Head of Information Security and Privacy
other jobs Morgan Law
Added before 13 Days
- England,London,City of London
- Full Time, Permanent
- £100,000 - £110,000 per annum
Job Description:
Full job descriptionMorgan Law is working with an arm’s-length Government body in the UK financial sector who are seeking a Head of Information Security and Privacy to join their compliance function and manage a 5 person Information Security and Governance function.
You will be responsible for the implementation and management of the Information management system, including third-party risk, ensuring its effectiveness is regularly assessed through external and internal audits.
You will ensure that the organisation is fully compliant with the required Information Security Standards including ISO 27001, Cyber Essentials, Cyber Essentials Plus, NIST and GovAssure. This includes the responsibility for all of the control documentation and audit process to ensure full compliance is recognised.
The role is hybrid, 2-3 days a week in their office in South London and comes with a very competitive benefits package.
Responsibilities
*Responsible for the development and management of information and cyber security frameworks and overseeing the management of the Information and Records Management.
*Develop and promote policies to ensure compliance with regulations, standards and good practice relating to information security management.
*Responsible for research and awareness of emerging security risks, ensuring solutions, services, policies, procedures and information security education programme are updated in reasonable timeframes to mitigate against new risks.
*Responsible for making sure that the organisation is compliant with Information Security Standards (e.g. ISO 27001), ensuring all governance and audit requirements are undertaken.
*Ensure that the organisation is appropriately protected in line with business needs against information and cyber risks including third-party and suppliers.
Experience Required
*Information Security Manager or equivalent with relevant industry experience.
*Experience of managing and overseeing ISO 27001 audits, Cyber Essentials and Cyber Essentials Plus.
*Develop and lead information and cyber security strategies, roadmaps and maturity plans.
*Provide technical security guidance and assurance to technical and non-technical stakeholders.
*Design and deliver security awareness programmes that improve understanding and influence behaviour.
*Support business continuity and resilience planning, testing and lessons learned.
*Engage senior stakeholders and committees through clear reporting, influence and constructive challenge.
You will be responsible for the implementation and management of the Information management system, including third-party risk, ensuring its effectiveness is regularly assessed through external and internal audits.
You will ensure that the organisation is fully compliant with the required Information Security Standards including ISO 27001, Cyber Essentials, Cyber Essentials Plus, NIST and GovAssure. This includes the responsibility for all of the control documentation and audit process to ensure full compliance is recognised.
The role is hybrid, 2-3 days a week in their office in South London and comes with a very competitive benefits package.
Responsibilities
*Responsible for the development and management of information and cyber security frameworks and overseeing the management of the Information and Records Management.
*Develop and promote policies to ensure compliance with regulations, standards and good practice relating to information security management.
*Responsible for research and awareness of emerging security risks, ensuring solutions, services, policies, procedures and information security education programme are updated in reasonable timeframes to mitigate against new risks.
*Responsible for making sure that the organisation is compliant with Information Security Standards (e.g. ISO 27001), ensuring all governance and audit requirements are undertaken.
*Ensure that the organisation is appropriately protected in line with business needs against information and cyber risks including third-party and suppliers.
Experience Required
*Information Security Manager or equivalent with relevant industry experience.
*Experience of managing and overseeing ISO 27001 audits, Cyber Essentials and Cyber Essentials Plus.
*Develop and lead information and cyber security strategies, roadmaps and maturity plans.
*Provide technical security guidance and assurance to technical and non-technical stakeholders.
*Design and deliver security awareness programmes that improve understanding and influence behaviour.
*Support business continuity and resilience planning, testing and lessons learned.
*Engage senior stakeholders and committees through clear reporting, influence and constructive challenge.
Job number 4077043
Increase your exposure to recruiters with ProJobs
Thousands of recruiters are looking for you in the Job Master profile database, increase your exposure 4 times with a ProJob subscription
You can cancel your subscription at any time.
metapel
Company Details:
Morgan Law
Company size:
Industry:
We specialise in interim, temporary, contract and permanent recruitment across middle and senior management roles. Our directors have worked an averag...