Information Security & Data Protection Manager
Core
Operational owner of Information Security, Data Protection, and AI Governance programmes ensuring alignment with ISO 27001, ISO 27701, Cyber Essentials, NIST CSF, and emerging AI regulations.
Role type
Information Security & Data Protection Manager
Builds
Operational ISDP framework, AI governance controls, and certification readiness for Cyber Essentials and ISO standards.
Domain
Information Security, Data Privacy, AI Governance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Information Security frameworks, Data Protection compliance, AI Governance, Risk assessment, Incident management, Supplier audit, Secure coding practices, Cloud platforms, Web operations
Preferred skills
ISO 27001/27701 certification experience, NIST CSF implementation, EU AI Act knowledge, OWASP secure coding, Penetration testing management
Technologies
ISO 27001, ISO 27701, Cyber Essentials, NIST CSF, ISO 42001, NIST AI RMF, EU AI Act, OWASP
Responsibilities
Own the Information Security and Data Protection Framework and documentation; advise IT, development, and business teams on security requirements; run the Business Approved Tools process including AI tool assessments; lead certification readiness for Cyber Essentials; monitor cyber threats and manage incident response and vulnerability scans; conduct risk assessments and maintain the risk register; own the AI Governance framework and inventory.
Seniority
Manager, hands-on IC
