Hybrid: 1 - 2 days at our Support Centre in Coleshill, Birmingham.
Become an Information & Cyber Security ManagerAt The Works, it all starts with our people, customers and the trust they place in us every day. As our Information & Cyber Security Manager, you'll play a vital role in protecting the technology, data and systems that keep our business running safely and securely.
Working closely with the Director of Technology Services, you'll lead our information and cyber security programme, helping to create a resilient, trusted and secure environment for colleagues and customers alike. From shaping and delivering our security strategy to managing risk, governance and compliance, you'll ensure we're prepared for today's challenges and tomorrow's opportunities.
You'll lead a small internal team, partner with our outsourced Security Operations Centre and work closely alongside our Network Operations partners. Together, you'll drive strong security practices across the business, safeguarding our systems, customer information and payment environments while enabling innovation and growth with confidence.
Your MissionDeliver the enterprise-wide information security strategy aligned to business objectives and regulatory requirements.
Establish and govern security frameworks and policies (e.g. ISO 27001, NIST, PCI DSS, Cyber Essentials Plus), ensuring ongoing compliance and audit readiness.
Lead security risk management, maintaining the risk register with clear ownership, mitigation plans, and effective tracking/reporting.
Own the security programme roadmap and investment plan, prioritising initiatives to address risk, compliance, and business change.
Oversee security operations and incident response, working with the outsourced SOC to ensure effective monitoring, escalation, and regulatory-compliant breach management.
Manage threat and vulnerability capabilities, including penetration testing, threat intelligence, and proactive threat hunting across the estate.
Own data security and regulatory compliance, including DLP strategy, PCI environments, DPIAs, and partnership with the DPO on GDPR obligations.
Embed security into architecture and technology, ensuring security-by-design across platforms, cloud environments, and change programmes, supported by an effective tooling strategy (SIEM, EDR/XDR, DLP).
Own third-party security and supplier assurance, managing vendors and ensuring ongoing compliance, risk visibility, and performance against SLAs.
Build and lead a high-performing security function, driving team capability, stakeholder engagement, and a strong organisational security culture through awareness and training.
Demonstrable experience in information security leadership roles
Strong working knowledge of GDPR, PCI DSS, ISO 27001, Cyber Essentials, and NIST Cybersecurity Framework
Experience running vulnerability management programmes and interpreting threat intelligence.
Understanding of the retail-specific threat landscape and drive to keep abreast of threats.
Experience managing SOC providers and security vendors, including SLA governance and escalation management
Hands on or oversight experience with SIEM, SOAR, EDR/XDR, DLP, and vulnerability scanning tooling.
Strong stakeholder communication skills, including the ability to translate technical risk into business impact.
And let's not forget about the most important part your team's well being and aspirations. You'll be their biggest supporter, cheering them on. You'll have amazing everyday conversations with your team, discussing everything from their performance to their wildest career aspirations.
Our PERKS really are 'The Works'At The Works, we are proud to have an inclusive culture where everyone truly feels able to be themselves. Our roles are open to all, including under-represented groups such as ethnic minorities, people with disabilities, carers & members of the LGBTQ+ community (including those who identify as lesbian, gay, bi, trans, non-binary, or use another term).
We are open to discussions around working hours and flexible working. And, where possible, we'll try to support this. If you need reasonable adjustments for an interview you might attend with us, let us know in your application and we'll be happy to help!