Sanderson
IT Security Manager

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
IT Security Manager
Salary: £74,466 – £80,504
Location: Swindon or London – Hybrid
Contract: Permanent
The Role
We are looking for an experienced IT Security Manager to take ownership of Information Security Governance, Risk Management and Controls across a large and complex organisation.
This is a senior role combining security strategy with hands-on ownership and delivery. You will be responsible for shaping the security roadmap, developing the security elements of the wider technology strategy and ensuring information security is embedded across technology, projects, suppliers and operational processes.
Working within a small security function and a largely outsourced technology environment, you will need to be comfortable setting direction while personally driving security improvements through to completion.
This isn't a traditional hands-on Security Engineering or SOC position. However, you will need strong technical security knowledge, with the ability to understand technical risks, challenge proposed solutions and ensure appropriate controls are implemented.
Key Responsibilities
- Own, develop and maintain information security policies, standards and controls across the organisation.
- Shape the Information Security strategy and develop and drive the Cyber Security roadmap.
- Lead Information Security Governance, Risk and Compliance activities.
- Define, implement, test and continually improve security controls aligned to recognised frameworks including ISO 27001.
- Lead the Information Security risk management programme, ensuring risks are identified, assessed, owned and actively managed through to mitigation or formal acceptance.
- Provide security assurance across technology projects and architecture, reviewing designs, identifying risks and ensuring appropriate controls are implemented.
- Lead third-party security assurance throughout the supplier lifecycle, challenging controls and ensuring remediation actions are completed.
- Monitor security and compliance metrics, control effectiveness and overall security maturity, using these insights to drive improvements.
- Lead security assurance activity including control testing, evidence gathering, compliance reviews and gap analysis.
- Provide guidance and challenge around security frameworks including ISO 27001, PCI DSS, CIS Controls and Cyber Essentials.
- Maintain oversight of security incidents, helping assess impact, coordinate activity and ensure lessons learned are reflected in future controls and processes.
- Own and continually improve the organisation's security awareness programme, including phishing campaigns, training and targeted guidance.
- Ensure information security requirements are appropriately considered within business continuity and disaster recovery planning and testing.
- Work closely with project teams from early discovery through to delivery, embedding security-by-design and ensuring agreed actions are completed before go-live.
- Provide clear security reporting, risk summaries and recommendations to senior leadership and governance forums.
- Work closely with outsourced technology and security suppliers, constructively challenging delivery and holding third parties accountable for agreed actions.
- Provide leadership, coaching and development to an IT Security Officer.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Skills & Experience
We are looking for an experienced Information or Cyber Security professional with strong expertise across governance, risk, compliance and security assurance.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
You will ideally have:
- Strong experience within Information Security, Cyber Security or Technology Risk.
- Deep knowledge of Information Security and compliance frameworks such as ISO 27001, PCI DSS, CIS Controls and Cyber Essentials.
- Previous experience within an Information Security risk management role.
- Strong technical understanding with the ability to assess technical risks, challenge proposed solutions and ensure appropriate security controls are implemented.
- Experience developing and delivering Information or Cyber Security strategies and improvement roadmaps.
- Experience managing security assurance activity, including control testing, evidence gathering, gap analysis and remediation.
- Strong third-party risk management and supplier assurance experience.
- Experience providing security assurance across technology projects, solutions or architecture.
- Experience working within an organisation undergoing significant business or technology change.
- Strong stakeholder management skills with the confidence to influence and constructively challenge at all levels.
- Experience presenting security risks, progress and recommendations to Executive or senior governance forums.
- Understanding of Data Protection and the relationship between Information Security Governance and Data Protection obligations.
- Experience coordinating teams and stakeholders to deliver security, risk or compliance improvements.
- Previous leadership or line management experience.
Qualifications
Relevant Information Security qualifications such as CISSP, CISA, CISM or CRISC would be highly beneficial. Experience or qualifications relating to recognised project management methodologies would also be advantageous.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London