Information Security & IT Manager
Listed on 2026-07-22
-
IT/Tech
Cybersecurity, Information Security & Data Protection
The Role
We are looking for an IT & Information Security Manager to take ownership of our IT systems, infrastructure and security. You’ll manage our Microsoft 365 environment, devices and IT support for a hybrid workforce, while helping to modernize our technology through cloud migration and improved monitoring. You’ll also lead our ISO 27001 and Cyber Essentials certifications, manage security policies and audits, oversee business continuity, and work with colleagues across the business to maintain a secure, reliable and compliant IT environment.
This role has real autonomy, and it’ll suit someone who wants to build something they’re proud of rather than simply clock in and out.
You’ll be based in or near Birmingham, working hybrid with office visits as needed for hardware and infrastructure work. You’ll have genuine autonomy and the space to shape how we do security and IT as the business grows including developing our ISMS into something you’re proud of.
Team culture is at the heart of what we do, so we’re looking for someone who brings a positive, collaborative attitude. We value a supportive and ego‑free environment, where everyone can share ideas and grow together. If you’re excited to be part of a team that builds each other up and tackles challenges together, we’d love to meet you!
What you’ll be doing
IT & infrastructure
- Own office infrastructure and all staff hardware end‑to‑end procurement, setup, asset lifecycle, joiner/leaver provisioning, and day‑to‑day fixes for the Birmingham office.
- Own identity, access and endpoint management company‑wide across our Windows estate Entra , Microsoft 365, and Intune with most staff hybrid or fully remote, so remote provisioning and support is central to this role, not an edge case. Experience with Mac management would be a bonus.
- Own the relationship with our outsourced IT support provider performance, SLAs, escalations and renewals and act as the senior escalation point for IT.
- Help drive our ongoing move from remaining on‑premise infrastructure to cloud, and support the decommissioning that follows.
- Strengthen monitoring, logging and alerting so we can spot and investigate anomalies early.
- Contribute to IT planning and budgeting, and report on our security and IT posture to leadership as needed.
Information security & compliance - Take ownership of our ISO 27001‑certified ISMS, carry it through its surveillance audits, and lead its continued development so it’s genuinely embedded in how we work day to day, not just on paper.
- Keep certifications such as Cyber Essentials (and Cyber Essentials Plus) in good standing.
- Lead responses to client security questionnaires, audits and due‑diligence requests, a regular and important part of the role, particularly for our public‑sector and regulated financial‑services clients.
- Develop, maintain and enforce security policies, standards and procedures, and drive awareness of them across the business, including annual staff security training.
- Ensure compliance with data protection obligations (UK GDPR / DPA), working alongside our DPO‑trained and compliance colleagues you are not the sole owner of data protection here, but need to be conversant enough to run day‑to‑day queries and elevate appropriately.
- Run vendor and third‑party risk assessments, and keep our supplier risk posture under review.
- Own disaster recovery and business continuity planning, including periodic testing.
- Respond to security incidents, run root‑cause analysis, and feed lessons back into our controls.
What you’ll bring
5+ years in IT management, information security, or a closely related role, with genuine breadth across both security/compliance and hands‑on IT infrastructure – this is a hybrid role and we need someone who won’t neglect one side in favour of the other.
Essential:
- Proven, hands‑on experience taking an organisation through ISO 27001 certification or a substantial ISMS rebuild – not just maintaining a system someone else built. You’ll be our sole owner of this, so you need to operate independently from day one. Familiarity with frameworks like NIST or CIS Controls is a plus.
- Experience responding to client security questionnaires and supporting…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: