Information Security Manager

Sword Group
Aberdeen
1 month ago
Applications closed

Related Jobs

View all jobs

Information Security Manager

Information Security Manager

Information Security Manager

Information Security Manager/Specialist (ISMS)

Information Security Manager

InfoSec Manager - Governance, Risk & Compliance

Sword is a leading provider of business technology solutions within the Energy, Public and Finance Sectors, driving transformational change within our clients. We use proven technology, specialist teams and domain expertise to build solid technical foundations across platforms, data, and business applications. We have a passion for using technology to solve business problems, working in partnership with our clients to help in achieving their goals.

We are excited to announce that we are looking for an experienced Information Security Manager to join the security team. Reporting directly to the CISO you will be responsible for the implementation and delivery of Sword’s cyber security strategy and program.

Key Responsibilities:

The Information Security Manager is primarily a technical role and will be required to operate with high levels of autonomy, effectively translating business objectives and risk management strategies into specific IT security processes enabled by security technologies and services.

Here are the key skills and experience relevant to this role:

Security Operations - Implement and oversee the day to day running of security including M365 Security (Sentinel, Defender, Conditional Access) and Azure security protocols. Vulnerability Management – Proactive and risk-based vulnerability management including attack surface management, system hardening, and cloud security posture management. Service Management – Ability to deliver security as a cohesive service through a combination of internal resources and external service providers. Incident Response – Oversee security incident management and drive enhancements to risk mitigation strategies through ongoing assessments. Continuous Improvement – Deliver the security program through a series of continuous and incremental improvements. Security Culture – Drive improvements in the internal security culture through ongoing awareness, training, simulated phishing campaigns, and security champion’s network. Security Governance – Develop and refine security policies, frameworks, and procedures, maintaining alignment and accreditation ISO 27001 and Cyber Essentials Plus. Risk Management – Conduct security risk assessments across vendors, projects, and internal teams, identifying areas of concern and driving remediation efforts. Regulatory & Client Requirements – Ensure Sword remains compliant with relevant legal, client, and regulatory obligations, keeping pace with evolving security landscapes. Third-Party & Supply Chain Security – Assess and manage security risks related to suppliers and partners, ensuring robust security measures are maintained.

This is a challenging and rewarding role that offers the opportunity to work with a talented team and help our clients as they continue their Digital Transformation journey. If you have a passion for technology and enjoy leading and mentoring technical teams, we encourage you to apply for this role.

Requirements

Here are the key skills and experience relevant to this role:

You should have direct experience, or strong working knowledge, of the following:

Microsoft security architecture and technologies including EDR, Firewalls, SIEM, DLP, IAM, and Email Security. Managing IT security infrastructure , firewalls, intrusion prevention systems (IPSs), web application firewalls (WAFs), endpoint protection, SIEM, vulnerability management, Data Loss Prevention (DLP), Email Security, Identity and Access Management. Cyber Security Frameworks (NIST), regulations such as the General Data Protection Regulations (GDPR) and Network Information Systems (NIS2), and industry standards such as ISO 27001. Experience designing the IT security requirements related to the deployment of applications and infrastructure. Significant experience in a similar role preferably in an international organisation. Experience of working with a range of IT and IT security specialist suppliers.

Qualifications and Personal Skills:

Major industry certification such as CISSP, CISM, CRISC, etc. Certification in relevant Microsoft security technologies. Takes ownership and accountability with an ability to self-manage tasks and activities to consistently deliver results. Dedicated and proactive learner who keeps up to date with security trends and is continuously improving and refining skills. Excellent communication, negotiation and influencing skills – able to influence operational effectiveness across an organisation to achieve results.

Benefits

At Sword, our core values and culture are based on caring about our people, investing in training and career development, and building inclusive teams where we are all encouraged to contribute to achieve success.

We offer comprehensive benefits designed to support your professional development and enhance your overall quality of life. In addition to aCompetitive Salary, here's what you can expect as part of our benefits package: 

Personalised Career Development:We create a development plan customised to your goals and aspirations, with a range of learning and development opportunities within a culture that encourages growth. 

Flexible working:Flexible work arrangements to support your work-life balance. We can’t promise to always be able to meet every request, however, are keen to discuss your individual preferences to make it work where we can. 

A Fantastic Benefits Package:This includes generous annual leave allowance, enhanced family friendly benefits, pension scheme, access to private health, well-being, and insurance schemes.

At Sword we are dedicated to fostering a diverse and inclusive workplace and are proud to be an equal opportunities employer, ensuring that all applicants receive fair and equal consideration for employment, regardless of whether they meet every requirement. If you don’t tick all the boxes but feel you have some of the relevant skills and experience we’re looking for, please do consider applying and highlight your transferable skills and experience. We embrace diversity in all its forms, valuing individuals regardless of age, disability, gender identity or reassignment, marital or civil partner status, pregnancy or maternity status, race, colour, nationality, ethnic or national origin, religion or belief, sex, or sexual orientation. Your perspective and potential are important to us. 

If we can do anything to help make the hiring process more accessible, please let our talent acquisition team know when you apply so we can support any adjustments. 

Get the latest insights and jobs direct. Sign up for our newsletter.

By subscribing you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Navigating Cybersecurity Career Fairs Like a Pro: Preparing Your Pitch, Questions to Ask, and Follow-Up Strategies to Stand Out

In a world where digital threats are escalating and online infrastructure underpins nearly every aspect of our personal and professional lives, cybersecurity has swiftly become one of the most sought-after career fields. Demand for skilled cybersecurity professionals outstrips supply, both in the UK and globally. From ethical hackers and penetration testers to governance, risk, and compliance (GRC) specialists, the opportunities are extensive—and lucrative. Amidst this surge in demand, cybersecurity career fairs provide an invaluable chance to meet potential employers face-to-face, gain industry insights, and make connections that can accelerate your career trajectory. Unlike applying to countless jobs online, these events bring companies, security leaders, and aspiring candidates together under one roof. When approached with the right strategy, a single conversation at a cybersecurity fair can open the door to your dream job. In this comprehensive guide, we’ll explore how to prepare thoroughly, engage confidently, and follow up effectively after a cybersecurity career fair. By incorporating these insights into your approach, you’ll stand out from the crowd and maximise your chances of securing the perfect role in this fast-growing field.

Common Pitfalls Cyber Security Job Seekers Face and How to Avoid Them

The cyber security industry in the UK and worldwide is experiencing rapid growth. With cyber attacks growing in sophistication and frequency, organisations are investing more resources than ever into defending their digital assets. From penetration testers and threat analysts to security architects and compliance officers, cyber security professionals are in high demand across a variety of sectors—including finance, healthcare, government, and retail. Yet, in spite of this high demand, the process of landing a cyber security role can be more challenging than many candidates anticipate. The stakes are high: prospective employers entrust cyber professionals with their most sensitive data, their compliance posture, and often their core business operations. Therefore, they’re looking for candidates who can demonstrate not just technical know-how, but also excellent communication, adaptability, and an awareness of the broader business context. In this article, we’ll explore the most common pitfalls that cyber security job seekers face, especially in the UK market, and how to avoid them. Whether you’re a recent graduate, a professional transitioning from a different field, or an experienced practitioner aiming for a senior role, these insights will help you stand out and secure the opportunities that fit your skill set and career goals.

Career Paths in Cybersecurity: From Entry-Level Roles to Leadership and Beyond

Cybersecurity has emerged as one of the most critical and fastest-growing fields in technology today. With data breaches and ransomware attacks making headlines, organisations of all sizes and in every sector are recognising the urgent need for robust cybersecurity measures. As a result, professionals with the right mix of technical and strategic skills are in high demand—offering competitive salaries, diverse career paths, and ample opportunities for progression. How do you begin a career in cybersecurity, and how can you advance from technical roles to leadership positions? In this in-depth guide, we explore the cybersecurity career ladder, outlining roles at entry, mid, and senior levels, as well as the key skills, qualifications, and experiences you’ll need to climb it. Whether you’re an aspiring cybersecurity analyst, a seasoned penetration tester, or an IT professional looking to pivot, this article will help you understand the paths available and how to chart your course towards success in the thriving UK cybersecurity market.