CloudMargin
Posted 1mo ago

Information Security Manager

CloudMargin
London, United Kingdom
OnsiteFull Time
Responsibilities
  • owning ISMS
  • leading audits
  • securing platform
Requirements
  • 5+ years in information security/GRC in technology or financial services
  • Experience managing an ISO 27001:2022-aligned ISMS
  • External audits
  • SaaS/cloud security
  • RFIs/RFPs
  • Budgets, and supplier management
Technical tools mentioned
OWASPJiraConfluenceAI

Job description

Primary Purpose of Role

As our Information Security Manager, you’ll own the information security function. You will be the first point of contact for everything from ISMS governance to platform security. You’ll run and evolve an established ISO 27001:2022-aligned programme with real scope to shape it, working directly with our CTO, VP of Engineering and commercial leadership. It’s a hands-on role for someone ready to step up and build their reputation as a security leader.


Core Accountabilities

  • Own and improve the ISMS and Risk Management Framework, including governance meetings, annual audits and policy/process documentation
  • Lead reviews of security policies and procedures, adapting them to business needs and generating new policies where required
  • Deliver and promote relevant security awareness training and security programs (e.g. phishing simulations)
  • Own responses to client and prospect RFIs, RFPs and security questionnaires
  • Partner with the Technology team to strengthen our SaaS platform’s security posture, including secure development practices (e.g. OWASP), infrastructure security and data protection, and help developers understand their security responsibilities
  • Support the CTO and VP of Engineering in defining and maintaining technical security standards
  • Build scalable, proactive security processes, making use of tools and AI where appropriate


Experience

  • 5+ years' experience in Information Security, Governance, Risk Management and/or Compliance roles in a technology / financial services setting
  • Demonstrable experience managing an ISMS in an ISO 27001:2022 aligned environment, including external audits and auditors
  • Managing budgets and suppliers
  • Exposure to securing SaaS or cloud-hosted platforms, including secure development practices (e.g. OWASP), infrastructure security and data protection
  • Experience responding to client security questionnaires, RFIs and RFPs, ideally using automation or managed tooling


Skills

  • Detailed knowledge of the ISO 27001:2022 standard
  • Understanding of application and cloud security fundamentals (e.g. OWASP Top 10, secure SDLC) and the ability to translate these for development teams
  • Excellent administrative skills, including document management, audit management, reporting and presenting (Jira and Confluence beneficial)
  • Communication skills supporting diverse audiences from external parties to internal technical stakeholders
  • Process improvement and automation – comfortable using tools and AI to scale security operations
  • Commercial awareness


Education / Professional Qualifications

Relevant professional certifications are desirable but not required (e.g. ISO 27001:2022 Lead Implementer / Lead Auditor, CISSP, CISM, CCSP or cloud security certifications)

About CloudMargin

Automated cloud-based collateral and margin management software platform.

Year founded
2014
Employees
62
Industries
Organization type
Private
Latest investment
Raised $21.80M Series B (2021) — led by Deutsche Bank, Citigroup, Deutsche Börse
Headquarters
GB

Similar jobs

Information Security Manager roles near London, undefined
12h
Save
Mark Applied
Hide
Information Security Manager
London, England, United Kingdom
OnsiteFull Time
Millennium Hotels and Resorts
Millennium Hotels and Resorts: Global hospitality group that owns and operates international hotels.
Develop and manage IT security strategy, PCI-DSS compliance, incident response, audits, security solutions, stakeholder consulting, and security awareness across UK hotel properties.
1w
Save
Mark Applied
Hide
Information Security Manager - HS2 Main Works
London, England, United Kingdom
OnsiteFull Time
Skanska
SkanskaNasdaq Stockholm: SKA B: Provides construction, civil engineering, and project development services.
Experience with Cyber Essentials, CISM or equivalent, cloud and security technologies, risk management, UK DPA/GDPR, and written and spoken English. A recognized security qualification is required.
ISO 27001, Firewalls, IDP, IAM, MFA, SSO, DLP, CASB, MDM, EDR, Cloud technology
1w
Save
Mark Applied
Hide
INFORMATION SECURITY MANAGER (f/m/d)
Frankfurt am Main or London or New York City or Singapore or Mumbai or Kuala Lumpur or Dubai
OnsiteFull Time
360T
360T: Provides electronic trading platforms for foreign exchange and money markets.
3+ YOERequires a computer science degree or equivalent, 3+ years in IT security, security standards and compliance experience, independent ownership, and fluent English; German is preferred.
ISO 27001:2022, ISMS, DORA, NIST, SOC1, SOC2, ISAE3402
2w
Save
Mark Applied
Hide
Information Security Manager
London, England, United Kingdom
HybridFull Time
RVU
RVU: Operates online platforms for comparing and switching consumer services
Background in information security, cloud-native experience, control documentation, security risk management, and programme delivery; relevant certs (CISSP/CRISC/CISM) desirable.
Vanta, GenAI
2w
Save
Mark Applied
Hide
Information Security Manager
London or Milton Keynes
£90k-£100k/yr HybridFull Time
Recognise Bank
Recognise Bank: Provides specialized banking and lending solutions for UK businesses.
Hands-on technical security experience running SIEM/EDR, vulnerability and identity security, incident response, cloud security (AWS/Azure), scripting (PowerShell/Python) and SOC operations; industry certs or equivalent experience required.
SIEM, EDR, Microsoft Entra ID, Microsoft Purview, AWS, Azure, PowerShell, Python, Microsoft Defender, Chronicle, GuardDuty, SentinelOne, Tenable, MSSP, MSP
3w
Save
Mark Applied
Hide
Senior Information Security Manager
Madrid or London
HybridFull Time
Ebury
Ebury: Provides international payments and currency risk management for businesses.
5+ YOE5+ years in information security/GRC, strong knowledge of ISO 27001, NIST, GDPR, DORA, risk management, audit ownership, third-party risk, and stakeholder communication; industry certifications preferred.
OneTrust
3w
Save
Mark Applied
Hide
Information Security Manager
London, England, United Kingdom
HybridFull Time
Faculty
Faculty: Provides applied AI services and decision intelligence software.
Proven hands-on ISO 27001 management and auditing experience, cloud security knowledge (AWS/Azure/GCP), strong stakeholder communication, and eligibility for UK Security Check (SC).
ISO 27001:2022, AWS, Azure, GCP
3w
Save
Mark Applied
Hide
Information Security Manager
Cambridge, England, United Kingdom
HybridFull Time
Speechmatics
Speechmatics: Provides speech recognition and voice AI software for developers.
Experience in cybersecurity/IT security management, incident management, GRC frameworks; CISSP or CISM (or equivalent); technical credibility and automation focus.