392 Ciso jobs in the United Kingdom

Chief Information Security Officer

London, London Fuse Energy

Posted 19 days ago

Job Viewed

Tap Again To Close

Job Description

Permanent

Fuse is building a fully integrated energy company—spanning solar, wind, hydrogen, power trading, and distributed energy systems. We sell directly to consumers to reduce costs and deliver real savings.

We're also creating the Energy Network: a decentralised system of smart devices that rewards users in Energy Dollars for electrifying their homes, shifting usage to off-peak hours, and supporting grid stability—critical for scaling AI and energy-intensive industries.

We’re looking for a Chief Information Security Officer (CISO) to lead our company-wide security strategy. You’ll protect our infrastructure, digital assets, and customer data while enabling fast, secure growth.

Key Responsibilities

Security Strategy & Leadership

  • Define and lead Fuse’s security strategy across infrastructure, applications, and data.
  • Lead hands-on development of security roadmaps, maturity models, and control frameworks tailored to Fuse’s risk profile.
  • Directly contribute to architecture reviews, threat modelling sessions, and key design decisions across product and platform teams.
  • Build and mentor a high-performing security team, including hiring, coaching, and managing performance.
  • Develop KPIs and reporting structures to measure and communicate security posture to leadership and the board.
  • Advise the executive team on security risks, regulatory exposure, and investment priorities to support long-term growth.

Governance & Compliance

  • Own company-wide security governance, including data protection, access control, and insider risk.
  • Ensure compliance with SOC 2, ISO 27001, GDPR, and other relevant frameworks.
  • Oversee security audits and third-party risk programs.

Risk Management & Threat Intelligence

  • Lead threat modelling, risk assessments, and security reviews of critical systems; design and deliver security awareness training programs for all employees to promote a culture of proactive risk management.
  • Build threat intelligence capabilities to stay ahead of emerging risks.
  • Balance risk management with product and engineering velocity.

Incident Response & Resilience

  • Own response plans for high-severity threats and incidents.
  • Build robust detection, containment, and remediation processes.
  • Drive business continuity and disaster recovery strategy.

Technology & Infrastructure Security

  • Partner with engineering to embed security in the SDLC and infrastructure.
  • Guide secure design for cryptographic systems, transaction flows, and the Energy Network.
  • Ensure resilience across distributed devices and on/off-chain systems.

Security Culture & Collaboration

  • Promote a security-first culture across product, data, legal, and compliance.
  • Represent Fuse externally in customer, regulatory, and industry engagements.

Requirements

  • 5+ years in cybersecurity, with prior leadership or CISO experience.
  • Deep understanding of cloud security (especially AWS), application security, and modern DevSecOps.
  • Proven experience securing systems involving digital assets, cryptographic components, or distributed infrastructure.
  • Strong grasp of regulatory frameworks: SOC 2, ISO 27001, GDPR, NIST, etc.
  • Background in threat modeling, incident response, and risk management.
  • Excellent leadership, communication, and stakeholder skills.
  • Bachelor’s or advanced degree in Computer Science, Information Security, or related field.

Bonus:

  • Experience with CTFs, red/blue team exercises, or offensive security.

Benefits

  • Competitive salary and a stock options sign-on bonus
  • Biannual bonus scheme
  • Fully expensed tech to match your needs!
  • Paid annual leave
  • Breakfast and dinner for office based employees
This advertiser has chosen not to accept applicants from your region.

Information Security Officer

London, London TPP Recruitment

Posted 1 day ago

Job Viewed

Tap Again To Close

Job Description

Information Security Officer

Hybrid – Home & London | Permanent | £68,000 | 35 hrs/week (flexible)


A rare and brilliant opportunity to join this international development children’s charity, as their new Information Security Officer . You'll be the expert, working closely with the Chief Information Officer and other senior leaders to embed security practices across systems, suppliers, and staff. You’ll be joining a small but impactful Technology team where the culture is collaborative and down-to-earth. You’ll have the autonomy to get stuck in, alongside the backing to develop professionally, whether that’s through security qualifications or broader leadership skills.


What you will be doing

As Information Security Officer , you’ll lead the implementation of the organisation’s cyber security plans.


  • Act as subject matter expert on information security across the organisation
  • Ensure compliance with standards like Cyber Essentials Plus and CIS .
  • Oversee third-party security providers and outsourced ICT services.
  • Manage incident response planning, investigations, and reporting.
  • Deliver engaging training to build a strong security culture.
  • Collaborate with Legal and Data Protection teams to ensure GDPR compliance.
  • Stay ahead of evolving threats and technologies to drive continuous improvement.
  • Opportunity to influence at board level without people management responsibilities


What we are looking for

What matters most is your hands-on experience navigating real-world security challenges and your ability to see both the technical and human side of data protection.


You should have:

  • Proven experience in ICT security management and incident response (CIS and Cyber Essential Plus).
  • Strong technical knowledge of Microsoft 365, Azure, and cloud security.
  • Familiarity with frameworks like ISO 27001, NIST, and CIS.
  • Excellent communication skills and a pragmatic, risk-based mindset.
  • Relevant certifications (e.g. AZ-500, CISSP, CISM, CCSP) are highly desirable.


This role offers hyrbid working (1-2 days/week in office) as well as open discussion around different working patterns i.e 9-day fortnight and varied start/finish times. The organisation values professional development and had a learning & development fund for certifications and career growth. A strong emphasis on wellbeing and work-life balance within a supportive, inclusive culture that welcomes applicants from all backgrounds.


To apply, please submit your up-to-date CV by the 26th of August 2025 at 5.00 PM . Cover letters are not required.


Please note, only successful applicants will be contacted with further information.


We want you to have every opportunity to demonstrate your skills, ability and potential; please contact us if you require any assistance or adjustment so that we can help with making the application process work for you.

This advertiser has chosen not to accept applicants from your region.

Information Security Officer

TPP Recruitment

Posted 1 day ago

Job Viewed

Tap Again To Close

Job Description

Information Security Officer

Hybrid – Home & London | Permanent | £68,000 | 35 hrs/week (flexible)


A rare and brilliant opportunity to join this international development children’s charity, as their new Information Security Officer . You'll be the expert, working closely with the Chief Information Officer and other senior leaders to embed security practices across systems, suppliers, and staff. You’ll be joining a small but impactful Technology team where the culture is collaborative and down-to-earth. You’ll have the autonomy to get stuck in, alongside the backing to develop professionally, whether that’s through security qualifications or broader leadership skills.


What you will be doing

As Information Security Officer , you’ll lead the implementation of the organisation’s cyber security plans.


  • Act as subject matter expert on information security across the organisation
  • Ensure compliance with standards like Cyber Essentials Plus and CIS .
  • Oversee third-party security providers and outsourced ICT services.
  • Manage incident response planning, investigations, and reporting.
  • Deliver engaging training to build a strong security culture.
  • Collaborate with Legal and Data Protection teams to ensure GDPR compliance.
  • Stay ahead of evolving threats and technologies to drive continuous improvement.
  • Opportunity to influence at board level without people management responsibilities


What we are looking for

What matters most is your hands-on experience navigating real-world security challenges and your ability to see both the technical and human side of data protection.


You should have:

  • Proven experience in ICT security management and incident response (CIS and Cyber Essential Plus).
  • Strong technical knowledge of Microsoft 365, Azure, and cloud security.
  • Familiarity with frameworks like ISO 27001, NIST, and CIS.
  • Excellent communication skills and a pragmatic, risk-based mindset.
  • Relevant certifications (e.g. AZ-500, CISSP, CISM, CCSP) are highly desirable.


This role offers hyrbid working (1-2 days/week in office) as well as open discussion around different working patterns i.e 9-day fortnight and varied start/finish times. The organisation values professional development and had a learning & development fund for certifications and career growth. A strong emphasis on wellbeing and work-life balance within a supportive, inclusive culture that welcomes applicants from all backgrounds.


To apply, please submit your up-to-date CV by the 26th of August 2025 at 5.00 PM . Cover letters are not required.


Please note, only successful applicants will be contacted with further information.


We want you to have every opportunity to demonstrate your skills, ability and potential; please contact us if you require any assistance or adjustment so that we can help with making the application process work for you.

This advertiser has chosen not to accept applicants from your region.

Regional Information Security Officer

Manchester, North West Tunstall Healthcare (UK) Ltd

Posted today

Job Viewed

Tap Again To Close

Job Description

permanent
We are currently recruiting for a Regional Information Security Officer , reporting to the Global Chief Information Security Officer (CISO), to oversee the information security function across the countries and Tunstall entities in their scope.

This is an incredibly exciting time to join Tunstall as we embark on an exciting period of transformation. You will be joining a recently created and growing.


































WHJS1_UKTJ

This advertiser has chosen not to accept applicants from your region.

Junior Information Security Officer

London, London Steamship Insurance Management Services Ltd

Posted 14 days ago

Job Viewed

Tap Again To Close

Job Description

Permanent

About the company

Steamship Mutual is a P&I insurance company, with 230 employees worldwide. The main office is based near Liverpool Street station, London. We have offices in Bermuda, Brazil, Cyprus, Greece, Hong Kong, Japan, and Singapore.

Overall Job Purpose

The Junior Information Security Officer (JISO) will assist the Information Security team in implementing and maintaining the information security management system with the objective of managing risks to information assets to an acceptable level.

The JISO will develop a good understanding of the information security policies, standards and procedures and will assist InfoSec in implementing, managing and monitoring the relevant controls.

It is imperative that the JISO develops a strong understanding of the organisation’s technology landscape to help identify potential threats and vulnerabilities.

Requirements

Key Responsibilities:

  • Assist in maintaining the information security standards, procedures and guidelines.
  • Participate in the information security risk management process to identify, assess, treat and monitor risks.
  • Manage information security incidents and events to protect information assets. Help develop and implement incident response plans and procedures to ensure that information services are recovered in a timely manner in the event of a security breach.
  • Track vendor and media disclosure of threats and vulnerabilities and advise on the appropriate courses of action.
  • Audit security controls and report non-compliance. Assist in auditing the environment against new or updated legal and regulatory requirements, or the agreed industry standards.
  • Assist with the quarterly cybersecurity ITSC and Board updates and key risk indicator reporting.
  • Maintain the information security awareness training program and conduct phishing tests.
  • Maintain the Privileged Access Management, Security and Event Management and Vulnerability Management systems.
  • Assist in identifying security solutions that will be effective in mitigating risks to information assets. Manage the implementation and maintenance of the approved solutions.

Person Specification:

  • Degree in Cybersecurity, Computer Science, Information Systems, or a related field.
  • Demonstrable interest in information security (e.g. coursework, certifications, personal projects).
  • Familiarity with security frameworks such as ISO27001, NIST, or CIS Controls.
  • Basic understanding of networking, operating systems, and cloud environments.
  • Awareness of common threat vectors, controls and basic incident response principles.
  • Basic knowledge of Windows operating systems, Active Directory, Entra ID
  • Strong analytical and problem-solving skills.
  • Excellent written and verbal communication.
  • Ability to handle sensitive information with discretion.
  • Eagerness to learn and adapt in a fast-paced environment.
  • Team player with a proactive and detail-oriented mindset.

Benefits

Join Us at Steamship Mutual

    • Become part of our collaborative, supportive, and friendly working environment, where you can enjoy a rewarding career with opportunities to enhance your existing skills and knowledge. We prioritise a healthy work-life balance and offer a competitive hybrid working policy.
    • Our clear and transparent career pathways provide continuous support for skill enhancement and create opportunities for professional development. Additionally, we offer access to the Protection & Indemnity Qualification, created by the International Group of P&I Clubs.
    • Our attractive benefits package includes private healthcare and a competitive wellbeing subsidy.

Company Values

Mutuality ensuring fairness amongst Club Members

Integrity upholding high ethical, legal, and regulatory standards

Safety and Sustainability contributing to safety of life at sea and the preservation of the environment

Transparency building strong relationships based on trust and open communication

Excellence enabling our people to realise their full potential as team members, industry experts, leaders, and managers

Collaborative embracing flexibility, diversity, and inclusivity

**Steamship Insurance Management Services Ltd is committed to providing a great service to all our members. We pride ourselves on offering a people-centred culture that provides mutual respect and support for all our staff and we welcome and encourage you to apply**

This advertiser has chosen not to accept applicants from your region.

Global Chief Information Officer

Dentons

Posted 3 days ago

Job Viewed

Tap Again To Close

Job Description

Permanent

Dentons is designed to be different. We are driven to always be the firm of the future, to challenge the status quo, and to provide holistic business solutions to our clients in new and innovative ways. We are the lightbulb moments. The bold ideas. We are the world's largest global law firm, with 12,000+ people across 80+ countries. Driven by the diverse perspectives of our people, our clients, and our communities, we combine local knowledge with global insight.

The Global Chief Information Officer (CIO) will lead the global technology function strategically, define a transformative vision, and provide high-impact leadership across a complex, multi-layered firm. This role is a strategic influencer tasked with aligning technology strategy to the global and regional business priorities and objectives.

The Global CIO will champion collaboration across regions, optimize business processes, enable inorganic and organic growth. They will oversee the cost-effective provision of shared services, global platforms, and vendor ecosystems, while ensuring technology security and regulatory compliance. The CIO will also work closely with the members of Global governance bodies (GMC, Global Board etc.) and all the Global Chiefs and in particular the Global Chief Finance Officer to manage complex budgets and billing structures and with the Global Chief Security Officer on technology security.

Responsibilities

Strategic Vision & Operating Model:

  • Develop and implement a Target Operating Model for the firmwide Technology function(s), including clarifying accountability over governance, funding, and delivery and support frameworks.
  • Create a 5-year technology roadmap aligned with the Global CEO’s strategy and regional priorities.
  • Influence and align regional and global stakeholders to ensure cohesive execution of technology initiatives.
  • Lead and execute transformation efforts enabled by technology, as approved.

Shared Services & Global Platforms:

  • Build upon the shared services already provided for the regions.
  • Define and monitor SLAs for shared technologies and services provided to the regions.
  • Oversee the provision and performance of global technology services, digital technologies, applications, and data services.
  • Ensure seamless integration of global platforms.

Leadership & Collaboration:

  • Lead and inspire a high-performing Global technology team; and align and inspire Regional IT leaders.
  • Provide guidance on staffing and structuring to build upon and support the shared services delivery model.
  • Foster cross-functional collaboration with practice, business, and security leaders.

Vendor & Financial Oversight:

  • Manage Global vendor contracts, billing processes, and performance accountability.
  • Identify opportunities to reduce costs through strategic sourcing.
  • Partner with the Global Chief Finance Officer to navigate procurement and complex budget structures.

Security, Compliance & Risk:

  • Collaborate with the Global Chief Security Officer to embed security and regulatory compliance into all technology initiatives and IT operations.
  • Lead efforts to seek and retain compliance of managed technology assets with international cyber security standards including and not limited to ISO27001 and Soc2

Operational Excellence:

  • Institute an IT Service Delivery model (e.g., ITIL) to maximize effectiveness and efficiency.
  • Align tooling, policies, and standards to resolve gaps and drive modernization.

Requirements

Required Qualifications:

  • Bachelor’s degree in Computer Science, Information Systems, Engineering, or related field.
  • Master’s degree in Business Administration (MBA), IT Management, Organizational Leadership, or Strategy; advantageous.

Required Experience:

  • 15+ years in IT leadership roles, including:
  • Leading firm-wide digital transformation
  • Managing global IT operations and infrastructure
  • Driving innovation and business process optimization
  • 5+ years in executive-level roles (e.g., CIO, CTO, VP of IT) with direct reporting to C-suite leadership

Skills & Knowledge:

  • Mastery of enterprise architecture, cloud platforms, and infrastructure.
  • Knowledge of cybersecurity frameworks and data privacy regulations.
  • Familiarity with AI and other emerging technologies.
  • Experience with IT service management (e.g., ITIL), DevOps, and software development lifecycle.

Competencies & Critical Leadership Capabilities:

Strategic & Business Knowledge

  • Global Strategy Alignment: Ability to align IT initiatives with both global and regional business strategies.
  • Target Operating Model Design: Expertise in defining and implementing shared service delivery models.
  • Technology Road mapping: Experience developing long-term technology plans (e.g., 5-year strategy).

Technical Expertise

  • Enterprise Architecture: Deep understanding of scalable, secure, and compliant systems.
  • Cloud Platforms: Proficiency in Azure, AWS, and hybrid environments.
  • Cybersecurity & Compliance: Familiarity with global regulatory frameworks.
  • Emerging Technologies: Awareness of AI., blockchain, and automation tools.
  • IT Service Management: Experience with ITIL frameworks and service-level agreements (SLAs).

Operational & Financial Skills

  • Vendor Management: Ability to negotiate, manage, and evaluate global vendor contracts.
  • Complex Budgeting: Skilled in navigating multi-layered, cross-regional IT budgets and billing structures.
  • Asset & Risk Management: Oversight of IT assets, technical debt reduction, and audit remediation.

Leadership & Collaboration

  • Cross-Functional Leadership: Leading global teams and regional IT leaders in a matrixed environment.
  • Stakeholder Engagement: Building trust and alignment across C-suite, regional, and functional leaders.
  • Change Management: Driving transformation with empathy, clarity, and strategic foresight.
  • Security Partnership: Collaborating with the Chief Security Officer to embed security into all IT operations.

Communication & Influence

  • Executive Communication: Translating complex technical concepts into business language.
  • Cultural Intelligence: Navigating diverse teams.
  • Client-Centric Mindset: Prioritizing user experience and client outcomes in technology decisions.

The above is intended to describe the general content of and requirements for the performance of this job.  It is not to be construed as an exhaustive statement of essential functions, responsibilities or requirements.

Benefits

Remuneration and benefits package will reflect the successful candidates experience and country where hired.

This advertiser has chosen not to accept applicants from your region.

Information Security Manager

London, London £70000 - £75000 Annually Context Recruitment

Posted 2 days ago

Job Viewed

Tap Again To Close

Job Description

permanent

Information Security Manager

70,000- 75,000 PA

Central London

Well-established construction engineering business is seeking an experienced Information Security Manager to join them on a permanent basis. You'll be joining at a critical time where they are expanding their technical team with an ambitious growth plan with multiple acquisitions planned over the coming years.

The Information Security Manager will be a crucial component in ensuring the effective management of both the technical cyber security environment and wider information security management piece for the business. This role is responsible for ensuring robust cyber security controls with a strong emphasis on ISO 27001 readiness. You'll liaise with assessors and internal teams, drive ISO-related strategies and use prior experience to ensure certification plans stay on track. Working with external teams to align processes, you'll also oversee InfoSec/Cyber services, conduct risk assessments and recommend security improvements.

Responsibilities:

  • Ownership and maintenance of all security related policies and procedures, implementing Security by Design and driving a culture of cyber security awareness in the business
  • Liaise with external ISO27001 assessors and internal teams to ensure smooth assessments
  • Actively contribute to ISO processes, strategies and problem-solving
  • Use prior ISO experience to support certification readiness
  • Working closely with stakeholders across the business in relation to Information Security Strategy and the creation, delivery and maintenance of a robust Cyber Security roadmap
  • Handle varied and complex security challenges, from system reviews to high-level risk assessments
  • Work closely with third-party suppliers in relation to audits, forensic analysis and pen testing

Requirements:

  • Experience with ISO 27001 is essential
  • Strong background in cyber security management
  • Proven experience in identifying and mitigating security risks#
  • Ability to make actionable recommendations for security improvements
  • Experience with GDPR and data protection, together with knowledge of IS standards
  • Security assessment frameworks (threat modelling, controls assessment, risk assessment)
  • Relevant qualifications; CISSP, CISM or similar would be beneficial.

Based in Central London, 4 days per week onsite initially dropping to 3 once passed probation.

This advertiser has chosen not to accept applicants from your region.
Be The First To Know

About the latest Ciso Jobs in United Kingdom !

Information Security Manager

EC1 London, London Context Recruitment

Posted 2 days ago

Job Viewed

Tap Again To Close

Job Description

full time

Information Security Manager

70,000- 75,000 PA

Central London

Well-established construction engineering business is seeking an experienced Information Security Manager to join them on a permanent basis. You'll be joining at a critical time where they are expanding their technical team with an ambitious growth plan with multiple acquisitions planned over the coming years.

The Information Security Manager will be a crucial component in ensuring the effective management of both the technical cyber security environment and wider information security management piece for the business. This role is responsible for ensuring robust cyber security controls with a strong emphasis on ISO 27001 readiness. You'll liaise with assessors and internal teams, drive ISO-related strategies and use prior experience to ensure certification plans stay on track. Working with external teams to align processes, you'll also oversee InfoSec/Cyber services, conduct risk assessments and recommend security improvements.

Responsibilities:

  • Ownership and maintenance of all security related policies and procedures, implementing Security by Design and driving a culture of cyber security awareness in the business
  • Liaise with external ISO27001 assessors and internal teams to ensure smooth assessments
  • Actively contribute to ISO processes, strategies and problem-solving
  • Use prior ISO experience to support certification readiness
  • Working closely with stakeholders across the business in relation to Information Security Strategy and the creation, delivery and maintenance of a robust Cyber Security roadmap
  • Handle varied and complex security challenges, from system reviews to high-level risk assessments
  • Work closely with third-party suppliers in relation to audits, forensic analysis and pen testing

Requirements:

  • Experience with ISO 27001 is essential
  • Strong background in cyber security management
  • Proven experience in identifying and mitigating security risks#
  • Ability to make actionable recommendations for security improvements
  • Experience with GDPR and data protection, together with knowledge of IS standards
  • Security assessment frameworks (threat modelling, controls assessment, risk assessment)
  • Relevant qualifications; CISSP, CISM or similar would be beneficial.

Based in Central London, 4 days per week onsite initially dropping to 3 once passed probation.

This advertiser has chosen not to accept applicants from your region.

Information Security Manager

Prism Digital

Posted 1 day ago

Job Viewed

Tap Again To Close

Job Description

Information Security GRC Manager | ISO27001, SOC2, Azure Security | Global Trading Platform


  • £70–80k base + 10% bonus
  • Hybrid in London
  • Training budget for certifications + conference attendance
  • Strong emphasis on professional autonomy and ethical leadership


A newly created opportunity to lead and shape the GRC function of a global financial group at a pivotal time, supporting the secure rollout of U.S. banking operations, driving ISO27001 and SOC2 maturity, and mentoring an evolving InfoSec team.


This is a hands-on manager-level role with real scope: oversight of policy, third-party risk, architectural reviews, and cloud compliance. You'll work closely with the Head of InfoSec to maintain audit readiness, improve security posture, and influence business-wide awareness and accountability.


What you’ll bring:

  • 5+ years in InfoSec, IT Security or Ops within a regulated environment
  • Certification required: CISSP, CISM, CRISC, or equivalent
  • Strong knowledge of ISO27001:2022, SOC2 Type II, NIST CSF, PCI DSS, GDPR, DORA
  • Confident with security risk assessments, audit responses, and policy governance
  • Hands-on cloud security experience: ideally with Azure and the Shared Responsibility Model
  • Comfort with complexity: able to analyze architecture, track metrics, and translate acronyms into actionable plans
  • Mentorship ability: ready to step up, guide analysts, and model high-integrity InfoSec practice


What you’ll be doing:

  • GRC ownership: maintain ISO27001 and SOC2 certifications, policies, and the Information Security Management System
  • Third-party risk management: oversee supplier assessments, support junior analysts, and guide reviews via Panorays
  • Security awareness & training: manage phishing simulations and content using Proofpoint
  • Security architecture reviews: support technical assessments of new systems and services
  • Data protection & cloud security: drive governance for Azure, Purview, and shared responsibility models
  • Team leadership: mentor two analysts and deputize for the Head of InfoSec when required
  • Project support: direct InfoSec involvement in the U.S. banking expansion and business unit reviews


Tech & tools you’ll use:

  • Protecht – Enterprise risk and audit management
  • Panorays – Third-party risk tooling
  • Rapid7 / Armis – Vulnerability management and threat detection
  • Proofpoint – Phishing and awareness platform
  • Microsoft Purview – Data governance and compliance
  • Azure & AWS – Cloud IAM, encryption, monitoring (Sentinel experience valued)


Why this role?

  • High-impact GRC project work tied to new market expansion
  • Strong internal security culture: backed by a collaborative team and engaged InfoSec leadership
  • A clear opportunity to stretch across awareness, compliance, and operational domains


Information Security GRC Manager | ISO27001, SOC2, Azure Security | Global Trading Platform

This advertiser has chosen not to accept applicants from your region.

Information Security Manager

London, London Prism Digital

Posted 1 day ago

Job Viewed

Tap Again To Close

Job Description

Information Security GRC Manager | ISO27001, SOC2, Azure Security | Global Trading Platform


  • £70–80k base + 10% bonus
  • Hybrid in London
  • Training budget for certifications + conference attendance
  • Strong emphasis on professional autonomy and ethical leadership


A newly created opportunity to lead and shape the GRC function of a global financial group at a pivotal time, supporting the secure rollout of U.S. banking operations, driving ISO27001 and SOC2 maturity, and mentoring an evolving InfoSec team.


This is a hands-on manager-level role with real scope: oversight of policy, third-party risk, architectural reviews, and cloud compliance. You'll work closely with the Head of InfoSec to maintain audit readiness, improve security posture, and influence business-wide awareness and accountability.


What you’ll bring:

  • 5+ years in InfoSec, IT Security or Ops within a regulated environment
  • Certification required: CISSP, CISM, CRISC, or equivalent
  • Strong knowledge of ISO27001:2022, SOC2 Type II, NIST CSF, PCI DSS, GDPR, DORA
  • Confident with security risk assessments, audit responses, and policy governance
  • Hands-on cloud security experience: ideally with Azure and the Shared Responsibility Model
  • Comfort with complexity: able to analyze architecture, track metrics, and translate acronyms into actionable plans
  • Mentorship ability: ready to step up, guide analysts, and model high-integrity InfoSec practice


What you’ll be doing:

  • GRC ownership: maintain ISO27001 and SOC2 certifications, policies, and the Information Security Management System
  • Third-party risk management: oversee supplier assessments, support junior analysts, and guide reviews via Panorays
  • Security awareness & training: manage phishing simulations and content using Proofpoint
  • Security architecture reviews: support technical assessments of new systems and services
  • Data protection & cloud security: drive governance for Azure, Purview, and shared responsibility models
  • Team leadership: mentor two analysts and deputize for the Head of InfoSec when required
  • Project support: direct InfoSec involvement in the U.S. banking expansion and business unit reviews


Tech & tools you’ll use:

  • Protecht – Enterprise risk and audit management
  • Panorays – Third-party risk tooling
  • Rapid7 / Armis – Vulnerability management and threat detection
  • Proofpoint – Phishing and awareness platform
  • Microsoft Purview – Data governance and compliance
  • Azure & AWS – Cloud IAM, encryption, monitoring (Sentinel experience valued)


Why this role?

  • High-impact GRC project work tied to new market expansion
  • Strong internal security culture: backed by a collaborative team and engaged InfoSec leadership
  • A clear opportunity to stretch across awareness, compliance, and operational domains


Information Security GRC Manager | ISO27001, SOC2, Azure Security | Global Trading Platform

This advertiser has chosen not to accept applicants from your region.

Nearby Locations

Other Jobs Near Me

Industry

  1. request_quote Accounting
  2. work Administrative
  3. eco Agriculture Forestry
  4. smart_toy AI & Emerging Technologies
  5. school Apprenticeships & Trainee
  6. apartment Architecture
  7. palette Arts & Entertainment
  8. directions_car Automotive
  9. flight_takeoff Aviation
  10. account_balance Banking & Finance
  11. local_florist Beauty & Wellness
  12. restaurant Catering
  13. volunteer_activism Charity & Voluntary
  14. science Chemical Engineering
  15. child_friendly Childcare
  16. foundation Civil Engineering
  17. clean_hands Cleaning & Sanitation
  18. diversity_3 Community & Social Care
  19. construction Construction
  20. brush Creative & Digital
  21. currency_bitcoin Crypto & Blockchain
  22. support_agent Customer Service & Helpdesk
  23. medical_services Dental
  24. medical_services Driving & Transport
  25. medical_services E Commerce & Social Media
  26. school Education & Teaching
  27. electrical_services Electrical Engineering
  28. bolt Energy
  29. local_mall Fmcg
  30. gavel Government & Non Profit
  31. emoji_events Graduate
  32. health_and_safety Healthcare
  33. beach_access Hospitality & Tourism
  34. groups Human Resources
  35. precision_manufacturing Industrial Engineering
  36. security Information Security
  37. handyman Installation & Maintenance
  38. policy Insurance
  39. code IT & Software
  40. gavel Legal
  41. sports_soccer Leisure & Sports
  42. inventory_2 Logistics & Warehousing
  43. supervisor_account Management
  44. supervisor_account Management Consultancy
  45. supervisor_account Manufacturing & Production
  46. campaign Marketing
  47. build Mechanical Engineering
  48. perm_media Media & PR
  49. local_hospital Medical
  50. local_hospital Military & Public Safety
  51. local_hospital Mining
  52. medical_services Nursing
  53. local_gas_station Oil & Gas
  54. biotech Pharmaceutical
  55. checklist_rtl Project Management
  56. shopping_bag Purchasing
  57. home_work Real Estate
  58. person_search Recruitment Consultancy
  59. store Retail
  60. point_of_sale Sales
  61. science Scientific Research & Development
  62. wifi Telecoms
  63. psychology Therapy
  64. pets Veterinary
View All Ciso Jobs