This job does not exist anymore.
Try running a new search or browse our vacancies.
Or fill in the form below to receive job alerts.
Job Type | Permanent |
Area | Staffordshire, Midlands |
Sector | IT/Technology |
Salary | £50,000-£60,000 plus excellent benefits |
Start Date | ASAP |
Advertiser | EllisKnight International |
Job Ref | 3163 |
Job Views | 186 |
- Description
Senior Information Security Manager - Security Governance, Controls, Assurance, Service.
EllisKnight Recruitment are currently recruiting for a Senior Information Security Manager for this Technology business based in Stoke. The Senior Information Security Manager will play a key role in defining, managing and ensuring the company is compliant with all aspects of IT security. The role will support the delivery of a variety of innovative, accreditable, cost efficient and profitable solutions to comply with HMG’s security classification system. These solutions are operated at a variety of company and customer premises and are the foundation for the Company’s secure managed ICT services to public sector customers. The role encompasses two key areas:
- Information Assurance: Implement measures focused on protection and safeguarding of the Company’s critical information and relevant information systems, assuring the integrity, availability, authentication, confidentiality and non-repudiation.
- Information Security: Protecting information and information systems from illegitimate access, usage, revelation, alteration, disruption and destruction to achieve the objectives of data integrity, availability and confidentiality.
Responsibilities:
• Mentor junior members of the security team.
• Lead the security accreditation and assurance processes for new and enhanced services which the company offer to our customers.
• Planning Information Assurance Capability:
- Develop and maintain Information Security Management System (ISMS) to best support the Company’s activities, including Risk Management and Accreditation Document Sets and Company Security Policies.
- Examine any risks to the Company's information security and put in place policies to manage those risks.
- Develop, maintain and continually improve a set of controls and measures to manage any threats to information assets.
- Plan and maintain compliance with the variety of security requirements that the Company meets.
• Monitoring Information Assurance
- Coordinate and implement all protective security activities including physical security.
- Accountable for information governance, including annual assessments and risk management.
- Monitor the operation of the Company’s Information Security Management System.
• Implementing Information Assurance:
- Perform the role of Incident Manager during any security incidents and emergencies, ensuring that all business recovery/contingency plans and/or procedures are actioned accordingly.
- Act as focal point for any investigations involving security; to prepare reports and note follow up action. Report any significant security breaches to the to the Operations Board; undertake full investigation; recommend remedial course of action.
- Manage the Company’s Information Security awareness, education and training programme.
- Maintain and develop relationships with appropriate suppliers, including consultants and service providers.
- To be the Company’s Security Controller, providing advice as necessary and implementing company security policy.
• Evaluating Information Assurance
- Represent security on any relevant project workgroups and project boards.
- Manage a process of continual Audit, to ensure that compliance is maintained with the various requirements on the Company, and to support continuous improvements.
- Organise and facilitate periodic review of policies and procedures.
- Carry out Security exercises including NCSC Cyber in a box.
- Manage the follow up actions.
Qualifications/Security Clearance
- CISSP/CISA/ CISM desirable or equivalent professional experience.
- Must hold or be able to gain national security clearance to the Developed Vetting (DV) level.
Skills/Experience
- Proven track record in Information Security and Assurance and deploying continuous improvement initiatives. (Essential)
- Experience in risk and regulatory frameworks and standards, such as NIST, ISO27001, MOD JSP440, JSP604 (Preferable)
- Experience of managed service environments, with an awareness of ITIL best practice. (Preferable)
- Willingness to work flexibly in response to changing organisational requirements. (Essential)