Mandarin speaking Information Security Manager (Banking)

People First (Recruitment) Ltd
London, United Kingdom
Today
Job Type
Permanent
Work Pattern
Full-time
Work Location
On-site
Seniority
Senior
Education
Masters
Posted
11 May 2026 (Today)

To see more Chinese jobs please follow us on WeChat: teamchinapf AND pfteamchina

Ref: 23406

Job Title: Mandarin speaking Information Security Manager (Banking)

The Skills You'll Need: Fluent in Mandarin and English, with working experience in Information Security / Cyber Security / IT Risk Management

Your New Salary: Competitive depending on experience

Location: Central London

Job Status: Permanent, office based

Summary:

The Information Security Manager is responsible for establishing, maintaining and improving the bank’s information security framework to protect the confidentiality, integrity, and availability of information assets, particularly for the London Branch. The role develops and oversees security policies, strategies, and controls in line with internal governance, UK regulatory requirements, and industry best practices.

Operating as a “1.5 Line of Defence” within the IT function, the role provides independent security risk oversight, challenges the effectiveness of IT security controls, and supports regulatory compliance and operational resilience.

Information Security Manager - What You'll be Doing Each Day:

Information Security Governance

* Upgrade and maintain the Branch’s information security policies, standards and procedures in line with Head Office policies and regulatory requirements.

* Upgrade and maintain an effective information security governance framework within the Branch.

* Ensure information security policies and procedures are properly implemented and periodically reviewed.

Information Security Risk Management

* Identify, assess and monitor information security risks affecting the Branch.

* Maintain the information security risk register and ensure appropriate mitigation measures are implemented. Provide information security risk reporting to senior management.

Security Oversight and Control Effectiveness

* Provide oversight and challenge to the implementation of information security controls performed by the IT team.

* Monitor the effectiveness of technical and procedural security controls across systems, infrastructure and applications. Coordinate periodic security reviews and internal control assessments.

Cyber Security and Security Monitoring

* Oversee cyber security measures including vulnerability management, access control, security monitoring and incident detection.

* Ensure regular vulnerability assessments, security reviews and penetration testing are conducted.

Incident Management

* Establish and maintain procedures for managing information security incidents. Coordinate investigation, response and reporting of cyber security incidents.

Operational Resilience

* Support the Branch’s operational resilience framework from an information security perspective. Participate in disaster recovery planning, cyber security exercises and resilience testing.

Third-Party and Outsourcing Risk

* Assess information security risks associated with third-party service providers and outsourcing arrangements.

* Ensure information security requirements are incorporated into vendor management and outsourcing governance processes.

Regulatory Compliance

* Ensure compliance with applicable UK regulatory expectations relating to information security, cyber risk and operational resilience. Support regulatory reviews, internal audit and external audit activities.

Security Awareness

* Promote information security awareness across the Branch.

* Organise information security training and awareness programmes for staff.

Others

* Perform any other duties as required by the line manager or Senior Management.

Information Security Manager - The Skills You'll Need to Succeed:

* Excellent verbal and written communication and presentation skills in Mandarin and English.

* Master’s degree or above in Information Security, Computer Science, Information Technology or a related discipline.

* Professional certifications such as CCIE, HCIE, CISSP, CISM, CISA or ISO27001 Lead Implementer are highly desirable.

* Relevant experience in network, information security, cyber security or IT risk management, preferably within the financial services industry.

* Experience in developing and implementing information security governance frameworks.

* Strong understanding of information security standards and frameworks such as ISO 27001, NIST Cybersecurity Framework or CIS Controls.

* Good knowledge of UK regulatory expectations related to cyber security, operational resilience and outsourcing risk.

* Understanding of banking IT environments including networks, applications and infrastructure security.

* Strong analytical and risk assessment skills.

* Ability to communicate effectively with both technical teams and senior management.

* Ability to coordinate incident response and cross-departmental collaboration. High level of integrity and professionalism.

* Strong risk awareness and sense of responsibility. Ability to work effectively in a regulated banking environment.

Please follow us on Linkedin: people-first-team-china

We would be grateful if you could send your CV as a Word document. If your application is successful, you will be contacted within 7 days. We regret that due to the high volume of applications we receive we cannot provide feedback on individual CVs. Please note that we can only consider candidates who are eligible to work in the UK and are able to provide relevant supporting documentation.

People First is committed to increasing diversity, and maintaining an inclusive workplace culture. We welcome applications from all qualified candidates regardless of their ethnicity, race, gender, religious beliefs, sexual orientation, age, marital status or whether or not they have a disability.

People First (Recruitment) Limited acts as an employment agency for permanent and fixed term contract recruitment and as an employment business for the supply of temporary workers. Please note that by applying for this job you accept our Terms of Use and Privacy Policy which can be found on our website

Related Jobs

View all jobs

Dev Ops Engineer

BTC Capital Markets Ltd Chaucer, United Kingdom

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Where to Advertise Cyber Security Jobs in the UK (2026 Guide)

Advertising cyber security jobs in the UK requires a different approach to most technical hiring. The candidate pool is small, heavily vetted and in high demand across government, financial services, critical national infrastructure and the private sector simultaneously. Many of the strongest candidates hold active security clearances, are not actively job-searching through general platforms, and move primarily through specialist networks and trusted referrals. General job boards reach a broad audience but lack the specificity that security professionals expect. Specialist platforms, government-affiliated channels and cleared candidate networks each serve a different part of the market. This guide, published by CybersecurityJobs.tech, covers where to advertise cyber security roles in the UK in 2026, how the main platforms compare, what employers should expect to pay, and what the data says about hiring across different role types.

Cyber Security Jobs UK 2026: What to Expect Over the Next 3 Years

Cyber security is one of the few sectors where demand for talent has never once dipped. Every major technological shift of the past decade — cloud migration, remote working, AI adoption, the proliferation of connected devices — has expanded the attack surface that security professionals are expected to defend. And every expansion of that attack surface has generated more jobs. But the cyber security jobs market of 2026 is not simply a larger version of what it was three years ago. It is a structurally different market. The threats have evolved, the technologies used to combat them have changed, the regulatory environment has tightened considerably, and the roles being created reflect all of that. A job seeker who understands only the cyber security landscape of 2023 is already working with an outdated map. The candidates who will thrive over the next three years are those who understand where the sector is heading — which specialisms are attracting the most investment, which technologies are reshaping defensive and offensive security practice, and how the definition of a cyber security professional is broadening well beyond the traditional image of a network defender in a SOC. This article breaks down what the UK cyber security jobs market is likely to look like through to 2028 — covering the titles emerging right now, the technologies driving employer demand, the skills that will matter most, and how to position your career ahead of the curve.

Penetration Tester Jobs in the UK: What Employers Actually Want in 2026

The demand for skilled professionals in cyber security has never been higher, and penetration testers sit at the very heart of this rapidly evolving industry. As organisations across the UK continue to digitise their operations, protect sensitive data, and defend against increasingly sophisticated threats, the need for ethical hackers has grown dramatically. If you are considering a career in this field—or looking to advance within it—it is essential to understand what employers are really looking for in 2026. This guide breaks down the current expectations, required skills, certifications, and practical experience that can help you stand out in a competitive job market.