Information Security Manager
Information Security Manager
3-month contract
Birmingham or Central London (hybrid working)
£600 - £650 per day (inside IR35)
IT Information Security Manager sought by a well-known, public-facing organisation operating across a complex and critical transport environment, providing services to hundreds of thousands of customers.
As part of a Critical National Infrastructure environment, the IT Information Security Manager will play a crucial role in the day-to-day management of the technical cyber security landscape, SOC services and wider information security management.
Reporting to the Head of IT and managing an IT Security Operations Engineer, this is a hands-on leadership role with responsibility for ensuring appropriate cyber security controls are in place, managing security risk and incidents, and maintaining ongoing compliance with relevant regulatory frameworks and industry standards.
Key Responsibilities
, Work with the Head of IT to create, maintain and deliver a robust Cyber Security Roadmap to minimise organisational risk
, Develop and maintain the Information Security Strategy, security policies and procedures
, Provide day-to-day oversight of the technical cyber security environment and associated security controls
, Manage the organisation's third-party SOC service, ensuring effective monitoring, escalation and response
, Take ownership of cyber security incidents, coordinating prompt technical response, remediation and mitigation
, Embed Security by Design principles across technology projects and initiatives
, Drive a strong culture of IT and cyber security awareness and responsibility across the organisation
, Conduct ongoing security threat, risk, capability and maturity assessments
, Manage vulnerability management, penetration testing schedules, remediation activities and threat intelligence
, Maintain and develop incident management processes and security playbooks
, Conduct and respond to security audits and support ongoing regulatory and standards compliance
, Support the implementation and ongoing management of ISO 27001, including gap analysis and remediation
, Oversee areas including patch management, PCI DSS, NIS, GDPR and data protection
, Engage and manage specialist third-party security providers across areas such as penetration testing, forensic analysis and security auditing
, Provide clear security reporting to senior stakeholders
Required Experience
, Previous experience working in a Cyber Security Manager, Information Security Manager, Cyber Risk Manager, Cyber Threat Manager, IT Security Manager or similar role
, Strong experience spanning both information security strategy/framework management and oversight of technical security controls
, Experience setting up, running and/or managing SOC services, including third-party SOC providers
, Strong cyber incident management experience, including coordinating technical response and remediation
, Extensive knowledge of security standards and frameworks including ISO 27001 and NIST
, Experience assessing an organisation against security standards, identifying gaps and delivering remediation plans
, Extensive experience with GDPR, data protection and relevant security legislation/regulatory frameworks
, Knowledge of security assessment methodologies including threat modelling, controls assessments and risk assessments
, Experience across vulnerability management, penetration testing, threat intelligence, incident playbooks and patch management
, Solid understanding of IT infrastructure fundamentals including networks, operating systems, databases, Azure and Microsoft 365
, Experience with Rapid7, Sophos MTR, SolarWinds and ServiceNow would be highly advantageous
, Exposure to PCI DSS and NIS would also be beneficial
, Excellent stakeholder management and reporting skills
, Relevant security qualifications such as CISSP, CRISC, CISM or Security+ are highly desirable
The successful candidate will need to be comfortable working across both the strategic and operational sides of information security, with the ability to engage senior stakeholders while maintaining sufficient technical depth to oversee security controls, incidents and third-party security services.
- Duration: 3 months
- Rate: £600 - £650 per day + inside IR35
- Location: Birmingham, England
- Type: Contract
- Industry: IT
- Recruiter: context recruitment
- Contact: Sophie Sanderson
- Tel: 02381 680 407
- Email: to view click here
- Posted: 2026-09-08 16:44:26 -
- View all Jobs from context recruitment
More Jobs from context recruitment
- SecOps Engineer
- Network Infrastructure Team Lead
- Service Desk Manager
- Senior Service Desk Engineer
- AI Architect
- IT Field Engineer
- Head of IT
- Head of Digital Solutions
- Senior Cloud Infrastructure Engineer
- IT Project Delivery Engineer
- IT Product Manager
- Incident Management Analyst
- IT Programme Manager
- IT Account Manager
- IT Business Analyst
- Service Desk Manager
- Construction Manager
- Junior Service Desk Analyst
- Enterprise Architect
- Senior Infrastructure Engineer