Skip to content

Open nowPosted 5 days ago

Information Security Manager - 12 month FTC

Workable (global search)108,016 open roles

Where
London, England, United Kingdom
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowInformation Security Manager - 12 month FTCWorkable (global search) · London, England, United Kingdom
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 5 days ago

Workable (global search) median: 7 days open

The posting

This is a 12 month FTC - 3 Days per week with 2 in office days

Hometrack’s market-leading property data sets, valuation models, and risk insights are delivered via our suite of B2B SaaS applications for mortgage lenders, brokers, and more. We’ve led the market for over twenty years!

Our services are mission-critical to the UK’s top banks, automating their mortgage offers. They’re used daily by home builders, mortgage brokers, local councils, and more to make informed property purchasing decisions. We have an exciting strategy to serve an even wider section of the market, with innovative products and services.

As the Information Security Manager, you will lead Hometrack’s information security framework, ensuring our data, technology, and operational practices meet the rigorous standards expected by our banking and mortgage lending partners.

You will be accountable for the ownership and maintenance of our ISO 27001 and Cyber Essentials certifications, driving continuous improvement in our overall security posture. This is a visible, high-impact role requiring both strategic ownership and hands-on governance to ensure security acts as a trusted business enabler across the organisation.

Key Responsibilities

1. Governance, Compliance & Certifications

  • Certification Ownership: Take accountability for the maintenance, auditing, and continuous improvement of Hometrack’s ISO 27001 Certified Information Security Management System (ISMS) and Cyber Essentials / Cyber Essentials Plus certifications, working in close collaboration with our Risk and Compliance officer.
  • Audit & Risk Management: Plan and oversee internal security audits, external surveillance audits, and maintain the corporate Risk Register, prioritising and tracking remediation activities.
  • Policy Management: Author, update, and enforce information security policies, standards, and procedures in line with industry best practices and regulatory shifts.

2. Financial Services & Regulatory Alignment

  • Client & Regulatory Assurance: Support the Risk and Compliance officer with financial client security assessments, due diligence questionnaires, and third-party risk audits.
  • Banking & Lending Compliance: Maintain a strong working knowledge of regulatory expectations affecting UK/EU banking and mortgage markets (e.g., FCA guidelines, PRA operational resilience frameworks, DORA, and GDPR) to ensure Hometrack’s solutions remain compliant.
  • Third-Party Risk Management: Evaluate and monitor the security posture of Hometrack’s vendors and technology suppliers.

3. Strategy & Continuous Improvement

  • Security Strategy Roadmap: Act as a key contributor, helping to prioritise, and implement strategic security initiatives to continuously mature Hometrack’s security posture.
  • Security Awareness & Culture: Alongside the compliance and security owners deliver engaging security awareness training, phishing simulations, and guidance across all departments to foster a security-first culture.
  • Incident Response & Resilience: Maintain, test, and continuously improve the Incident Response, Business Continuity, and Disaster Recovery plans.

4. Technical Collaboration & Support

  • Collaborate closely with technical teams to embed "security by design" into software development and cloud architecture.
  • Manage vulnerability management frameworks, penetration testing cycles, and threat modeling exercises, ensuring timely remediation of findings.
  • Cross-Functional Collaboration: Exceptional ability to forge and sustain relationships across organisational boundaries, working alongside diverse teams to influence and prioritise technical backlogs effectively.
  • Financial Oversight: Direct accountability for departmental budgets, ensuring operational cost efficiency and value-driven resource allocation.

Experience & Knowledge

  • Information Security Leadership: Proven experience operating as an Information Security Manager or Senior Security Officer within a technology, FinTech, or PropTech environment.
  • Financial Services Context: Direct experience working within, or closely servicing, the Financial Services sector—specifically banking, mortgage lending, or credit processing.
  • Framework Mastery: Demonstrable experience owning and maintaining an ISO 27001 ISMS and Cyber Essentials / Cyber Essentials Plus from end to end.
  • Regulatory Awareness: Solid understanding of financial regulatory standards, third-party risk requirements, and data protection laws (GDPR/DPA 2018).
  • Technical Credibility: Broad understanding of cloud platforms (AWS/Azure), secure software development lifecycles (DevSecOps), network security, and identity/access management (IAM).
  • Stakeholder Management: Exceptional communication skills with the ability to translate technical security concepts into business risk discussions for senior stakeholders and external enterprise clients.

Qualifications & Certifications (Desirable)

  • Certified Information Security Manager (CISM)
  • Certified Information Systems Security Professional (CISSP)
  • Certified in Risk and Information Systems Control (CRISC)
  • ISO 27001 Lead Implementer or Lead Auditor

Benefits

  • 25 days annual leave + extra days for years of service
  • Day off for volunteering & Digital detox day
  • Festive Closure - business closed for period between Christmas and New Year
  • Cycle to work and electric car schemes
  • Free Calm App membership
  • Enhanced Parental leave
  • Fertility Treatment Financial Support
  • Group Income Protection and private medical insurance
  • Gym on-site in London – or membership in regional offices
  • 7.5% pension contribution by the company
  • Discretionary annual bonus up to 10% of base salary
  • Talent referral bonus up to £5K
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.