IT Security Manager
Location: Tidworth, Wiltshire
Salary: Up to £65,000
Working Pattern: Full-time, 37.5 hours per week | Hybrid working – up to 2 days from home
Contract: Permanent
The Opportunity
We are working with a major organisation operating across a large, complex and highly regulated environment to recruit an experienced IT Security Manager.
This is a key role within the IT function, taking ownership of the organisation’s IT security strategy, roadmap and security improvement initiatives, while ensuring appropriate controls, compliance and cyber resilience are maintained across the business.
We are looking for someone with a strong technical IT security background who can operate at both strategic and operational level. You will work closely with internal IT teams, cyber security specialists, quality and compliance functions, suppliers and senior stakeholders to continually strengthen the organisation’s security posture.
Key Responsibilities
- Own and drive the organisation’s IT security strategy and roadmap, ensuring security priorities remain aligned with wider business and technology objectives.
- Lead the delivery of IT security initiatives, improvement programmes and remediation activities across the organisation.
- Develop and deliver organisation-wide cyber security awareness and training, ensuring employees understand their responsibilities and measuring the effectiveness of security education.
- Work closely with internal and external cyber security specialists to identify vulnerabilities, assess risks and strengthen security controls.
- Lead and coordinate the response to IT security incidents and breaches, ensuring risks are contained, investigated and appropriately remediated.
- Support disaster recovery and business continuity planning, testing and improvement to minimise the impact of potential disruption.
- Lead and support security audits, compliance activities and remediation programmes, ensuring actions are appropriately prioritised and closed out.
- Ensure new and existing IT systems, infrastructure and technical solutions meet required organisational security standards.
- Work with third-party suppliers and partners to ensure appropriate security controls are maintained throughout the supply chain.
- Provide clear security reporting, risk information and progress updates to senior stakeholders.
- Support wider IT projects and business change programmes, ensuring security requirements are considered throughout the project lifecycle.
- Monitor emerging cyber threats, vulnerabilities, technologies and industry trends, identifying opportunities to proactively improve cyber defence capabilities.
What We’re Looking For
- Strong professional experience within IT Security, Cyber Security or Information Security, ideally within a complex or highly regulated environment.
- A strong technical understanding of IT environments, infrastructure and cyber security controls.
- Experience developing or contributing to IT security strategies, roadmaps and improvement programmes.
- Strong experience of security audits, risk management, remediation and compliance.
- Experience managing or supporting cyber security incidents and security breaches.
- Knowledge of disaster recovery and business continuity within an IT environment.
- Experience working with third-party suppliers and managing security risks across the supply chain.
- Previous exposure to IT service delivery, projects and business change.
- Strong stakeholder management skills with the ability to communicate technical security risks clearly to both technical and non-technical audiences.
- Excellent planning, problem-solving, reporting and organisational skills.
- Relevant technical experience and/or a degree within Computing, Cyber Security, Information Technology or a related discipline.
Why Apply?
This is an opportunity to take significant ownership of cyber and IT security within a large and complex organisation, with the scope to influence strategy as well as deliver tangible improvements.
You will join an established IT environment where security is a business-critical priority, offering a broad remit across cyber strategy, technical security, incident management, compliance, resilience, supplier security and user awareness.
The role offers a salary of up to £65,000, a 37.5-hour working week and hybrid working with the opportunity to work from home for up to two days per week.