Information Security Manager
Summary
Manages EXA Infrastructure's information security team and program in London (hybrid, ~3 days in office): oversees security monitoring, incident management, policies, and ISO27001/SOC2 compliance, manages outsourced security providers, and advises executives on emerging threats. Requires hybrid cloud security knowledge across Azure, AWS, and GCP.
Role Purpose
As the Information Security Manager, you will be responsible for managing and maintaining the EXA information security team and program, including procedures and policies designed to protect enterprise communications, systems and assets from both internal and external threats.
You will need to work alongside other executives to align security initiatives with broader business objectives and offer specialist advice and support regarding anticipating, accessing and actively managing new and emerging threats. You will oversee the company's IT security strategy and ensure corporate security policies, standards and procedures align with the current threat landscape and customer requirements and that company policies and are upheld by all.
The complexity of this position requires a management approach that is engaging and collaborative, with an ability to work with other leaders to set the best balance between security requirements and other priorities at the enterprise level.
Key Responsibilities
- Maintain the cybersecurity capabilities, processes and technologies that help protect EXA Infrastructure’s security posture and continuously improve these where required..
- Work with other infrastructure and application teams to understand the technology landscape and assist with aligning to EXA Infrastructure’s security posture.
- Deliver on the existing cyber security program, collate and present evidence for management awareness and regulatory scrutiny where required.
- Oversee a small team responsible for security monitoring, incident management and engineering of security technologies into EXA Infrastructure’s environment.
- Maintain the team responsible for the development of effective policies to secure sensitive data and ensure information security and compliance with relevant regulatory, legal and customer certification requirements (ISO27001, SOC2)
- Manage multiple outsourced security providers and ensure the quality and effectiveness of the services.
- Performing research to stay abreast of new technologies and security vulnerabilities.
- Continue championing the culture of appropriate cyber security risk assessment and risk acceptance across from stake holders to end users and IT professionals
- Review, endorse and align information security risk management and mitigation plans
- Advise management on the appropriate cyber security solutions and technologies to remediate risks to an acceptable level.
- Review and addressing cyber-security incidents as well as gain buy-in and oversee remedial activities to mitigate risks which are outside of the risk tolerance.
- Assist in the change management process to ensure changes encompass cyber security considerations.
- Conversing regularly with leaders and employees to ensure all IT security policies are deployed, revised, sustained and overseen effectively.
Individual Profile
- Knowledge on secured on-premise and public cloud deployments for infrastructure and applications running on a hybrid landscape that includes all public cloud technologies: Azure, GCP, AWS
- Knowledge on Security Software and hardware, including but not only: Privileged Access Control systems, Perimeter security, End point security, Micro Segmentation, Threat analytics
- An ability to motivate and manage a team of information security staff supporting the organization's goals and an ability to lead the continuous process of evolving the information security vision for the future
- Deep understanding of the security industry in UK, Europe and the US.
- An ability to cultivate and build collaborative working relationships with a broad range of enterprise stakeholders
- Create and deliver effective presentations as a means for communicating project and deliverable progress
- Ability to weigh the relative costs and benefits of potential actions and identify the most appropriate one
- Drive change through the ability to effectively influence others to modify their opinions, plans, or behaviours.
- Communicate complex and technical issues to diverse audiences, orally and in writing, in an easily-understood, authoritative, and actionable manner
- Strong interpersonal, verbal, and written communication skills in English
- Excellent organisational skills with the ability to multi-task
- Ability to manage own time effectively and to be prompt and punctual
Our working environment
We are committed to working in the location where we do our best work. As a small and growing company with great offices in great locations, most employees will aim to be in the office 3 days a week and 2 days working from home/ other locations.
Here at EXA, we believe the future includes everyone, we are open to all applications to create an environment and culture that includes one and all. We are a proud global community, that wants to drive diversity of thought though our employees and culture. We want you to come as you and make yourself and EXA successful.