Information Security and Privacy Manager
Location: West Midlands
Salary: £75,000 - £85,000
Hybrid working: Once a week in the office
Are you passionate about information security and privacy? We're seeking an experienced Information Security and Privacy Manager to lead the charge in delivering robust security solutions within a dynamic, regulated environment. This role is vital in driving security initiatives, safeguarding sensitive data, and ensuring compliance with privacy legislation.
About the Role:
As the Information Security and Privacy Manager, you will report directly to the Executive Director of Finance & Shared Services, playing a key role in protecting the organization's reputation and ensuring regulatory compliance. You will be responsible for building a strong security culture, leading internal security assessments, managing data privacy risks, and ensuring compliance with industry regulations such as GDPR and ISO27001. This is a hands-on role suited to an experienced Data Protection Officer (DPO) or privacy professional with deep knowledge of compliance frameworks and information security standards.
Key Responsibilities:
1. Define and implement information security policies and processes across the organization.
2. Serve as the subject matter expert in security and privacy, advising colleagues and senior stakeholders up to board level.
3. Lead internal security risk assessments, security training programs, and oversee ISO27001 audits.
4. Manage security incidents and breaches, ensuring swift response and mitigation.
5. Ensure ongoing compliance with GDPR and other relevant privacy regulations.
6. Perform Data Privacy Impact Assessments (DPIA) and Data Protection Audits.
7. Collaborate with internal teams to align security and privacy measures with business needs.
8. Monitor updates in privacy legislation and drive organizational compliance.
Technical Expertise:
1. Proven expertise in information security and privacy, with certifications such as CISSP, CISM, ISO27001 Lead Auditor, GDPR Practitioner, or equivalent.
2. Strong knowledge of compliance frameworks (ISO27001, GDPR) and experience in IT security.
3. Significant experience as a Data Protection Officer (DPO), managing data privacy programs and ensuring GDPR compliance.
4. Expertise in Data Privacy Impact Assessments (DPIAs), handling subject access requests, and managing data breaches.
5. In-depth understanding of privacy and data protection legislation, including GDPR.
Qualifications & Experience:
1. 3+ years of experience in assurance or managerial roles, with 4+ years in security and/or privacy roles.
2. Demonstrable experience as a DPO or in a privacy-related role.
3. Strong influencing skills, with experience engaging senior stakeholders and executives.
4. Excellent communication skills and the ability to build trusted relationships across the organization.
5. Comprehensive understanding of risk management and commercial acumen to support procurement teams.
6. Ability to thrive in a fast-paced environment, solve challenges proactively, and drive progress.
What’s in it for you?
This is a critical opportunity to safeguard data and lead security initiatives within an organization that manages large amounts of sensitive data in a regulated market. You’ll work in a collaborative environment, with the chance to make a significant impact on the business while advancing your career.
If you’re ready to step into a pivotal role in information security and privacy, we’d love to hear from you.
#J-18808-Ljbffr