technology & Operations function in LeedsPermanent role with hybrid workingAbout Our ClientThe Medicines and Healthcare products Regulatory Agency enhance and improve the health of millions of people every day through the effective regulation of medicines and medical devices, underpinned by science and research. The...
-
Information Security Manager
14 hours ago
Greater Bristol Area, United Kingdom NCC – Innovating for Industry Full timeInformation Security ManagerNCCLocation:Bristol based with Hybrid working – 2 days on site, 3 days homeSalary:£54,102 to £67,056 per annum (experience dependent)Government Security Clearance:You will be required to undertake government security clearance if successful securing this role. Please only apply if willing to undertake clearance process.Closing...
-
Leeds, United Kingdom Turner & Townsend Full timeCompany Description - At Turner & Townsend we’re passionate about making the difference. That means delivering better outcomes for our clients, helping our people to realize their potential, and doing our part to create a prosperous society._ - Every day we help our major global clients deliver ambitious and highly technical projects, in over 110 offices...
-
Leeds, United Kingdom Turner & Townsend Full time**Company Description**: - At Turner & Townsend we’re passionate about making the difference. That means delivering better outcomes for our clients, helping our people to realize their potential, and doing our part to create a prosperous society._ - Every day we help our major global clients deliver ambitious and highly technical projects, in over 110...
-
IT Information Security Manager
1 week ago
Leeds, United Kingdom FashionJobs Full timeINTRODUCTION We believe creativity opens spaces. Our purpose is to unlock the power of imagination to push boundaries and open new possibilities for our people, our customers, and our communities. Grounded in our heritage and culture, it underpins thechoices we make for Burberry today and informs our long-term goals. At Burberry, we have always sought to...
-
London Area, United Kingdom ivee | The job platform for everyone else Full timePlease note:Thanks for your interest in this role - just to be clear, this is not a job working at ivee.This is a live role with a client, listed through ivee.ivee is exclusively for people restarting, pivoting, or returning to work within the UK. Please do not apply if you are outside the UK.Have you taken a career break or are you looking to pivot into...
-
Information Technology Audit Manager
2 days ago
London Area, United Kingdom Audit & Risk Recruitment Full time £80,000 - £120,000 per yearAudit and Risk Recruitmentareexclusivelysupporting a client that is part of a FTSE 100 organisation during an exciting period of change and transformation. This role offers a unique opportunity for an experienced IT Audit professional to take a leading role in shaping the IT Audit plan, providing assurance over a high-profile business merger, and supporting...
-
Senior Information Security Officer
1 week ago
Greater London, United Kingdom Cyber Security training courses Full timeYour new role - Permanent - ON SITE 5 Days per week. You will be required to undergo vigorous onboarding checks - UK Only. Sponsorship NOT available. The main purpose of this job mainly focusses on information security, cybersecurity, and data security from a Greenfield perspective. We are on a journey to secure Cyber Essentials plus and ISO27001...