Security & Privacy Manager
Who you’ll be joining
We’re problem solvers at heart. Sometimes the answer is technology, sometimes it is strategy, and sometimes it is a strong cup of tea and a bit of thoughtful conversation. Whatever it takes, we work it out with our clients.
We’re an IT consultancy that helps organisations get the best out of their technology. That means keeping them secure and keeping the bad guys out, making sure everything works and is easy to use, and doing smart things with data and software to give their business an edge. It is important work, and we care about doing it well and for the right reasons.
Life at Waterstons is friendly, flexible and built on trust. We hire people who are curious, thoughtful and good at getting to the heart of a problem. You get support, trust and room to grow in a place that still feels human. The unlimited holidays and private healthcare are a nice touch, although most people stay because it feels like the right place to do good work with good people.
What You’ll Be Doing
As our Security & Privacy Manager, you will be responsible for the day to day management of Waterstons Information Security, Data Protection and wider business compliance activities. You will work closely with colleagues across the business including Systems & Facilities, People & Culture and senior stakeholders, providing guidance and support to ensure we maintain strong security and privacy standards.
You will also take ownership of Waterstons ISO27001 management and provide advice across the organisation on all aspects of information security and data protection. On occasion you may support with client related matters where required.
This role requires someone who can think strategically as well as operationally, considering how decisions may impact business risk, reputation and compliance status, while driving continual improvement across the organisation.
Your Day-to-Day
Managing and completing security and privacy activities in a timely and thorough way
Maintaining Information Security and ISO27001 documentation and records including policies, registers, incidents, risks, supplier due diligence and audits
Maintaining Data Protection documentation and records including privacy notices, registers, rights requests, agreements, asset registers and data maps
Assessing and managing security and privacy risk across the business, identifying appropriate remediation actions while taking a pragmatic and balanced approach
Managing incidents and breaches including triage, investigation, mitigation and communications
Managing internal and external audits
Supporting supplier due diligence alongside the Purchasing Manager
Advising and supporting colleagues across the business on security and privacy matters at all levels
Working with People & Culture on employee security related activities
Working with Facilities on physical security controls
Managing priorities and workload independently, adapting as business needs change
Keeping up to date with emerging security and privacy developments across Waterstons locations
Driving continual improvement across security, privacy and compliance practices
Supporting wider compliance requirements across the business where required
What we're looking for
If some (or most) of the following sound like you, we'd love to hear from you:
At least five years experience in Information Security with a strong understanding of ISO27001 controls and best practice
Degree level education or equivalent industry experience
Solid IT foundation knowledge including Microsoft 365, SharePoint, Office applications and an understanding of Active Directory and security tools
Experience in risk assessment and incident management with the ability to consider wider business implications
Data Protection Practitioner certification and or practical experience of Data Protection management and UK GDPR
Strong attention to detail combined with the ability to make pragmatic, risk based decisions
A willingness to learn, develop and expand your knowledge
Excellent customer service mindset and stakeholder engagement skills
Strong communication skills with a calm, approachable and adaptable style, with the ability to be firm and decisive when required
Nice to have
ISO27001 Lead Auditor or Implementer qualification
Experience or familiarity with frameworks such as Cyber Essentials, NIST, NIS, CAF or SOC2
Wider knowledge of information security standards and best practice
Security certifications such as CISSP, CISM or CISA
Experience reviewing legal agreements relating to security and data protection
Experience writing or reviewing policies
Experience participating in internal or external ISO audits
Experience developing or delivering training
Broader technical knowledge of IT systems and security controls
How We Take Care of You
As well as offering a competitive salary, we have an attractive benefits package including:
A healthy work life balance with flexible and agile working being the norm
Unlimited holiday allowance
EV car scheme (salary sacrifice)
Room to grow with supported development opportunities and sponsored training
Enhanced family policies
If you ever need it, company sick pay and life assurance
Supported wellbeing with regular initiatives, an employee assistance programme and private medical insurance
Flexible benefits such as a dental scheme, eye care support, season ticket loan and cycle to work
We require a security check to be carried out on all colleagues due to the nature of some of our clients’ industries.
Waterstons is committed to creating and an inclusive, understanding, and flexible place to work. We value diversity, equality and inclusion and encourage everyone to 'bring their whole selves' to work. We believe that a company that works to truly embrace and value diversity, create an environment where everyone from any background can do their best work, and feel valued and appreciated is a better company to work for.
Privacy Statement
Waterstons are gathering the data in this application for the purpose of recruitment and to ensure we can contact you regarding this application. For information about what we do with your personal data see our Privacy Notice.
- Locations
- Durham, England, United Kingdom
- Remote status
- Hybrid
- Yearly salary
- £60,000 - £65,000
- Job Type
- Experienced Role
Already working at Waterstons?
Let’s recruit together and find your next colleague.