Information Security Manager - Liverpool - £55,000-£65,000
The Information Security Manager is responsible for the operational delivery, maintenance, and continuous improvement of the organisation's information security framework.
The role ensures that information assets, systems, and services are appropriately protected against internal and external threats, while maintaining compliance with regulatory, legal, and internal policy requirements.
Reporting to the Head of Information Security & Continuity, the role plays a key part in embedding a strong security culture, managing security risk, and ensuring effective response to cyber incidents. The Information Security Manager works closely with Technology, Risk, Compliance, and business teams to ensure that security controls are proportionate, effective, and aligned to business objectives.
Core Responsibilities
Support the development, implementation, and ongoing maintenance of the Information Security Management System (ISMS) aligned to ISO 27001
Implement and enforce information security policies, standards, and procedures across the organisation
Conduct security risk assessments, ensuring risks are identified, assessed, and managed through appropriate controls
Maintain and track remediation of vulnerabilities and audit findings
Monitor the threat landscape and coordinate responses to emerging risks and vulnerabilities
Lead the investigation and response to information security incidents, ensuring lessons learned and improvements are implemented
Support internal and external audits, including ISO 27001 certification and surveillance activities
Manage third-party and supplier security risk assessments and assurance processes
Work with IT and project teams to ensure security is embedded into system design, development, and change management processes
Deliver and continuously improve the organisation's security awareness and training programme
Ensure compliance with regulatory requirements, including FCA expectations and data protection legislation (GDPR)
Provide regular reporting on security risk, incidents, control effectiveness, and compliance status
Essential Experience
Demonstrable experience in an Information Security or Cyber Security role within a corporate environment
Strong working knowledge of information security frameworks and standards (e.g. ISO 27001, NIST Cyber Security Framework)
Experience in conducting risk assessments and implementing effective security controls
Hands-on experience in incident response, investigation, and resolution
Experience supporting internal and external audits and compliance activities
Experience managing third-party security risk or supplier assurance processes
Ability to translate technical risks into clear business impact for stakeholders
Strong communication, stakeholder engagement, and organisational skills
Understanding of fundamentals of IT Infrastructure
Desirable Experience
Experience working within financial services or regulated environments
Experience with cloud security (e.g. Azure, AWS)
Familiarity with SIEM, vulnerability management, and endpoint security tools
Understanding of data protection and GDPR requirements
Essential Qualifications
Degree or equivalent professional experience in a relevant field
Industry certifications such as CISSP, CISM, or equivalent (desirable)
ISO 27001 Lead Implementer or Auditor (desirable)