IT Security Manager

Company: Nexus Jobs
Apply for the IT Security Manager
Location: London
Job Description:

Overview

As IT Security Manager, you will lead information security efforts across a large international organisation, guiding corporate functions to mature security controls. You’ll collaborate with cross‑functional teams to promote security practices and act as the SME on regulatory compliance and policy standardisation. You’ll shape BU/Divisional security roadmaps, drive security by design, and support governance, risk, and third-party security activities. This role offers impact across projects, security awareness, and ongoing assurance, with a strong emphasis on stakeholder engagement and pragmatic risk management.

Responsibilities

  • Advise and support corporate functions to improve information security maturity
  • Act as IT Security SME on legal/regulatory compliance
  • Develop and apply security standards aligned with group policies
  • Provide security governance across projects and steering committees
  • Promote security by design and facilitate GRC initiatives
  • Develop BU/divisional security roadmaps and track non-conformities
  • Coach and upskill IT and business teams in security practices
  • Produce and standardise guidance materials (e.g., asset registers, due-diligence)
  • Engage third parties and manage relationships to support security objectives
  • Assist procurement and tendering processes with security considerations
  • Raise baseline controls and standardise where appropriate
  • Support security awareness programs, including phishing campaigns
  • Lead and participate in security working group meetings
  • Ensure alignment of security controls with business requirements
  • Oversee incident management and security assessments (e.g., penetration testing)
  • Manage change leadership in security-related projects
  • Communicate effectively with senior stakeholders to gain buy-in
  • Be office-based in Central London at least 3 days per week

Key requirements

  • 5–8 years of proven information security experience
  • Strong stakeholder engagement and presentation skills to senior leadership
  • Experience leading information security risk governance processes
  • Familiarity with ISO27001 and NIST CSF standards
  • Ability to create, implement and assess information security policies and standards
  • Experience with third-party risk, vendor due diligence, and security assessments
  • Ability to translate complex security risks into practical business implications
  • Budget management and program leadership experience
  • Proven ability to drive security roadmaps and initiatives across business units
  • Experience in security incident management and compliance reporting
  • strong communication and influencing abilities
  • collaborative mindset and ability to bridge tech and business teams
  • problem solving with pragmatic, risk-based thinking
  • ISO27001
  • NIST CSF
  • information security policies and standards

…

Posted: September 30th, 2026