Rodeo
Get started

ME+EM Ltd

Information Security Manager

London
Posted about 15 hours ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Job Title: Information Security Manager

Reporting to: Information Technology

Location: Head Office, White City Place, West London

Contract Type: Full time, 37.5 hours per week


About Us:

ME+EM is one of the UK’s fastest-growing luxury fashion brands. In addition to a thriving global digital presence, we operate flagship stores in London and Edinburgh, concessions within Harrods and Selfridges, and have recently expanded with new store openings in the U.S.

At ME+EM we are an entrepreneurial, creative, and passionate group of people. We work hard, are enthusiastic to learn and are not afraid to take risks. Everyone contributes to our success at all levels, and that precisely what makes being a member of the team so rewarding.

Our office and stores are always busy and fast paced, but we work just as hard to make sure it’s fun, with social activities and biannual parties. We pride ourselves on being approachable, supportive, and welcoming and ensure that everyone’s hard work is rewarded. It takes all these things to build a strong, successful business and our door is always open to new talent ready to contribute to our growth and evolution.


About the Role:

As ME+EM continues its rapid global expansion, protecting our brand identity, our intellectual property, and our customers’ data is paramount. We are looking for an operational leader to head our small but focused Information Security team. This is a "Player-Coach" role. You will line manage a talented Engineer and Analyst while remaining technically active, coordinating complex security projects across a range of departments. You are the bridge between high-level risk management and technical execution, ensuring that security enables - rather than hinders - our global growth.


Job Responsibilities

Team Leadership & Orchestration

  • Direct Management: Lead, mentor, and set the roadmap for the Information Security Engineer and Analyst. Focus on career development and technical cross-skilling.
  • Workflow Management: Act as the "Traffic Controller" for the team, using Kanban to prioritise high-value tasks and ensuring the team stays focused on meaningful risk reduction rather than just "noise."
  • Cross-Functional Liaison: Partner with teams across the business to ensure "Security by Design" is integrated into every new project.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Third-Party Risk Management (TPRM)

  • Vendor Due Diligence: Own the end-to-end security assessment process for all new global partners (e.g., SaaS providers, 3PL warehouses, marketing agencies).
  • Continuous Monitoring: Implement a "Tiered Risk" framework to monitor existing partners, ensuring critical vendors meet our encryption, data handling, and availability standards.
  • Supply Chain Resilience: Assess the security posture of third-party APIs and integrations to prevent data leaks or service disruptions.

Operational Excellence & Incident Response

  • Incident Commander: Lead the response to information security incidents. Act as the primary escalation point, coordinating containment while providing clear, non-technical updates to business leadership.
  • Tooling & Automation: Oversee the optimisation of our security stack. Work with the Engineer to automate repetitive tasks and with the Analyst to improve threat detection accuracy.
  • Vulnerability Management: Oversee our global scanning programme. Prioritise remediation based on business impact - ensuring our systems and infrastructure remain resilient.

Security Validation & Pentesting

  • Pentest Ownership: Own the global Penetration Testing schedule, ensuring all critical outward-facing assets (website, head office, stores) are tested regularly.
  • Continuous Testing: Implement and oversee Continuous Security Testing or Attack Surface Management tools to identify vulnerabilities in real-time as our digital footprint scales.
  • Remediation Management: Don’t just "pass the report" to IT; work with the Engineer and Developers to validate fixes and ensure that high-risk findings are closed out within agreed SLAs.

Governance, Risk & Compliance (GRC)

  • Brand Protection: Manage DMARC and anti-phishing tools to defend ME+EM customers from fraudulent "copycat" websites and email scams.
  • Global Data Privacy: Ensure our operations remain compliant with UK/EU GDPR and PCI-DSS 4.0 as we scale into the US and other international markets.
  • Policy Maintenance: Ensure internal security policies are practical, up-to-date, and understood by the wider business.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

The Ideal Candidate:

The Background:

  • Experience in Cyber Security. You’ve likely been an Analyst or Engineer yourself and are ready to lead without losing your technical edge.

The Mindset:

  • You understand that in a fast-growing luxury fashion brand, our ability to move quickly is everything. You can design solutions that maintain security without compromising on the business’s ability to deliver for our customers.

The Tech Stack:

  • Experience with enterprise Cloud Security (Google and Microsoft), EDR (e.g., SentinelOne), and SIEM.

Communication:

  • You can explain a "SQL Injection" to a developer and a "Supply Chain Risk" to a Creative Director with equal clarity.

Employee Benefits:

  • 33 days annual leave for full-time employees (25 days holiday + 8 bank holidays)
  • A day off to celebrate your birthday.
  • Pension Scheme
  • Group Life Insurance
  • Employee Assistance Programme (EAP)
  • Length of Service Award
  • Refer a Friend Scheme
  • Staff uniform for retail employees
  • Generous Staff and Friends and Family Discount
  • Annual Volunteer Day
  • Cycle to Work Scheme
  • Tech Scheme
  • Eye Care Vouchers
  • Real Living Wage Employer
  • Employee-led committees
  • Social events and biannual parties
  • Enhanced maternity and paternity package after 2 years of service.

Equal Opportunities Employer:

ME+EM is an equal opportunities employer committed to fostering and preserving a culture of diversity, equality, and inclusion in our workforce. As an equal opportunities’ employer, we do not discriminate against applicants based on race, colour, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. We believe that diversity enriches our workforce and strengthens our organisation. Therefore, we encourage minorities, LGBTQ+ candidates, and individuals with disabilities to apply for opportunities within our company.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Information Security Management
Team Leadership
Third-Party Risk Management
Incident Response
Vulnerability Management
Penetration Testing
Governance Risk & Compliance
Cloud Security
GDPR Compliance
PCI-DSS 4.0
DMARC
SIEM
EDR
Kanban
Security by Design
Attack Surface Management

Location

London, England, United Kingdom

Sign up to applySee more jobs like this