Information Security Framework Manager

2 days ago


London, United Kingdom Lorien Full time

**Role specific**
This role works strategically across UKT and the Bank to lead the embedding and maintenance of the Information Security framework ('ISMS'). This is a senior role within our Information Security Privacy, Policy and Awareness Team with accountability for thedesign, implementation and continual improvement of the ISMS and its underpinning processes. The role has a direct report. The main purpose of the Information Security Framework Manager role is to:

- Responsible for the embedding and continual improvement of the ISMS, ensuring its effective design and operation in the Bank;
- Maintaining oversight of ISMS effectiveness in line with Framework Owner responsibilities in the Bank's Risk Management Framework and monitoring business performance against information security controls, including maintaining effective framework performancemetrics (KCIs), coordinating and presenting effective risk scorecards and quarterly management reports at the Data Governance Committee, to ensure and support the Committee's oversight of the ISMS and influence decision making on areas requiring focus or improvement;
- Influencing business priorities and control owner plans for information security improvements and risk mitigation;
- Influencing across the Bank, including senior management, to ensure clear ownership and accountability for information security controls
- Ensure the clear design and articulation of information security controls which align to the Bank's legal, regulatory and business needs
- Influencing the effective integration and ongoing alignment of the information security framework with the Bank's Risk Management Framework and operational risk processes
- Responsible for creating and maintaining the Information Security policy, ISMS, Control Standards and instructions, and for the effective planning, prioritisation and delivery of their review cycles to ensure the framework is kept up to date, aligns toUK legal, regulatory and good practice requirements and Bank's global minimum standard for information security;
- Manage the planning and delivery of the team's Information Security Framework business plan, including effectively leading and developing team members, managing any changes, new demands, requirements, or issues and providing regular status/delivery performancereports to management as required;
- Provide specialist information security policy advice, support and challenge to stakeholders across the Bank, and represent the Information Security team with Business stakeholders as a trusted advisor, finding cost-effective security solutions that efficientlysupport customer needs;
- Support the continued development of specialist information security technical knowledge within the UK Information Security team;
- Act as lead Duty Incident Manager on a shared rota basis to manage information security and personal data breaches in accordance with defined incident management processes, ensuring impacts and risks are appropriately identified, assessed and mitigated;
- Deputise for elements of the reporting manager's role (Privacy, Policy & Awareness Manager) as required, on an ad-hoc basis, to cover absences, periods of increased workload, etc

**Key Skills**:

- solid experience embedding, managing and operating an information security framework / ISMS
- able to influence decision making to surface and mitigate issues and risks across a wide range of stakeholders, up to and including senior management / executive
- lead, manage and develop other colleagues, including wellbeing and performance of a team;
- prioritise and deliver competing priorities and manage stakeholders effectively
- own and / or oversight the delivery of key processes and/or improvement projects
- take responsibility and act autonomously;
- plan, organise and prioritise tasks and projects;
- have the ability to solve problems creatively and effectively;
- be a strong team player;
- be able to interact proactively and confidently with all areas of business, including senior management
- have excellent interpersonal and communication skills in both written and spoken English;
- ability to successfully communicate complex data protection requirements to non-technical stakeholders
- pragmatic, and effectively balances risk and control requirements with commercial drivers and customer outcomes
- positive, collaborative and builds and maintains effective cross functional relationships

Carbon60, Lorien & SRG - The Impellam Group STEM Portfolio are acting as an Employment Business in relation to this vacancy.



  • London, United Kingdom Information Security Solutions Full time

    Company: Financial Services Location: Hybrid - City of London Reports to Information Risk Manager **Salary**: £80,000 Benefits: Generous No. Required: 1 Start Date: ASAP **The Role** As the Information Security Risk Specialist, you shall support the Information Risk Manager which has responsibility for all Governance Risk and Compliance activities in the...

  • Security Manager

    1 week ago


    London, Greater London, United Kingdom Information Security Solutions Full time £120,000 - £160,000 per year

    We are searching for candidates that match the role below:Title………………………Security ManagerCompany………………Financial ServicesLocation………………..LondonWorking pattern……Hybrid – 2 days per week in the officeSalary……………………£120,000 - £160,000The RoleWe are seeking a Security Manager to lead security...


  • London, United Kingdom Harrison Holgate Full time

    Our client, a leading city-based insurance broker, is seeking an experienced Information Security Manager to lead the development and delivery of the firm's information security programme. This key role will be central to protecting business systems, data, and operations across a growing organisation. Key responsibilities:* Design and implement security...


  • London, United Kingdom BCT Resourcing Full time

    We are looking for an experienced Information Security Manager with a strength in IT Risk to join a reputable and rapidly expanding organisation. This is a brand new role within the organisation due to a large scale technology transformation, so it's a fantastic time to join in an autonomous role where you will be driving real change. Core...


  • London Area, United Kingdom Context Recruitment Full time

    Information Security Manager£70,000 - £75,000 PACentral LondonA well-established construction engineering business is seeking an experienced Information Security Manager to join them on a permanent basis. You'll be joining at a critical time as the organisation expands its technical capability, with ambitious growth plans and multiple acquisitions planned...


  • London Area, United Kingdom Context Recruitment Full time £70,000 - £75,000 per year

    Information Security Manager£70,000 - £75,000 PACentral LondonA well-established construction engineering business is seeking an experienced Information Security Manager to join them on a permanent basis. You'll be joining at a critical time as the organisation expands its technical capability, with ambitious growth plans and multiple acquisitions planned...


  • Greater London, United Kingdom Cyber Security training courses Full time

    Your new role - Permanent - ON SITE 5 Days per week. You will be required to undergo vigorous onboarding checks - UK Only. Sponsorship NOT available. The main purpose of this job mainly focusses on information security, cybersecurity, and data security from a Greenfield perspective. We are on a journey to secure Cyber Essentials plus and ISO27001...


  • London, United Kingdom Revlon Full time

    “Empowering Beauty Through Security – Join Revlon as Global Senior Manager, Information Security” Senior Manager, Information Security – Global Role Location: London (Global remit) 3 days office, 2 days remote Division: Technology Reports to: Chief Information Security Officer Join Revlon and help us protect the beauty of innovation. We’re seeking...


  • London, United Kingdom Wilson James Full time

    Are you passionate about information security? Are you looking for a new challenge and a chance to grow in your Information Security Career? If so, then we have the job for you! You will also be managing and coordinating the corporate Information Security Risk Management program, liaising with information asset owners to ensure that assets are appropriately...


  • London, United Kingdom UBA UK Full time

    _**Responsibilities**_:_ **1. Establish Governance & Build Knowledge** - Propose and implement UBA -UK Information security governance structure as part of a global matrix and formulate risk management program approach. - Provides regular reporting on the current status of the information security program to enterprise risk teams and senior business...