Glasgow, Lanarkshire
Hays Specialist Recruitment Limited
IT Governance, Risk and Compliance ManagerPermanent Salary: £85,000 – £95,000 (neg.) plus £7,000 car allowance and 10% bonusLocation: GlasgowWorking Arrangement: Hybrid – 2 days on site
Your new company:
I’m currently looking for an Information Security Manager to work for one of Hays’ long-term clients based in Glasgow. This is a hybrid role with a requirement of working on-site 2 days per week, paying up to £95,000 per annum depending on your experience.
This role is a GRC-led leadership position and the ideal candidate will have operated at a senior level maintaining information security accreditations such as ISO27001 and Cyber Essentials +, acting as an IT Risk SME, and working closely with senior leadership on the security assurance of a business.
This role involves:
Leading on business-wide GRC and information security assurance initiativesContributing to a future-focused security model considering IT risk, data security, incident response plans, alongside disaster recovery and business continuityLeading in the maintenance of ISO27001 and CE+ compliance and certification where appropriateCompleting IT Risk assessments, adding to and maintaining the risk registerOverseeing the cyber security incident response process and taking a leading role in assessing corrective actionsActing quickly and decisively on information security incidents in line with your knowledge of industry best practiceWorking with various business leaders on regular security awareness activities, effectively communicating details of emerging security threats and risks and acting as an Information Security Risk Management SMEEngaging with business continuity with senior IT leadersTaking an active involvement in annual information security reviews, communicating to senior stakeholders about contemporary risks to be considered and initiatives to combat themAdvising on all areas of data security – e.g. impact assessments, data security awareness training, data protectionTweaking and maintaining the ISMS in line with your knowledge of industry best practiceUsing your knowledge of technical IT controls to ensure that projects, transformations, current policies and systems are fit for purpose and aligned with organisational risk appetiteLeading a small team of security analysts spanning risk and governanceLeading the risk and governance function as a GRC SME and supporting with risk assessments of transformations, regulations, and policiesOverseeing supplier assurance processes from a security perspectiveAssisting in the creation of governance policies and processesCreating reports for governance groupsMaintaining a contemporary knowledge of current threats and cyber trends, using this to guide the strategic direction of the technology governance model, and to ensure operational risks are managed appropriatelyCollaborating with stakeholders within audit, operational risk and the three lines of defenceProviding strategic advice and input on the organisation’s cyber security strategy
What you’ll need to succeed:
An SME within Information Security Risk ManagementExperience maintaining ISO27001 and Cyber EssentialsExperience developing and maintaining an ISMSExcellent communication and stakeholder engagement skillsExperience leading a cyber security awareness campaign and assisting with surrounding educational measuresA business solution focused mindsetRelevant industry certificationsExperience leading and supporting with risk management and risk assessmentsThe ability to maintaining and foster sound security principles across the organisation whilst keeping a business solution mindset, to not inhibit business functions, projects and transformationsExperience defining governance modelsTeam management experienceStrong IT risk management experience and comprehension of best practice controls and security risk frameworks – NIST, COBIT.
What you’ll get in return:
£85,000 – £95,000 per annum10% Bonus£7,000 car allowanceGood pension and other benefits
Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C’s, Privacy Policy and Disclaimers which can be found at hays.co.uk
