- Company Name
- London North Eastern Railway
- Job Title
- Information Security Manager
- Job Description
-
**Job title:** Information Security Manager
**Role Summary:** Deliver and oversee the Information Security strategy, ensuring protection of systems, data and customer information across the organisation. Lead policy development, compliance, risk management, incident response, and security awareness while collaborating with stakeholders and external bodies.
**Expectations:**
- Implement and continuously improve an organisation‑wide Information Security Framework aligned with GDPR, NIS Directive, PCI DSS, ISO27001 and other relevant standards.
- Maintain compliance and certification status, ensuring timely audits, assessments and remediation.
- Securely manage risk, vulnerabilities, and incidents, minimising business disruption.
- Embedd security into all stages of projects and programmes.
**Key Responsibilities:**
- Own and maintain security policies, procedures, standards and guidelines.
- Oversee technical controls: firewalls, DLP, AV, patch management, intrusion detection and monitoring tools.
- Conduct vulnerability assessments, penetration tests and coordinate remediation.
- Ensure GDPR governance, Data Subject Requests and processor compliance.
- Manage PCI DSS compliance activities including relationships with Acquirers and PCI Council.
- Lead NIS Directive compliance for essential services.
- Maintain ISO27001 certification and drive continuous improvement of the ISMS.
- Manage incident response, investigation and post‑incident reviews.
- Deliver security awareness training and promote a security‑culture.
- Collaborate with internal teams, suppliers and regulators (e.g., NCSC, DfT) to share threat information and best practices.
**Required Skills:**
- Proven IT Security leadership with strong understanding of risk management.
- Expertise in security technologies: firewalls, IDS/IPS, AV, authentication, log management, content filtering.
- Experience delivering security programmes, audits and compliance reviews.
- Ability to translate regulations into practical, business‑focused controls.
- Strong stakeholder communication, change management and team leadership.
- Proficiency in vulnerability management, incident handling and IT governance.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, IT, Cybersecurity or related field.
- Recognised security certifications: CISSP (or equivalent), PCI Security Standards qualification (ISA, PCIP) required.
- Valid ISO27001 Lead Implementer or Auditor certification preferred.