Naukrijobs UK
Register
London Jobs
Manchester Jobs
Liverpool Jobs
Nottingham Jobs
Birmingham Jobs
Cambridge Jobs
Glasgow Jobs
Bristol Jobs
Wales Jobs
Oil & Gas Jobs
Banking Jobs
Construction Jobs
Top Management Jobs
IT - Software Jobs
Medical Healthcare Jobs
Purchase / Logistics Jobs
Sales
Ajax Jobs
Designing Jobs
ASP .NET Jobs
Java Jobs
MySQL Jobs
Sap hr Jobs
Software Testing Jobs
Html Jobs
IT Jobs
Logistics Jobs
Customer Service Jobs
Airport Jobs
Banking Jobs
Driver Jobs
Part Time Jobs
Civil Engineering Jobs
Accountant Jobs
Safety Officer Jobs
Nursing Jobs
Civil Engineering Jobs
Hospitality Jobs
Part Time Jobs
Security Jobs
Finance Jobs
Marketing Jobs
Shipping Jobs
Real Estate Jobs
Telecom Jobs

Information Security Manager

Job LocationNewcastle Upon Tyne
EducationNot Mentioned
SalarySalary negotiable
IndustryNot Mentioned
Functional AreaNot Mentioned
Job TypePermanent, full-time

Job Description

A brand new role is available for an experienced Information Security Manager/Analyst to work for a large organisation in Newcastle Upon Tyne.The Information Security Manager contributes to the effective protection of the firm against cybercrime and acts as an internal specialist for Information Security, Data Protection and GDPR. The ISM is responsible for the maintenance of ISO27001. The ISM will work with the wider firm to deliver a commercial, pragmatic, effective and risk based approach to activities that provide appropriate access to, and protect the confidentiality, availability and integrity of Client, Staff, and Firm information.The Role:

  • Responsibility for providing proactive and pragmatic advice as the internal information security expert to the firm.
  • Responsible for the management and maintenance of the Firms Information Security Management System in line with the ISO27001 Certification and managing associated external continual assessment visits.
  • Take a proactive approach to mitigating risk by working with stakeholders to maintain and monitor the Firms Information Security Risk Register.
  • Engage with stakeholders to implement information security policies and procedures that meet external standards and internal needs of the firm.
  • Chairs, documents and coordinates the activities of the Information Security Committee.
  • Provides direct training and oversight to all staff, partners and or other third parties.
  • Takes the lead and initiates, facilitates, and promotes activities to create Information Security awareness and best practice within the Firm and ongoing awareness and education activities.
  • Manages the Firms third party reviews to meet internal standards and in line with ISO27001.
  • Perform Information Security Risk Assessments and Privacy Impact Assessments for the Firm.
  • Support the wider firm on impact assessments, business continuity, disaster recovery and data protection risks.
  • Acts as an Internal Auditor for Information Security Incident issues and manages the Information Security audit plan including identifying areas of good practice, areas for improvement and any training needs.
  • Responsible for managing the Information Security Incident Process and ensuring that any mitigation measures are implemented and reviewed.
  • Proactively advises the Firm of current and emerging cyber threats and provides information about Information Security technologies and related regulatory issues.
  • Key member of the Disaster Recovery and Business Continuity Team
  • Act as the Firms Data Protection Officer including coordinating and responding to subject access requests.
  • Works with external consultants on the implementation of GDPR.
  • Responsible for keeping abreast of current and emerging security threats, technologies and legislative changes.
  • Managing the Supplier on-boarding process
  • The Person:
  • Working knowledge of ISO 27001:2013 & other leading industry standards Knowledge of best practice standards for Information Security and Cyber Security (e.g. Cyber Essentials and Cyber Essentials Plus)
  • Experience in information security management and control and collaborating with stakeholders to mitigate risk while delivering business improvements
  • A broad understanding of information security risks, issues and measures and providing business focused solutions.
  • Comprehensive knowledge of current security management tools/ technologies and the external legislative landscape.
  • Experience of data protection and knowledge of GDPR
  • Demonstrated analysis, planning, research and creative problem solving skills
  • Effective interpersonal, consulting, persuading and negotiation skills across all levels
  • Well-developed oral communication and presentations skills
  • Experience of developing and delivering information security related training programs
  • Effective writing skills and experience in policy writing
  • Desirable, but not essential, knowledgeable on the NHS Information Governance Toolkit.
  • Experience in project management
  • Qualifications required: Preferably CISM Certified (Certificate in Information Security Management)Based in Newcastle City Centre, great benefits available including 25 days holiday plus bank holidays, pension scheme, flexible benefits options.Office hours - Monday to FridaySalary is negotiable for this role. Required skills
  • Risk
  • Cybercrime
  • ISO Procedures
  • Information Security
  • GDPR
  • Keyskills :
    Risk Cybercrime ISO Procedures Infmation Security GDPR

    APPLY NOW

    © 2019 Naukrijobs All Rights Reserved