Director of Information Security

3 weeks ago


Ripponden UK, Sowerby Bridge, United Kingdom JLA Group Full time

JLA is a mission critical infrastructure solutions business offering services Laundry, Catering, Heating, Fire Safety, Infection Control and Air Conditioning.

The company offers an end-to-end, on premise, machine supply and breakdown service proposition under the name Total Care, and additional products and services. JLA is driven by a world class Sales & Marketing engine, owns and maintains all assets, and has an efficient on-site operations team working daily with customers.


When you join the JLA family, you'll also gain access to an extensive benefits package.


We care about our people and take your well-being seriously, which is why we offer a range of supportive tools for health and wellbeing, financial guidance, and legal advice. Our Employee Assistance Programme, 24/7 Wellness and Lifestyle App plus a dedicated team of Mental Health First Aiders are there to support you through life's challenges. We also offer up to 8 counseling sessions, which can be in-person or remote, providing you with the support and flexibility to suit your own personal needs.


You can reach any fitness goals with our free onsite gym at head office along with a range of other gym membership discounts available.


To offer financial support, we not only provide life assurance coverage, company sick pay, and a company pension scheme, we offer a range of added benefits such as free office parking, eye care vouchers, a cycle-to-work scheme, and exclusive discounts through our staff benefits hub.

We really pride ourselves in offering a healthy work-life balance and believe it is important to have time away to recharge which is why we provide 25 days of annual leave plus bank holidays, flexible working options, and enhanced family leave policies.


We are a company that appreciates you and invests in your success and even have a Colleague Recognition Scheme to celebrate your achievements. We're dedicated to your growth, offering support in career development and training. We value your referrals, and through our Refer a Friend scheme, you can earn up to £1,000 in bonus rewards


About the role


JLA is committed to maintaining a secure and compliant business. As part of this ongoing commitment we are looking for an experienced Information Security professional to take responsibility for our vision, strategy, and the overall program to keep our information assets and operational systems protected.


The Director of Information Security will oversee the development and implementation of JLA’s information security strategy, including policies, procedures and tools designed to protect enterprise communications, systems, and assets from both internal and external threats.


Importantly they will be responsible for understanding the evolving threat, compliance and technology landscape and owning JLA’s response to these risks alongside the technology and legal functions.


Key Responsibilities:


Leadership and Strategy:

  • Develop, implement, and monitor a strategic, comprehensive best-practice enterprise information security and IT risk management program.
  • Work directly with the business units to facilitate risk assessment and risk management processes.
  • Develop and enhance an information security management framework and associated policies.


Governance, Risk, and Compliance:

  • Ensure compliance with relevant security policies, standards, regulations, and laws.
  • Ensure applicable data is classified, managed, stored and retained in accordance with best-practice and applicable laws.
  • Oversee the approval, training, and dissemination of security policies and practices.
  • Take responsibility for statutory attestations and achieving key information security accreditations to demonstrate best-practice.


Incident Readiness and BCP:

  • Oversee the ongoing development of JLA’s disaster recovery and business continuity plan.
  • Develop and manage the cross-functional information security incident response team and ensure efficient and effective incident management processes are in place.
  • Run incident response test and simulations to ensure there are adequate mitigations in place to minimize recovery time.


Security Operations:

  • Monitor the security and compliance environment continuously, managing third-party vendors and monitoring tools.
  • Evaluate and provide recommendations for security, compliance and information governance technologies and solutions.


Vendor and Third-Party Management:

  • Manage security vendors and service providers.
  • Work with the procurement team to ensure that third-party providers are compliant with the organization's security policies and contractual obligations.


Skills and Experience


  • Proven ability to develop and execute a comprehensive information security strategy.
  • Proven experience in developing and managing security policies and procedures
  • Experience with cloud security, in particular Azure and hybrid Azure environments.
  • Strong working knowledge of the Azure Entra and Microsoft Security and Compliance tools, and applying these across M365.
  • In-depth knowledge of information security frameworks (e.g., ISO 27001, NIST).
  • Strong understanding of relevant legal and regulatory requirements, such as GDPR, and PCI-DSS.
  • Excellent leadership, communication, and project management skills.
  • Ability to handle high-stress situations and make sound decisions under pressure.


Qualifications:


Education and Experience:

  • Bachelor’s degree in Computer Science, Information Systems, or a related field.
  • Minimum of 10 years of experience in a combination of risk management, information security, and IT roles.
  • At least 3 years in a senior information security role.


Certifications:

The ideal candidate will have one or more of the following certifications:


  • CISSP (Certified Information Systems Security Professional)
  • CISM (Certified Information Security Manager)
  • CRISC (Certified in Risk and Information Systems Control)


Other relevant certifications are a plus.



  • Ripponden, United Kingdom JLA Group Full time

    JLA is a mission critical infrastructure solutions business offering services Laundry, Catering, Heating, Fire Safety, Infection Control and Air Conditioning.Is this your next job Read the full description below to find out, and do not hesitate to make an application.The company offers an end-to-end, on premise, machine supply and breakdown service...


  • Ripponden, United Kingdom JLA Group Full time

    JLA is a mission critical infrastructure solutions business offering services Laundry, Catering, Heating, Fire Safety, Infection Control and Air Conditioning.Is this your next job Read the full description below to find out, and do not hesitate to make an application.The company offers an end-to-end, on premise, machine supply and breakdown service...


  • Ripponden, United Kingdom JLA Group Full time

    JLA is a mission critical infrastructure solutions business offering services Laundry, Catering, Heating, Fire Safety, Infection Control and Air Conditioning.The company offers an end-to-end, on premise, machine supply and breakdown service proposition under the name Total Care, and additional products and services. JLA is driven by a world class Sales &...


  • Ripponden, United Kingdom JLA Group Full time

    JLA is a mission critical infrastructure solutions business offering services Laundry, Catering, Heating, Fire Safety, Infection Control and Air Conditioning.The company offers an end-to-end, on premise, machine supply and breakdown service proposition under the name Total Care, and additional products and services. JLA is driven by a world class Sales &...


  • Ripponden, United Kingdom JLA Group Full time

    JLA is a mission critical infrastructure solutions business offering services Laundry, Catering, Heating, Fire Safety, Infection Control and Air Conditioning.The company offers an end-to-end, on premise, machine supply and breakdown service proposition under the name Total Care, and additional products and services. JLA is driven by a world class Sales &...


  • Ripponden, United Kingdom JLA Group Full time

    JLA is a mission critical infrastructure solutions business offering services Laundry, Catering, Heating, Fire Safety, Infection Control and Air Conditioning. The company offers an end-to-end, on premise, machine supply and breakdown service proposition under the name Total Care, and additional products and services. JLA is driven by a world class Sales &...


  • Ripponden, United Kingdom JLA Group Full time

    JLA is a mission critical infrastructure solutions business offering services Laundry, Catering, Heating, Fire Safety, Infection Control and Air Conditioning.The company offers an end-to-end, on premise, machine supply and breakdown service proposition under the name Total Care, and additional products and services. JLA is driven by a world class Sales &...


  • Ripponden, West Yorkshire, United Kingdom JLA Group Full time

    JLA is a mission critical infrastructure solutions business offering services Laundry, Catering, Heating, Fire Safety, Infection Control and Air Conditioning. The company offers an end-to-end, on premise, machine supply and breakdown service proposition under the name Total Care, and additional products and services. JLA is driven by a world class Sales &...


  • Ripponden, West Yorkshire, United Kingdom JLA Group Full time

    JLA is a mission critical infrastructure solutions business offering services Laundry, Catering, Heating, Fire Safety, Infection Control and Air Conditioning. The company offers an end-to-end, on premise, machine supply and breakdown service proposition under the name Total Care, and additional products and services. JLA is driven by a world class Sales &...


  • London, UK, UK, United Kingdom Saepio Information Security Full time

    Title: Cloud Security Solutions ArchitectLocation: Hybrid, London or High Wycombe, United KingdomSalary: £70k basic, £90k OTE Year 1, £110k OTE Year 2Hours: Full Time - (Mon – Fri, 9am – 6pm)Reporting To: Solutions Architecture ManagerSaepio are an Information Security Solutions Provider that work with UK based corporate customers with between...


  • UK, UK, United Kingdom Bestman Solutions Full time

    Head of Information SecurityAbout Our Client: Our client is a forward-thinking customer focused firm committed to safeguarding their information assets. As they expand their Cyber Security function, they are seeking a dynamic and experienced Head of Information Security to join their team. This role is pivotal in supporting the Chief Information Security...


  • UK, UK, United Kingdom Locke and McCloud Full time

    Information Security ManagerRole OverviewWe are rapidly expanding and seeking a motivated Information Security Manager with strong technical and communication skills. This role is crucial to driving our ambitious customer acquisition and revenue goals, going beyond compliance to actively shape our security landscape.Key ResponsibilitiesDevelop and maintain...


  • UK, UK, United Kingdom Apply Recruitment Full time

    Information Security Officer – Lancashire – Hybrid.£58k to £61k plus 10.5% bonus, 14% company pension contribution, healthcare, flex bens programme etcInformation Security Officer required for this Northwest based regulated organisation.The organisation is looking to build its cyber security capability significantly, is well funded into the millions...


  • UK, UK, United Kingdom Maxwell Bond Full time

    Information Security Consultant - Hybrid - Gloucestershire - £60,000Maxwell Bond have partnered with a consultancy who specialise in cyber risk management and are in an exciting period of growth and are looking to add some more heads to help deliver projects within the MoD. For the nature of this work it is essential that you are able to obtain security...


  • UK, UK, United Kingdom Nityo Infotech Full time

    Demonstrated significant experience in either an internal or external information security, risk, and compliance role.Strong knowledge of digital security and experience in cyber risk management and advice.Extensive experience in establishing relationships to form effective partnerships with stakeholders within the business.In-depth understanding of relevant...

  • Security Engineer

    1 week ago


    UK, UK, United Kingdom Grantfen Fire & Security Ltd Full time

    Company Description Grantfen Fire & Security Ltd, is a dynamic security systems integrator based in Preston. The company is a leading security solutions provider focused on clients' risks and requirements, with a reputation for technical excellence and innovation. Grantfen's in-house IT development team enables flexibility and integration of legacy...


  • UK, UK, United Kingdom Infinity Quest Full time

    Role: Security ArchitectLocation: Cambridge, UK (Hybrid)Contract length: Initially 6 months Job Overview:The role will spend time helping teams come up to speed with refreshed approaches to security requirement identification, threat modelling, coding standards, and security testing, with a focus on applying these concepts to traditional and modern...


  • UK, UK, United Kingdom Kurt Geiger Full time

    DescriptionKurt Geiger | About UsWe are an inclusive, creative footwear and accessories brand powered by kindness. We want to empower our talent to be confident and true to themselves, the London way. London is our home, our heartbeat, and we draw inspiration from the energy and spirit of the city; its diversity and creativity. For over fifty years our team...


  • UK, UK, United Kingdom MAC Recruit Group Ltd Full time

    I am working with a fintech scale-up who have a distributed team across the UK, with a base in Glasgow. Their customers are worldwide, and each country has different requirements, supported via their industry leading platform centred around rewards and cashback.Their growth has been significant this year, with their next important hire being within the...


  • Leeds, UK, West Yorkshire, United Kingdom Locke and McCloud Full time

    Information Security ConsultantWe are seeking a Global Information Security Consultant to join our Information Security team. You will provide expert advice on IT security, enhance policies, and support a multi-region infrastructure. This role involves reviewing all aspects of our IT environment and supporting enterprise-wide security solutions, with a focus...