Senior Manager, Information Security & Data Risk
Listed on 2026-08-08
-
IT/Tech
Information Security & Data Protection, Cybersecurity, Security Management & Operations
Role Purpose
The Senior Manager, Information Security & Data Risk leads advisory engagements that protect client data throughout its lifecycle. The role helps clients understand information-security and data-risk exposure, translate national and organisational requirements into practical controls, and integrate classification, privacy, identity, resilience and assurance into data-management and technology programmes. This position combines security leadership with consulting discipline. It directs assessments, facilitates risk decisions, quality-assures security deliverables and coordinates closely with governance, architecture, operations, legal, compliance and audit stakeholders.
The Senior Manager prepares risk and control recommendations, but formal risk acceptance and security approval remain with authorised client roles. The role must communicate technical risk clearly, support proportionate remediation and ensure that control requirements are documented, testable and suitable for operational handover.
- Lead information-security, data-risk, privacy, classification and resilience work streams for client engagements.
- Assess security governance, policies, control design, threat exposure, access practices, monitoring and operational evidence.
- Translate legal, regulatory, national and client requirements into clear security and privacy requirements for data initiatives.
- Design or review classification, handling, access-control, encryption, logging, retention and secure-disposal controls.
- Advise architecture and engineering teams on security-by-design requirements for platforms, APIs, pipelines and analytics solutions.
- Develop risk registers, control matrices, remediation plans, exception records and evidence requirements.
- Facilitate risk workshops and present options, residual risks and recommendations to authorised client decision-makers.
- Review identity and access management, privileged access, segregation of duties and joiner-mover-leaver controls.
- Assess incident-response, backup, disaster-recovery and business-continuity arrangements affecting client data.
- Coordinate with privacy, compliance, internal audit, system owners and technical teams on assurance and remediation.
- Quality-assure security assessments, designs, test evidence and executive reports produced by delivery teams.
- Support client capability through control walkthroughs, awareness sessions, documentation and handover.
- Bachelor's degree in cybersecurity, information security, computer science or a related field.
- master's degree preferred.
- An equivalent combination of relevant education and directly applicable consulting or implementation experience may be considered.
- Typically 10+ years in information security or technology risk, including 4+ years in leadership.
- Demonstrated experience leading information-security, cyber-risk, privacy or technology-risk engagements.
- Experience advising senior stakeholders in government, regulated sectors or complex enterprises.
- Experience designing and assessing security controls for data platforms, integrations and operational environments.
- A record of communicating residual risk and remediation priorities to both technical and executive audiences.
- Security governance, risk management and control frameworks.
- Data classification, handling, privacy and lifecycle protection.
- Identity and access management, privileged access and segregation of duties.
- Security architecture for platforms, APIs, integration and analytics.
- Logging, monitoring, vulnerability management and incident response.
- Backup, disaster recovery, resilience and continuity controls.
- Compliance evidence, exception management and assurance testing.
- Public-sector and regulated-environment security considerations.
- Security governance.
- Risk assessment.
- Data classification.
- Identity and access management.
- Resilience.
- Regulatory compliance.
- Risk judgement.
- Confidentiality.
- Assurance leadership.
- Crisis communication.
- Facilitating risk and control discussions with senior stakeholders.
- Writing clear risk statements, control requirements and remediation plans.
- Presenting technical security matters in business-impact language.
- Managing sensitive information with discretion and professional judgement.
- Coordinating security, privacy, legal, audit and technology specialists.
- Maintaining independence and evidence-based challenge.
- Supporting risk decisions without assuming client risk-acceptance authority.
- CISSP
- CISM
- IAPP CIPP or CIPM
Security governance
Risk assessment
Data classification
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).