Information Security & Cyber Security Manager
Job Description
Information Security & Cyber Security Manager
\n\nLocation: London (Hybrid)
\nReporting to: CTO
\n\nThe client
\n\nMy client is a profitable and fast-growing UK fintech on a mission to make financial services more accessible, transparent, and customer-centric. FCA Authorised and regulated, they specialise in responsible lending, using technology and data to deliver better outcomes for our customers while operating within a highly regulated environment.
\nA business in scale-up mode — with a modern technology platform, an expanding customer base, and a clear ambition to build a market-leading lending proposition. With around 100 employees, they combine the pace and ownership of a startup with the discipline required in financial services.
\n\nRole Purpose
\n\nResponsible for the design, implementation, operation and oversight our information security and cyber security framework, including governance, cyber security, IAM, operational resilience, supplier assurance and regulatory compliance.
\nYou report directly into the CTO and have full ownership of this fintech's Info Sec and Cyber Security. You will also be this firm's first fulltime Info Sec lead, so setup of function and framework will be your responsibility. This is a rare opportunity for a fin tech this size.
\nYou will also have the opportunity to face off to all relevant business leads in the firm.
\n\n\nKey Responsibilities
\n\n• Information Security Controls & Governance
\n• Information & Cyber Security Assurance
\n• FCA Compliance & Regulatory Security
\n• Identity & Access Management (Entra ID, Conditional Access, PIM, Intune, M365, AWS IAM)
\n• Cyber Security Strategy & Risk Management
\n• Cloud & Technology Security (AWS)
\n• Third-Party Risk Management
\n• Operational Resilience & Incident Management
\n• Security Awareness & Culture
\n• Penetration Testing
\n\n\nEssential Skills and experience
\n• Experience in Information Security, Cyber Security, Technology Risk or Security Governance
\n• Experience in FCA-regulated financial services
\n• Strong knowledge of ISO 27001, NIST and CIS Controls
\n• Strong understanding of Microsoft Entra ID and AWS security
\n• Experience conducting access reviews, risk assessments and supplier assurance
\n• Excellent stakeholder management skills
\nSuccess measures
\n• Mature Information Security Management Framework
\n• Robust access governance and certification processes
\n• Stronger security controls across Microsoft 365, Entra ID and AWS
\n• Improved operational resilience and regulatory compliance
\n• Effective board-level security reporting
\n\n\nCompensation
\n\nSalary: £75,000 – £100,000
\nBenefits: Private health insurance
