Information Security Manager
Based on site in Cheadle (SK8 3GW) - Monday to Friday26 days holiday, and a day off for your birthday (increasing with service to 30 days), plus bank holidaysFree access to company holiday homesBuy & sell holidaysDiscretionary annual bonus plus an additional Shared Reward BonusMatched pension contributionHealth cash plan plus Private medical insuranceLife assurance and Critical illness coverTravel season ticket loans and Ride to work schemeFree local gym accessLocal bar / restaurant discounts We’re Together. For over 50 years, we’ve helped thousands of people, businesses and professionals unlock their property ambitions with our common-sense approach to mortgages and secured loans.We take the time to understand our customers and our door is always open, so we can often help when other lenders can’t or won’t. Based in Cheadle, Cheshire, our 900 colleagues help our customers throughout the UK, backed by the power of a £7.8 billion loan book. Reporting to the Chief Information Security Officer, you will play a critical role in supporting the development and continuous improvement of our Information Security governance, risk management, and assurance framework.You will be a seasoned InfoSec professional able to support and maintain governance and leading frameworks such as NIST CSF and the UK Cyber Assessment Framework (CAF) to identify, assess and managing risks across the Group. You will develop risk metrics (KPIs/KRIs). However, what is critical for the role is the ability to deliver security training and awareness programmes as well as leading third-party cyber, information and AI security due diligence. This would include ongoing monitoring of risks and incidents. The role also involves supporting audits, driving continuous improvement across policies and controls, and implementing monitoring solutions using Microsoft Purview and DLP. Working closely with the CISO and Cyber Security team, you will contribute to governance, reporting and incident response, while building strong stakeholder relationships across IT, Risk and the wider business.in a nutshell, responsibilities include:Maintain and enhance Information Security governance frameworks aligned to NIST CSF and CAFDefine and report on security risk metrics, KPIs and KRIsIdentify and assess Information Security risks across business and technology environmentsDeliver engaging security awareness and training programmesConduct third-party cyber, information and AI security due diligenceSupport audit and assurance activities, including evidence collationDrive continuous improvement across policies, processes and controlsSupport Microsoft Purview and DLP monitoring capabilitiesPartner with the CISO on governance, reporting and incident response activities You are a proactive and detail-oriented Information Security professional with experience working in regulated environments and a passion for improving security maturity.Essential ExperienceProven experience in third-part...