Information Security Manager
A great opportunity to maintain & administer the ISO27001:2013 Accreditation, to support the organization with Internal Audits, Information Security Risk management and ensure compliance with GDPR
Role Title:
Information Security Manager
Location:
Hybrid (Reading when required).
Business Unit:
IT
Org No:
Reports To:
- Head of IT Operations
Role Purpose:
Working with the IT department to assist the company obtaining ISO/IEC 27001:2017 certification. The primary role will be to establish and maintain the ISMS management system and look to continuously improve the compliance of the organisation in relation to international standards.
ISO experience is essential for this role, 27001 experience would be desirable but not required if you have experience in other ISO standards.
Key Responsibilities:
Creation and maintenance of the ISMS management system.
Achieving and maintaining external certifications, including ISO/IEC 27001 and Cyber Essentials certifications. Organising and managing Information Security Group meetings, ensuring that the Group operates according to its terms of reference and that actions are completed.
Designing and delivering training on information security and raising and promoting awareness of good information security practices.
Maintaining the information security risk register.
Monitoring and maintaining supplier and customer contracts and agreements.
Maintaining information security policies, keeping policies up to date and developing new policies as required.
Assisting in responding to questionnaires and enquiries from clients and prospects on information security standards.
Maintaining external documentation on information security practices to provide to clients and assist with tender responses.
Reviewing the information security practices of suppliers and third parties to the company.
Developing information security due diligence procedures on suppliers
Key Deliverables:
Ensuring robust processes are in place to enable compliance with the GDPR and Data Protection Act 2018 and establishment of the information security management framework.
Creation of ISMS management system.
Review of all policies and recommendations for improvement.
Stakeholders:
Head of IT
HR Department
CTO
COO
Company users
Legal
Competencies
Skills
Excellent Administrative skills
Excellent Document Writing skills
Experience of managing ISO standards
Experience with Risk Management principles
Experience with delivering Internal Audits
Skilled communicator with clear and concise written ability.
Excellent personal time management.
Knowledge
Excellent understanding of ISO standards and frameworks.
Detailed and practical understanding of good infrastructure design covering security, monitoring, and alerting.
Good understanding of GDPR and Information security.
Experience with Microsoft SharePoint and Microsoft 365 would be beneficial
Attributes
Attention to detail.
Strong business acumen.
Ability to work with little supervision.
Adaptable and personal willingness to be flexible when situation demands.
Humility.
Qualifications and Experience
A level qualified or equivalent.
5 years of relevant experience.
Internal Auditor or Lead Auditor in ISO/IEC 27001
- Team
- IT Operations
- Locations
- Dynamic Planner HQ
- Remote status
- Hybrid Remote
Dynamic Planner HQ
Workplace & culture
While we are a team, first and foremost, at Dynamic Planner – we understand we are all individuals within that wider culture and environment.
Ultimately, family comes first, which is why each Dynamic Planner team member is fully supported to work flexibly and work remotely where possible. The work-life balance is a two-way street. We find if you give a little, you get a lot back from brilliant and brilliantly committed people.
About Dynamic Planner
Dynamic Planner enables advice firms to match people with suitable portfolios through engaging financial plans. Founded in 2003, it is an end-to-end, risk-based system, using a single definition of risk to ensure nothing is lost in translation in the planning and advice process.
Information Security Manager
A great opportunity to maintain & administer the ISO27001:2013 Accreditation, to support the organization with Internal Audits, Information Security Risk management and ensure compliance with GDPR
Loading application form
Already working at Dynamic Planner?
Let’s recruit together and find your next colleague.