Open roles

Global Information Security Manager

Role info
Principal Consultant
​
Full Time
​
Solihull, England, United Kingdom
​
Competitive
Apply Now
​
Share this role

The role

We are seeking…

a pragmatic, hands-on information security leader who can bring structure, pace and clear ownership to nxzen’s cyber and information security environment. You will be comfortable operating across governance and execution: setting standards, managing risk, driving remediation, supporting incidents and working closely with IT, compliance, customers and senior leadership.

This is an opportunity to…

shape and mature the information security function in a growing business serving critical national infrastructure clients. You will have real scope to build the operating model, strengthen our ISO 27001 and resilience position, improve day-to-day control and assurance, and influence how security is embedded as nxzen scales — without inheriting a large, bureaucratic security organisation.

‍


Responsibilites

Key responsibilities‍

The Global Information Security Manager is nxzen's accountable day-to-day owner for information security governance and operations. The role will lead the ISMS, cyber risk and control environment, incident readiness, security assurance and the operating relationship with internal IT, offshore security resources, external SOC/providers, auditors and customers.

  • Own and mature nxzen's ISO 27001 ISMS, including policies, risk treatment, control ownership, objectives, evidence and management review.
  • Own the cyber risk register and monthly control/risk review, escalating material risk acceptance decisions to the Group COO / appropriate executive.
  • Lead vulnerability governance, remediation ageing and control effectiveness, working with onshore and offshore technical resources on execution.
  • Own incident triage and the cyber incident operating model; lead material incidents with Group COO involvement and specialist support where required.
  • Define and embed SOC operating responsibilities, escalation paths, playbooks and effectiveness testing.
  • Own security assurance for audits, certifications and customer requests, with specialist technical support used selectively for complex matters.
  • Lead BCDR security governance and support the broader business continuity programme, ensuring security and technology dependencies are understood and tested.
  • Own information-security policies and standards, including identity/access, device/security requirements and supplier security expectations.
  • Coordinate supplier security assurance and third-party information-security due diligence.
  • Drive recurring security awareness with People and Ch.
  • Produce clear monthly/quarterly security MI, risk and control reporting for the Group COO and ExCo/Board.

‍


The candidate

What we’re looking for

  • An operator rather than a policy-only security professional: someone who will make controls work day to day.
  • Commercial judgement and proportionate risk thinking, particularly in a business serving Critical National Infrastructure clients.
  • Confidence to challenge constructively and escalate when control or customer risk is material.
  • High ownership and follow-through without building unnecessary bureaucracy.
  • A collaborative leader who can work effectively with internal functions including IT, Compliance, P&C, Delivery, Finance, offshore teams and senior cyber specialists.
  • Customer-facing credibility: able to explain nxzen's security position clearly.
  • A pragmatic mindset that balances security, user experience, delivery speed and cost.

Nice to have

  • Experience in utilities, energy, engineering, infrastructure, managed services or other regulated / Critical National Infrastructure sectors.
  • Experience with NIS / CAF, Cyber Essentials Plus, Achilles or comparable customer/supplier assurance frameworks.
  • Experience establishing or testing BCDR / cyber-resilience plans.
  • Previous responsibility for third-party/supplier security assurance.
  • Relevant professional certification such as CISSP, CISM, ISO 27001 Lead Implementer / Lead Auditor or equivalent.
  • Experience working with offshore security teams or distributed global operating models.
  • Experience presenting security risk/control positions to Boards, ExCo or major enterprise customers.
  • Understanding of OT / industrial cyber risk, even if deep OT assurance is provided by specialist colleagues.

‍