Blue Matter is a rapidly growing strategic consulting firm serving clients in the life sciences industry. We partner with our clients to help them achieve commercial success across the lifecycle of their products, portfolios and organisations. Our project types include new product planning, launch strategy & planning, brand & life cycle planning and corporate & portfolio strategy, across a variety of specialty therapeutic areas.
We have a unique entrepreneurial culture and invest in building Blue Matter to be one of the best places to work. We have a strong global presence with offices in the US (San Francisco, New York, Boston), Europe (London, Zurich, Netherlands), and India (Mumbai, Gurgaon, Pune).Why this role exists
Our clients are among the most security- and privacy-conscious organizations in the world, and they trust us with highly sensitive commercial and scientific information. At the same time, our internal AI platform, BlueCortex , is becoming central to how we serve them — which raises both the stakes and the opportunity around how we govern data and technology. As we grow, we need a dedicated owner for information security and compliance. This role sits in our Technology & Operations team and is based in the UK — giving us strong coverage of GDPR and UK GDPR obligations, alignment with European clients and subsidiaries, and time-zone support for our global team. This is a hands-on, high-ownership role — not a tick-box function. You’ll build and run the firm’s security and compliance program end-to-end, and you’ll be the trusted point of contact when clients ask how we protect their data. It’s ideal for someone who wants to shape a program in a fast-moving, AI-forward consultancy rather than maintain one that already exists.What you’ll do
Security governance and strategy- Own and run Blue Matter’s information security program end-to-end, including for BlueCortex.
- Define, maintain, and operationalize security policies, standards, and procedures, and keep them current as the firm scales.
- Maintain the risk register, run regular risk assessments, and drive remediation to closure.
- Report on security and compliance posture to leadership in clear, business-oriented terms.
- Drive certification and attestation efforts (e.g., ISO 27001 and/or SOC 2): design and maintain the control framework, own the documentation and evidence, and lead internal and external audits.
- Build a sustainable, “always-audit-ready” approach rather than a once-a-year scramble.
- Track relevant regulatory and framework developments and translate them into practical action.
- Lead data protection under GDPR and UK GDPR; act as, or closely support, our Data Protection function.
- Maintain records of processing (RoPA), conduct Data Protection Impact Assessments (DPIAs), and own data-handling, retention, and minimization policies.
- Manage data subject requests and any personal-data incidents, including regulator and individual notifications where required.
- Oversee data transfer mechanisms and data residency considerations across our global footprint and subsidiaries.
- Own the response to client security due-diligence: complete security questionnaires and assessments from biopharma and medtech clients accurately and on time.
- Support commercial and contractual discussions on security, privacy, and data processing terms (e.g., DPAs).
- Maintain a library of reusable security documentation, certifications, and answers to accelerate client reviews.
- Secure and govern our Microsoft 365 environment — Entra ID, Microsoft Defender, Microsoft Purview, and Intune.
- Own identity and access management: conditional access, MFA, privileged access, joiner/mover/leaver processes, and least-privilege enforcement.
- Implement and tune data loss prevention (DLP), information protection/labelling, and device compliance.
- Partner with IT on secure configuration, patching, and endpoint hardening.
- Run third-party and vendor risk management across our supply chain, including security review of new tools and AI/SaaS vendors.
- Maintain an inventory of vendors and their data access, and reassess risk on a regular cadence.
- Own the incident response plan; lead detection, triage, investigation, containment, and post-incident review.
- Investigate security events (for example, analysing Entra ID sign-in and audit logs), and produce clear, actionable incident reports.
- Run tabletop exercises so the firm is prepared before an incident happens.
- Build and deliver security awareness training and phishing simulations.
- Make security approachable and practical so the whole firm becomes a partner in protecting client data.
What success looks like
- First 90 days: You’ve assessed our current posture, identified the highest-priority risks and gaps, and built a clear, prioritized roadmap. You’re already the point person for client security questionnaires.
- First 6 months: Core policies are in place and adopted, the M365 security stack is meaningfully hardened, vendor risk and incident response processes are operating, and certification/attestation work is underway with a credible plan.
- First year: The firm has a mature, sustainable security and compliance program; a defensible data-protection posture under GDPR/UK GDPR; and a smoother, faster client security-review process.
What you’ll bring
- 5+ years of experience in information security and/or GRC, ideally in an environment that handles sensitive client data (regulated industries, professional services, SaaS, or similar).
- Strong, practical knowledge of GDPR and UK GDPR and day-to-day data protection.
- Hands-on experience with ISO 27001 and/or SOC 2 implementation and audits.
- Working familiarity with the Microsoft security stack (Entra ID, Defender, Purview, Intune).
- Experience responding to client/customer security assessments and questionnaires.
- One or more relevant certifications — for example CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer/Auditor, CIPP/E, or CIPM — or equivalent demonstrable experience.
- Based in the UK with the right to work, and comfortable supporting a globally distributed team across time zones.
- Excellent written and verbal communication: you can translate security and risk into plain business language for leadership, clients, and colleagues.
- Experience standing up or maturing a security/compliance program (not only operating an established one).
- Familiarity with EU and UK regulatory developments such as NIS2 and DORA.
- Experience managing third-party/vendor risk for SaaS and AI tooling.
- Exposure to life sciences or pharma, and awareness of GxP, GDP, or healthcare data considerations (e.g., HIPAA for US-facing work).
- Experience establishing data-protection or data-risk practices.
- Experience supporting M&A or subsidiary integration from a security and compliance perspective.
Who thrives here
- Builders who want to own a program and shape it, not just keep the lights on.
- Pragmatic risk managers who right-size controls to the business instead of defaulting to maximum friction.
- Clear communicators who can earn trust with clients, leadership, and engineers alike.
- People genuinely interested in the security and governance challenges of a modern, AI-forward firm.
How we work
- £55k - £74k per annumEstimated...extraordinary talent to join us. About the role Security and Compliance are critical business functions within Charlotte... ...teams is essential to our continued success. The Information Security and Compliance Manager will be responsible for developing and overseeing...SuggestedFull-timeHybrid workingOn-site
£60k - £75k per annum
Information Security Manager Role Description This is a full-time role as an Information Security Manager for Bank in Central London. The Information Security Manager will be responsible for day-to-day tasks related to information security management, including implementing...SuggestedPermanentFull-timeHybrid workingOn-siteRemote- £58k - £76k per annumEstimated...London news: Your New Job Title: Mandarin speaking Information Security Manager (Banking) The Skills You'll Need: Fluent in Mandarin and... ...of IT security controls, and supports regulatory compliance and operational resilience. What You'll be Doing Each Day...SuggestedPermanentFixed-term contractOn-site
£80k - £85k per annum
...Information Security Manager (GRC-Focused) We’re partnered exclusively with one of our London based financial services clients in their search... .... You’ll lead policies, frameworks, risk management and compliance, while working closely with engineering and architecture teams...SuggestedPermanent- £46k - £61k per annumEstimated...own systems, and that's where you come in. We're hiring an Information Security Manager to make sure the rigour we put into understanding speech... ...just policy references. Owning our governance, risk and compliance frameworks, and keeping them honest, turning policy into controls...SuggestedInternshipHybrid workingOn-siteRemoteWork from homeFlexible hours3 days/week
- £52k - £70k per annumEstimated...Information Security Manager This role blends hands-on technical security expertise with risk management, governance, and assurance, ensuring... ...that are aligned to the MHR UK Lead and drive PCI-DSS Compliance program together with identified business stakeholders...Full-time
£65k - £80k per annum
Role Description This is a full-time hybrid role for an Information Security Manager with 2nd and 3rd Line IT support experience. The role involves... ..., implementing network security measures, and ensuring compliance with industry standards. The Information Security Manager...Full-timeHybrid workingOn-siteRemote- £56k - £74k per annumEstimated...colleagues, and communities succeed. About the role The Information Security Manager owns and runs Recognise Bank's 1st line technical security... ...Security Officer, who owns 2nd line governance, risk and compliance, so that the bank has hands-on technical control and...Full-timeFlexible hours
£500 - £600 per day
Company: SR2 Job Type: Contract, Full Time Salary: £500 - £600/dayFull-time£50k - £60k per annum
Cyber & Information Security Manager Location: Peterborough and London Salary: £50,000-£60,000 VIQU is looking for an experienced Cyber & Information Security Manager for our client to take responsibility for cyber and information security within a large, geographically...Full-time£50k - £60k per annum
Company: VIQU IT Job Type: Permanent, Full Time Salary: £50000 - £60000/annumPermanentFull-time£500 - £650 per day
Information Security Manager with Network Engineering Skills Our Client is a bank based in Central London who are looking to recruit a seasoned... ...events, coordinating incident response, and ensuring compliance with relevant standards and regulations. The person in this...Full-timeHybrid workingOn-siteWork from home- £51k - £67k per annumEstimated...assurance approaches often rely on lengthy checklists and surface-level compliance testing. We’re doing things differently. At Zopa, we... ...approach to assurance. We’re looking for a Compliance Assurance Manager to join us on a fixed term contract, to lead the way in...Fixed-term contract
- £47k - £62k per annumEstimated...banks, hedge funds and asset managers. With more than 40 offices worldwide... ...the Americas. For more information visit Position Reference:... ..., scalability and security for the business. Technology... ...Report any breaches of policy to Compliance and/ or your supervisor as required...Full-timeImmediate start
- £56k - £71k per annumEstimated...About the role Sitting in our 2 nd Line Function, the Information Security Officer (ISO) plays a pivotal role in help ing the bank achieve... ...Information Security, IT, Operational Resilience and the management, storage and use of data , will provide independent...Full-timeFlexible hours
- £54k - £71k per annumEstimated...global alternative investment management firm focused on pursuing... ...the FTSE 250 Index. Further information can be found At Man Group... ...designed to provide for the security and integrity of your Personal... ...governance, operational, and compliance requirements that come with itith...Long-term contractFull-timeHybrid workingFlexible hours
- £58k - £75k per annumEstimated...deliver best-in-class advisory services in accounting, risk, cyber security, technology, and business transformation. We pride... ...including Audit Committees and Board of Directors. · Build risk management practices for clients, including policies, procedures, Risk Register...Full-timeFlexible hours
- £69k - £91k per annumEstimated...Job Description Role: OT Cyber Security Senior Manager Location: UK Level: Senior Manager... ...point of application. Note: The above information relates to a specific client... ...workshops using industry frameworks and compliance mandates Identify and articulate risks...Full-timeHybrid workingOn-site
£450 per day
...Contract Role: Information Security Officer (Cloud Security) Contract Location: London/Belfast... ...security architecture and cyber risk management across large-scale technology... ...identifying cyber risks and ensuring compliance with enterprise security policies....Daily payHybrid workingImmediate start- ...Cargo and take a leading role in shaping the security landscape across our London Heathrow campus. This isn’t just about compliance, it’s about driving innovation, influencing... ...cargo operational security within an integrated management system, safeguarding our people, assets, and...Long-term contractOn-siteImmediate startRemoteMonday to FridayFlexible hoursShift work
£140k per annum
...Broker, seek a Cyber Claims Lead. You will be taking the lead on complex Cyber and Tech claims. Your expertise will be invaluable in managing these claims effectively and efficiently. There will also be a smaller amount of D&O, PI and Crime claims. You will be responsible...Hybrid working- £29k - £38k per annumEstimated...Job Description Role: Zero Trust Security Lead Career Level: Senior Manager Location: London Travel/Mobility Requirement: Flexibility to travel... ...be found. #LI-EU Locations London Additional Information Equal Employment Opportunity Statement All...Full-time
- ...Protect what matters. Help build the future of secure digital banking. Join us as a Cyber & Incident Response Manager and play an important role in protecting our customers... ...This is an exciting opportunity to join our Information Security team in a role that combines hands-on...Hybrid workingOn-siteRemote
£35k - £40k per annum
...financial services organisation, is seeking an Information Security Officer to support the ongoing development and management of its Information Security and Cyber Security... ...maturity framework. Security Governance & Compliance Coordinate security assessments, including...PermanentFlexible hours- £59k - £77k per annumEstimated...on us for mission-critical learning, compliance and talent development solutions that... ...We're looking for an experienced Chief Information Security Officer (CISO) to lead our global security... ...Strengthen security, privacy, risk management and organisational resilience. Partner...Full-timeHybrid workingFlexible hours
£140k - £175k per annum
Company: INFOSEC Job Type: Permanent, Full Time Salary: £140000 - £175000/annum bonusPermanentFull-time- £60k - £78k per annumEstimated...is looking for an experienced Chief Information Security Officer (CISO) to lead our global cyber... ...Engineering, Product, Infrastructure, Legal, Compliance and Finance. The CISO will oversee... ..., security operations, vulnerability management and operational resilience. Devise...Full-timeApprenticeshipOn-siteRemoteFlexible hours
- £65k - £85k per annumEstimated...company, building the best way to move and manage the world’s money. Min fees. Max ease... ...Operations and Product to second-line Compliance specialists, and Internal Audit – to... ...ACAMS, ICA) are preferred. Additional Information Hybrid working - 3 days on site &...Full-timeHybrid working
£85k - £95k per annum
Head of IT Infrastructure and Security In summary we are looking to recruit an all-... ...Infrastructure coupled with Security, Compliance & Risk Management You must have upwards of 10 years hands... ...& Decision-Making: Capable of making informed decisions and resolving complex IT...Full-timeHybrid workingOn-site- ...You will be the only dedicated security person at Doctify, and you... ...Endpoint security and device management: Roll out and run enterprise... ...for. Governance, risk, and compliance: Mature our governance framework... ...calls with incomplete information in a scale-up where priorities...Hybrid workingImmediate startRemoteShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security & Compliance Manager. Be the first to apply!
- IT security manager London
- information security manager London
- director aml compliance London
- senior customs compliance manager London
- compliance monitoring manager London
- regulatory project manager London
- gas compliance manager London
- senior director regulatory affairs London
- privacy compliance manager London
- regulatory senior manager at kpmg London
