This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We’re looking for a dynamic hands-on Cyber Security Manager to lead, strengthen and mature our operational cyber security capability across a complex, multi-supplier environment. This is a technical leadership role for someone who enjoys staying close to the detail while also leading people, improving processes and driving change. You’ll take ownership of day-to-day security operations, incident response, vulnerability management and identity security, while managing a specialist team and key security suppliers. Working closely with colleagues across technology, data, infrastructure, information governance and audit, you’ll help ensure the organisation is secure by design, resilient in practice and prepared for assurance, audit and regulatory scrutiny. Please note, this is a 12 month fixed term contract.
Job Responsibility:
Operate security controls to defined Minimum Security Baselines and policies
meet SLA/SLOs for patching, vulnerability Mean Time To Remediate, identity hygiene and change success
Lead technical incident response (contain–eradicate–recover) and support ISIM with incident governance and reporting
Lead the technical Disaster Recovery posture for cyber incidents (runbooks, rehearsal/exercises, recovery validation), aligning with ISIM's BCP/DR requirements
Own technical enforcement of Identity & Access Management (e.g., conditional access, privileged access hygiene, risky-user reduction), maintain IAM hygiene KPIs, and implement ISIM's policy requirements in identity platforms
Provide and manage the technical control evidence for CE+ and PCI DSS, and deliver remediation of audit/assessment findings to agreed SLAs (Information Security & Integrity Manager owns the programme and audit responses)
Provide operational evidence (metrics, logs, runbooks) into CAB and Business Management Unit assurance packs
Provide and manage technical control evidence for CE+ and PCI DSS and deliver remediation of audit/assessment findings to agreed SLAs
operate and harden in-scope controls (e.g., endpoint, identity, network, logging) in line with ISIM policy
Commission and technically coordinate penetration testing
own remediation
Manage a security engineering team and suppliers
build skills, SOPs and reusable patterns
Contribute technical content to awareness and training led by ISIM
Requirements:
Proficiency with reporting and visualisation tools (e.g., Power BI, Excel, dashboarding platforms)
Experience working in or alongside portfolio-led environments with multiple concurrent projects or product teams
Aligning to ISO 27001 in complex, multi-supplier environments
Leading technical incident response and remediation
Hybrid cloud security in Microsoft 365 / Azure
Operating security controls at scale (firewalls, endpoint, identity, email/web, vulnerability/patch)
Establishing policies, MSBs, risk registers, DPIAs, and supplier security
Commissioning pen tests and driving remediation
Managing technical teams and suppliers
Experience working with operational, service, delivery or technology-related data
Experience producing dashboards, reports or analytics for senior stakeholders
Experience supporting continuous improvement or lessons-learned processes