Position: Information Security Risk & Compliance Manager
Location: Hybrid / Flexible working options available across hubs:
London: Angel Court (EC2R 7HJ)
Leeds: Bupa Place, Kirkstall Forge (LS5 3BF)
Salford: Salford Quays (M50 3SP)
Employment Type: Permanent, Full-Time (37.5 hours per week)
Salary & Perks: From £64,000 per annum (Negotiable depending on experience) + 10% Annual Performance Bonus + Private Medical Insurance
As a supportive bridge staffing agency, we are proud to connect talented governance, risk, and technology professionals with industry-leading corporate environments. We are currently recruiting on behalf of a premier healthcare and insurance leader to strengthen their Technology Governance, Risk & Control team, protecting millions of customers, colleagues, and business operations globally.
We are seeking an experienced, analytical, and influential Information Security Risk & Compliance Manager to join the team. In this pivotal role, you will lead the management and continuous improvement of Bupa's ISO27001 Information Security Management System (ISMS), drive effective security governance, and ensure alignment with key regulatory obligations.
Key Responsibilities:
Lead the management, continuous improvement, and external audit activities for the ISO27001 Information Security Management System (ISMS).
Coordinate and oversee information security compliance, assurance, control reviews, and risk remediation plans across strategic technology programmes.
Produce high-quality management information, dashboards, and reporting for governance forums, executive committees, and risk committees.
Build strong cross-functional relationships to embed security risk management into everyday decision-making, supporting compliance with standards like the FCA, PRA, and ICO.
Proven experience managing an ISMS, ideally including hands-on ownership of ISO27001 certification and external audit processes.
Strong knowledge of information security frameworks and standards, such as ISO27001, ISO27002, NIST, CIS Controls, and PCI DSS.
Familiarity with UK regulatory environments (e.g., FCA, PRA, ICO) and cloud security risks and controls.
Exceptional stakeholder management, communication, and reporting skills, with the ability to articulate complex security concepts to technical and non-technical audiences.
Experience within a regulated industry (such as financial services or insurance) is highly advantageous.
Working through our staffing partnership opens up an incredible array of wellbeing rewards, professional support, and financial perks:
Pay & Performance: Competitive salary starting from £64,000 (negotiable) + 10% annual performance bonus.
Health & Wellbeing: Comprehensive private medical insurance, access to the Viva global wellbeing programme, and remote healthcare and mental health support.
Workplace Flexibility: Hybrid and flexible working opportunities designed to support a healthy work-life balance.
Financial Protection: Generous pension contributions, 25 days holiday (increasing with service), enhanced family-friendly benefits, and exclusive corporate discounts.