×
Register Here to Apply for Jobs or Post Jobs. X

Information Security and Compliance Risk Manager

Job in City Of London, Central London, Greater London, England, UK
Listing for: BUPA
Full Time position
Listed on 2026-09-03
Job specializations:
  • IT/Tech
    Information Security & Data Protection, Cybersecurity
Salary/Wage Range or Industry Benchmark: 64000 GBP Yearly GBP 64000.00 YEAR
Job Description & How to Apply Below
Location: City Of London

Job Description:

Information Security Risk & Compliance Manager
Salary: from £64,000 (Negotiable depending on experience)

Location:

London (EC2R 7HJ
), Leeds (LS5 3BF
), Salford (M50 3SP
)
Permanent
Shift pattern:
Full time, 37.5 hours per week
Role specific benefits: 10% Bonus

We make health happen

At Bupa, our purpose is simple: helping people live longer, healthier, happier lives and making a better world. As an organisation focused on health and care, information security plays a vital role in protecting our customers, colleagues and business operations.

We're looking for an Information Security Risk & Compliance Manager to join our Technology Governance, Risk & Control team. This is an exciting opportunity to influence how information security risk is managed across the organisation, helping to strengthen security maturity, maintain compliance with recognised industry standards, and support regulatory requirements.

Working closely with senior stakeholders across the business, you'll be at the centre of driving effective governance, risk management and compliance activities. You'll help ensure our Information Security Management System (ISMS) remains aligned to best practice, support regulatory readiness, and contribute to a culture where security risk management is embedded into everyday decision-making.

How you'll help us make health happen:
  • Lead the management and continuous improvement of Bupa's ISO
    27001 Information Security Management System (ISMS).

  • Act as the primary liaison for external ISO
    27001 audits and certification activities.

  • Coordinate and oversee information security compliance, assurance and control review activities.

  • Monitor and report on remediation plans, control effectiveness and compliance obligations.

  • Support risk management activities across technology and information security programmes and strategic initiatives.

  • Produce high-quality reporting and management information for governance forums, executive committees and risk committees.

  • Build strong relationships with stakeholders across the business to drive effective security governance.

  • Challenge and support the identification, prioritisation and escalation of information security risks.

  • Contribute to integrated assurance activities and track risk remediation commitments.

  • Support responses to regulatory requirements and external standards, including engagement with bodies such as the FCA and PRA.

  • Promote a customer-focused approach, ensuring good customer and regulatory outcomes remain central to decision-making.

Key Skills & Experience

To be successful as an Information Security Risk & Compliance Manager, you'll bring:

  • Experience managing an Information Security Management System (ISMS), ideally including ISO
    27001 certification and audit activities.

  • Strong knowledge of information security governance, risk and compliance practices.

  • Experience delivering information security audits, assurance programmes or IT control reviews.

  • A solid understanding of recognised security frameworks and standards, including ISO
    27001, ISO
    27002, NIST, CIS Controls and PCI DSS.

  • Knowledge of UK regulatory environments, including organisations such as the FCA, PRA and ICO.

  • The ability to build credibility and influence stakeholders at all levels.

  • Strong analytical, reporting and communication skills, with the ability to explain complex security concepts clearly to both technical and non-technical audiences.

  • Experience developing management information, dashboards and committee reporting.

  • High levels of integrity, professionalism and sound judgement when handling sensitive information.

  • Experience with in a regulated industry, particularly financial services, would be beneficial but is not essential.

  • An understanding of cloud security risks and controls.

  • The ability to manage competing priorities and deliver against deadlines in a fast-paced environment.

Benefits

Our benefits are designed to make health happen for our people. Viva is our global wellbeing programme and includes all aspects of our health - from mental and physical, to financial, social and environmental wellbeing. We support flexible working and have a range of family friendly benefits.

Joining Bupa in this role…

Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary