Rodeo
Get started

Hitachi Cyber

ISO 27001 Business Transformation Programme Manager

England
Posted 1 day ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Join Hitachi Rail and play a key role in delivering a strategic UK-wide information security transformation.

We are seeking an ISO 27001 Business Transformation Programme Manager to lead the successful achievement and long-term sustainability of ISO/IEC 27001 certification across our UK business operations. This senior leadership role combines programme delivery, information security governance, risk management, business transformation, and executive stakeholder engagement to embed security best practices into our operations, technology services, and organizational culture.

What you will do:

Programme Leadership & Delivery

  • Lead the end-to-end ISO 27001 transformation programme from assessment through certification.
  • Define and execute the programme strategy, roadmap, governance, and delivery plans.
  • Manage cross-functional workstreams across IT, Cyber Security, Risk, Legal, HR, and Operations.
  • Ensure delivery within scope, timeline, budget, and quality expectations.

ISO 27001 Certification Management

  • Lead ISO/IEC 27001 certification readiness and gap assessment activities.
  • Oversee remediation plans, security controls, and policy development.
  • Manage relationships with auditors, certification bodies, and external partners.
  • Coordinate certification audits and drive resolution of audit findings.

Business Transformation & Change Management

  • Drive the adoption of information security practices across the organization.
  • Lead change management, communications, and awareness initiatives.
  • Foster a culture of security, accountability, and continuous improvement.
  • Support implementation of new processes, controls, and governance frameworks.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Information Security Management System (ISMS)

  • Lead the implementation and continual improvement of the ISMS.
  • Ensure alignment of business processes and controls with ISO 27001 requirements.
  • Oversee risk assessment and risk treatment activities.
  • Monitor compliance, performance, and operational effectiveness.

Stakeholder Management

  • Partner with executive leaders and key stakeholders to drive programme success.
  • Present programme status, risks, and recommendations to senior leadership.
  • Build alignment and engagement across business functions.
  • Coordinate with auditors, regulators, and certification partners.

Risk, Compliance & Governance

  • Manage programme risks, issues, and governance activities.
  • Ensure alignment with broader risk, compliance, and regulatory requirements.
  • Maintain audit readiness and compliance evidence.
  • Drive continuous improvement to sustain certification.

Vendor & Partner Management

  • Manage relationships with external auditors, advisors, and delivery partners.
  • Oversee third-party contributions and performance.
  • Ensure contractual deliverables and programme objectives are achieved.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

If you recognize yourself in the following, we would love to meet you!

  • 10+ years of experience leading large-scale business transformation, cyber security, risk, compliance, or governance programmes.
  • Proven track record delivering enterprise-wide ISO 27001 certification initiatives within complex, global organizations.
  • Strong expertise in information security governance, risk management, programme delivery, and stakeholder engagement.
  • Demonstrated ability to lead cross-functional teams and influence senior executives in a matrix environment.
  • Bachelor's degree in Information Technology, Cyber Security, Business, Risk Management, or a related field.
  • PMP, MSP, PRINCE2, or equivalent programme management certification.
  • Experience in highly regulated industries.
  • Knowledge of frameworks such as NIST, CIS Controls, SOC 2, ISO 22301, and GDPR (an asset).
  • ISO 27001 Lead Implementer/Lead Auditor, CISSP, CISM, CRISC, or CGEIT certification (an asset).
  • Experience with digital transformation, change management, and GRC platforms (an asset).

Apply today! We thank all applicants for their interest. Only those selected for an interview will be contacted.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

ISO 27001 Certification
Programme Management
Information Security Governance
Risk Management
Business Transformation
Stakeholder Engagement
Change Management
ISMS Implementation
Audit Management
Compliance
Cyber Security
Vendor Management

Location

England, United Kingdom

Sign up to applySee more jobs like this