About this role
Salary: £56,000 - 96,000 per year
Requirements: Experience in compliance, information security, risk management or governanceStrong working knowledge of ISO 27001Experience managing, implementing or auditing an ISMSISO 27001 Lead Implementer or Lead Auditor certification is desirableCISM, CISSP, CRISC, an information security degree or equivalent professional backgroundUnderstanding of risk assessment methods such as ISO 27005, NIST or similarExperience planning and conducting internal auditsGood understanding of GDPR, data protection principles and breach notification requirementsConfidence working with senior stakeholders, technical teams and external auditorsStrong written communication skills, with the ability to produce practical policies, procedures and reportsExperience in a regulated or audit-led environment would be helpful, but strong ISMS ownership is the key requirement Responsibilities: Own, maintain and improve our ISMS in line with ISO 27001Manage information security risk assessments, treatment plans and our risk registerPlan and deliver our internal audit programme for information securityPrepare our business for ISO 27001 surveillance and recertification auditsManage corrective actions, non-conformities and audit evidenceDevelop, review and maintain our information security policies and proceduresSupport GDPR, NIS2 and wider information governance requirementsManage our information security incident process, including escalation, investigation and lessons learnedAssess third-party and supplier information security riskSupport information security awareness across the businessReport clearly to senior management on risk, audit performance, incidents, control effectiveness and compliance Technologies: SupportSecurityEmbedded More:
We are a growing technology business in South Wales offering a new Information Security Manager role with real ownership, visibility and influence across the organisation. This position sits between compliance, risk, governance and technical security, with the chance to shape how information security is understood, managed and improved as we grow. You will work closely with senior leadership and teams across IT, Operations, Legal and wider business functions. We offer a competitive salary in line with experience, 25 days holiday plus bank holidays, a company bonus, a pension scheme with 5% company contribution, annual salary review, Cycle to Work Scheme, and flexible start and finish options including an early finish on Friday.
last updated 31 week of 2026