Bupa
Information Security and Compliance Risk Manager

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Job Description: Information Security Risk & Compliance Manager
Salary: from £64,000 (Negotiable depending on experience)
Location: London (EC2R 7HJ), Leeds (LS5 3BF), Salford (M50 3SP)
Permanent
Shift pattern: Full time, 37.5 hours per week
Role specific benefits: 10% Bonus
We make health happen
At Bupa, our purpose is simple: helping people live longer, healthier, happier lives and making a better world. As an organisation focused on health and care, information security plays a vital role in protecting our customers, colleagues and business operations.
We're looking for an Information Security Risk & Compliance Manager to join our Technology Governance, Risk & Control team. This is an exciting opportunity to influence how information security risk is managed across the organisation, helping to strengthen security maturity, maintain compliance with recognised industry standards, and support regulatory requirements.
Working closely with senior stakeholders across the business, you'll be at the centre of driving effective governance, risk management and compliance activities. You'll help ensure our Information Security Management System (ISMS) remains aligned to best practice, support regulatory readiness, and contribute to a culture where security risk management is embedded into everyday decision-making.
How you’ll help us make health happen:
As an Information Security Risk & Compliance Manager, you will:
- Lead the management and continuous improvement of Bupa's ISO27001 Information Security Management System (ISMS).
- Act as the primary liaison for external ISO27001 audits and certification activities.
- Coordinate and oversee information security compliance, assurance and control review activities.
- Monitor and report on remediation plans, control effectiveness and compliance obligations.
- Support risk management activities across technology and information security programmes and strategic initiatives.
- Produce high-quality reporting and management information for governance forums, executive committees and risk committees.
- Build strong relationships with stakeholders across the business to drive effective security governance.
- Challenge and support the identification, prioritisation and escalation of information security risks.
- Contribute to integrated assurance activities and track risk remediation commitments.
- Support responses to regulatory requirements and external standards, including engagement with bodies such as the FCA and PRA.
- Promote a customer-focused approach, ensuring good customer and regulatory outcomes remain central to decision-making.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Key Skills & Experience
To be successful as an Information Security Risk & Compliance Manager, you'll bring:
- Experience managing an Information Security Management System (ISMS), ideally including ISO27001 certification and audit activities.
- Strong knowledge of information security governance, risk and compliance practices.
- Experience delivering information security audits, assurance programmes or IT control reviews.
- A solid understanding of recognised security frameworks and standards, including ISO27001, ISO27002, NIST, CIS Controls and PCI DSS.
- Knowledge of UK regulatory environments, including organisations such as the FCA, PRA and ICO.
- The ability to build credibility and influence stakeholders at all levels.
- Strong analytical, reporting and communication skills, with the ability to explain complex security concepts clearly to both technical and non-technical audiences.
- Experience developing management information, dashboards and committee reporting.
- High levels of integrity, professionalism and sound judgement when handling sensitive information.
- Experience within a regulated industry, particularly financial services, would be beneficial but is not essential.
- An understanding of cloud security risks and controls.
- The ability to manage competing priorities and deliver against deadlines in a fast-paced environment.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Benefits
Our benefits are designed to make health happen for our people. Viva is our global wellbeing programme and includes all aspects of our health – from mental and physical, to financial, social and environmental wellbeing. We support flexible working and have a range of family friendly benefits.
Joining Bupa in this role you will receive the following benefits and more:
- Annual performance bonus
- Private medical insurance
- Generous pension contribution
- 25 days holiday, increasing with service
- Access to our Viva wellbeing programme
- Flexible and hybrid working opportunities
- Access to discounts and wellbeing support services
- Enhanced family friendly benefits
Why Bupa
We're a health insurer and provider. With no shareholders, our customers are our focus. Our people are all driven by the same purpose – helping people live longer, healthier, happier lives and making a better world. We make health happen by being brave, caring and responsible in everything we do.
We encourage all of our people to "Be you at Bupa". We champion diversity and understand the importance of our people representing the communities and customers we serve. That's why we especially encourage applications from people with diverse backgrounds and experiences.
Bupa is a Level 2 Disability Confident Employer. This means we aim to offer an interview/assessment to every disabled applicant who meets the minimum criteria for the role. We'll make sure you are treated fairly and offer reasonable adjustments as part of our recruitment process to anyone who needs them.
If you require information regarding this role in an alternative format, please email: careers@bupa.com
Time Type: Full time
Job Area: Legal, Risk & Audit
Locations: Angel Court, London, Bupa Place, Kirkstall Forge
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location