Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Information Security & Compliance Manager

£49 - £57.4 per hourEstimated
Full-time

Blue Matter is a rapidly growing strategic consulting firm serving clients in the life sciences industry. We partner with our clients to help them achieve commercial success across the lifecycle of their products, portfolios and organisations. Our project types include new product planning, launch strategy & planning, brand & life cycle planning and corporate & portfolio strategy, across a variety of specialty therapeutic areas. 

We have a unique entrepreneurial culture and invest in building Blue Matter to be one of the best places to work. We have a strong global presence with offices in the US (San Francisco, New York, Boston), Europe (London, Zurich, Netherlands), and India (Mumbai, Gurgaon, Pune).

 

Why this role exists

Our clients are among the most security- and privacy-conscious organizations in the world, and they trust us with highly sensitive commercial and scientific information. At the same time, our internal AI platform, BlueCortex , is becoming central to how we serve them — which raises both the stakes and the opportunity around how we govern data and technology.

As we grow, we need a dedicated owner for information security and compliance. This role sits in our Technology & Operations team and is based in the UK — giving us strong coverage of GDPR and UK GDPR obligations, alignment with European clients and subsidiaries, and time-zone support for our global team.

This is a hands-on, high-ownership role — not a tick-box function. You’ll build and run the firm’s security and compliance program end-to-end, and you’ll be the trusted point of contact when clients ask how we protect their data. It’s ideal for someone who wants to shape a program in a fast-moving, AI-forward consultancy rather than maintain one that already exists.

 

What you’ll do

Security governance and strategy
  • Own and run Blue Matter’s information security program end-to-end, including for BlueCortex.
  • Define, maintain, and operationalize security policies, standards, and procedures, and keep them current as the firm scales.
  • Maintain the risk register, run regular risk assessments, and drive remediation to closure.
  • Report on security and compliance posture to leadership in clear, business-oriented terms.
Compliance and certifications
  • Drive certification and attestation efforts (e.g., ISO 27001 and/or SOC 2): design and maintain the control framework, own the documentation and evidence, and lead internal and external audits.
  • Build a sustainable, “always-audit-ready” approach rather than a once-a-year scramble.
  • Track relevant regulatory and framework developments and translate them into practical action.
Data protection and privacy
  • Lead data protection under GDPR and UK GDPR; act as, or closely support, our Data Protection function.
  • Maintain records of processing (RoPA), conduct Data Protection Impact Assessments (DPIAs), and own data-handling, retention, and minimization policies.
  • Manage data subject requests and any personal-data incidents, including regulator and individual notifications where required.
  • Oversee data transfer mechanisms and data residency considerations across our global footprint and subsidiaries.
Client security assurance
  • Own the response to client security due-diligence: complete security questionnaires and assessments from biopharma and medtech clients accurately and on time.
  • Support commercial and contractual discussions on security, privacy, and data processing terms (e.g., DPAs).
  • Maintain a library of reusable security documentation, certifications, and answers to accelerate client reviews.
Microsoft 365 security operations
  • Secure and govern our Microsoft 365 environment — Entra ID, Microsoft Defender, Microsoft Purview, and Intune.
  • Own identity and access management: conditional access, MFA, privileged access, joiner/mover/leaver processes, and least-privilege enforcement.
  • Implement and tune data loss prevention (DLP), information protection/labelling, and device compliance.
  • Partner with IT on secure configuration, patching, and endpoint hardening.
Third-party and vendor risk
  • Run third-party and vendor risk management across our supply chain, including security review of new tools and AI/SaaS vendors.
  • Maintain an inventory of vendors and their data access, and reassess risk on a regular cadence.
Incident response and investigations
  • Own the incident response plan; lead detection, triage, investigation, containment, and post-incident review.
  • Investigate security events (for example, analysing Entra ID sign-in and audit logs), and produce clear, actionable incident reports.
  • Run tabletop exercises so the firm is prepared before an incident happens.
Security awareness and culture
  • Build and deliver security awareness training and phishing simulations.
  • Make security approachable and practical so the whole firm becomes a partner in protecting client data.


What success looks like

  • First 90 days: You’ve assessed our current posture, identified the highest-priority risks and gaps, and built a clear, prioritized roadmap. You’re already the point person for client security questionnaires.
  • First 6 months: Core policies are in place and adopted, the M365 security stack is meaningfully hardened, vendor risk and incident response processes are operating, and certification/attestation work is underway with a credible plan.
  • First year: The firm has a mature, sustainable security and compliance program; a defensible data-protection posture under GDPR/UK GDPR; and a smoother, faster client security-review process.


What you’ll bring

Required
  • 5+ years of experience in information security and/or GRC, ideally in an environment that handles sensitive client data (regulated industries, professional services, SaaS, or similar).
  • Strong, practical knowledge of GDPR and UK GDPR and day-to-day data protection.
  • Hands-on experience with ISO 27001 and/or SOC 2 implementation and audits.
  • Working familiarity with the Microsoft security stack (Entra ID, Defender, Purview, Intune).
  • Experience responding to client/customer security assessments and questionnaires.
  • One or more relevant certifications — for example CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer/Auditor, CIPP/E, or CIPM — or equivalent demonstrable experience.
  • Based in the UK with the right to work, and comfortable supporting a globally distributed team across time zones.
  • Excellent written and verbal communication: you can translate security and risk into plain business language for leadership, clients, and colleagues.
Strongly preferred
  • Experience standing up or maturing a security/compliance program (not only operating an established one).
  • Familiarity with EU and UK regulatory developments such as NIS2 and DORA.
  • Experience managing third-party/vendor risk for SaaS and AI tooling.
Nice to have
  • Exposure to life sciences or pharma, and awareness of GxP, GDP, or healthcare data considerations (e.g., HIPAA for US-facing work).
  • Experience establishing data-protection or data-risk practices.
  • Experience supporting M&A or subsidiary integration from a security and compliance perspective.


Who thrives here

  • Builders who want to own a program and shape it, not just keep the lights on.
  • Pragmatic risk managers who right-size controls to the business instead of defaulting to maximum friction.
  • Clear communicators who can earn trust with clients, leadership, and engineers alike.
  • People genuinely interested in the security and governance challenges of a modern, AI-forward firm.


How we work

A small, capable Technology & Operations team with real ownership and direct access to leadership. You’ll have the autonomy to build the program the right way — and the visibility that comes with being the firm’s security and compliance lead. This is a remote/hybrid role based in the UK with occasional travel for team collaboration.

Vacancy posted more than 2 months ago
Similar jobs that could be interesting for youBased on the Information Security & Compliance Manager in London vacancy
  • £56k - £74k per annumEstimated
     ...colleagues, and communities succeed.   About the role The Information Security Manager owns and runs Recognise Bank's 1st line technical security...  ...Security Officer, who owns 2nd line governance, risk and compliance, so that the bank has hands-on technical control and... 
    Suggested
    Full-time
    Flexible hours

    recognisebank

    London
    a month ago
  • £42k - £58k per annumEstimated
     ...and confidential legal transactions, so information security is core to the product and to client trust. The Information Security Manager owns information security across Legatics...  ...Engineering, the role spans technical security, compliance and governance, client assurance, and the... 
    Suggested
    Permanent
    Fixed-term contract
    On-site
    Immediate start
    Remote

    Legatics

    London
    12 days ago
  • £67k - £91k per annumEstimated
     ...brokers, local councils, and more to make informed property purchasing decisions. We have...  ...and services. As the Information Security Manager, you will lead Hometrack’s information...  ...Key Responsibilities 1. Governance, Compliance & Certifications Certification Ownership... 
    Suggested
    Full-time
    Shift work

    Hometrack

    London
    11 days ago
  • £60k - £78k per annumEstimated
     ...Information Security Manager This role blends hands-on technical security expertise with risk management, governance, and assurance, ensuring...  ...that are aligned to the MHR UK Lead and drive PCI-DSS Compliance program together with identified business stakeholders... 
    Suggested
    Full-time

    Millennium Hotel and Resorts UK

    London
    18 days ago
  • £49k - £64k per annumEstimated
     ...At Virgin Media O2, we're shaping the future of secure digital innovation, and the Information Security Manager plays a critical role in making that happen. As a key member of our Security team, you'll be at the forefront of protecting and enabling some of the most exciting... 
    Suggested
    Full-time
    Hybrid working
    On-site
    Immediate start
    Flexible hours

    VMED O2 UK Limited

    London
    1 day ago
  • £58k - £76k per annumEstimated
     ...London news: Your New Job Title: Mandarin speaking Information Security Manager (Banking) The Skills You'll Need: Fluent in Mandarin and...  ...of IT security controls, and supports regulatory compliance and operational resilience. What You'll be Doing Each Day... 
    Permanent
    Fixed-term contract
    On-site

    People First Recruitment

    Central London
    more than 2 months ago
  • £500 per day

    Information Security Architect / Manager Our Client is an International company with offices in Central London. They are looking to bring on-board...  ...resilience. Working closely with key stakeholders to ensure compliance with security policies, and promotion of strong... 
    Daily pay
    Full-time

    Nexus Jobs Limited

    London
    22 days ago
  • £500 - £650 per day

    Information Security Manager with Network Engineering Skills Our Client is a bank based in Central London who are looking to recruit a seasoned...  ...events, coordinating incident response, and ensuring compliance with relevant standards and regulations. The person in this... 
    Full-time
    Hybrid working
    On-site
    Work from home

    Nexus Jobs Limited

    London
    16 hours ago
  • £67k - £90k per annumEstimated
     ...banking, wealth planning and investment management. We believe in traditional relationship...  ...Purpose To provide independent cyber security assurance that technology solutions are...  ...Head of Cyber Cyber Governance & Compliance Manager Cyber Operations & Third-Party... 

    Arbuthnot Latham

    London
    11 days ago
  • £51k - £67k per annumEstimated
     ...assurance approaches often rely on lengthy checklists and surface-level compliance testing. We’re doing things differently. At Zopa, we...  ...approach to assurance. We’re looking for a Compliance Assurance Manager to join us on a fixed term contract, to lead the way in... 
    Fixed-term contract

    zopa

    London
    a month ago
  • £75k - £85k per annum

    IT Security Manager Our Client is a large international organisation who are looking to recruit...  ...them to maintain and improve their information security maturity. To work collaboratively...  ..., including legal and regulatory compliance Advise Company Corporate functions on... 
    Full-time
    On-site

    Nexus Jobs Limited

    London
    22 days ago
  • £77k - £102k per annumEstimated
     ...Role Overview We are seeking a highly experienced Compliance leader to act as Director, International Compliance Governance & Strategy....  ...senior forums and decision-making bodies as required. • Own and manage central compliance frameworks, including SMCR and associated governance... 

    BNY

    London
    16 days ago
  •  ...2024 to build Orbital, a physics-informed foundation model for energy operations...  ...whose whole job is to keep us secure day to day. Right now detection,...  ...access; single sign-on; secrets management. •Endpoint fleet hardening, patch compliance, EDR administration and device lifecycle... 
    Remote

    Applied Computing

    London
    11 days ago
  • £60k - £78k per annumEstimated
     ...is looking for an experienced Chief Information Security Officer (CISO) to lead our global cyber...  ...Engineering, Product, Infrastructure, Legal, Compliance and Finance. The CISO will oversee...  ..., security operations, vulnerability management and operational resilience. Devise... 
    Full-time
    Apprenticeship
    On-site
    Remote
    Flexible hours

    Blockchain.com

    London
    26 days ago
  • £59k - £77k per annumEstimated
     ...credible, and highly influential Chief Information Security Officer (CISO) to lead our cyber...  ...scraping, LLMs).  Enterprise Risk & Compliance: Drive risk and governance initiatives...  ...Operations & Cyber Resilience: SecOps Management: Oversee day-to-day security operations... 
    Permanent

    dmg::media

    London
    3 days ago
  • £56k - £71k per annumEstimated
     ...About the role Sitting in our 2 nd Line Function, the Information Security Officer (ISO)  plays a pivotal role in help ing the bank achieve...  ...Information Security,  IT,  Operational Resilience and the management, storage and use of data , will provide independent... 
    Full-time
    Flexible hours

    recognisebank

    London
    more than 2 months ago
  • We are looking for a number of SC cleared Cyber Security Managers to be involved in the planning and implementing of organisation-wide processes...  ...that demand the very highest levels of security, compliance and assurance. An award-winning organisation, having secured... 
    Temporary

    LA International Computer Consultants Ltd

    Westminster, Greater London
    16 hours ago
  • £55k - £70k per annum

     ...Manage the day-to-day operation and continual improvement of the Asia ISMS. Maintain information security policies, risk registers, incident registers and exception registers. Coordinate ISO 27001 internal and external audits and oversee remediation activities. Prepare... 

    Michael Page

    London
    3 days ago
  • £140k per annum

     ...Broker, seek a Cyber Claims Lead. You will be taking the lead on complex Cyber and Tech claims. Your expertise will be invaluable in managing these claims effectively and efficiently. There will also be a smaller amount of D&O, PI and Crime claims. You will be responsible... 
    Hybrid working

    Harrison Holgate

    London
    12 hours ago
  • £47k - £62k per annumEstimated
     ...banks, hedge funds and asset managers. With more than 40 offices worldwide...  ...the Americas. For more information visit Position Reference:...  ..., scalability and security for the business. Technology...  ...Report any breaches of policy to Compliance and/ or your supervisor as required... 
    Full-time
    Immediate start

    Marex

    London
    7 days ago
  • £53.69k per annum

     ...shaping and embedding a strong security culture in cyber, physical...  ...reduce human-related risk in compliance with regulatory and customer...  ...awareness, knowledge, and skills to manage security risks in alignment...  ...resources to keep colleagues informed, engaged and mitigate risk of... 
    Permanent
    Hybrid working
    Work from home
    Flexible hours

    National Physical Laboratory

    Teddington, Greater London
    4 days ago
  • £45k - £62k per annumEstimated
     ...PwC UK is looking for a Senior Manager to join their Cyber, Data and Technology Resilience practice in Glasgow. You will lead solution...  ...compelling proposals. This role demands a strong background in cyber security, particularly within the Defence sector. Successful candidates... 
    Permanent
    Full-time
    Flexible hours
    Stratford, Greater London
    12 days ago
  • £56k - £75k per annumEstimated
    Company: HAYS SPECIALIST RECRUITMENT Job Type: Permanent
    Permanent

    HAYS SPECIALIST RECRUITMENT

    London
    12 days ago
  • £66k - £85k per annumEstimated
     .... WHERE YOU SIT As our Chief Information Security Officer , you’ll be part of the Technology...  ...security maturity, maintaining key compliance certifications and ensuring security...  ...set the standard for governance, risk management and compliance across the organisation... 
    Hybrid working

    Dr. Martens UK

    London
    4 days ago
  • £76k - £99k per annumEstimated
     ...world’s leading provider of secure financial messaging services,...  ...The role is responsible for managing the end-to-end security due diligence...  ...activities, and supporting compliance with applicable regulatory...  ...Bachelor's degree in Information Security, Cybersecurity, Computer... 

    SWIFT

    London
    3 days ago
  •  ...other: --- Salary: Day Rate+expenses/Package: --- Location/Language: --- Requirements Description: --- Tasks Description: --- Essential Skills/Experience Description: --- Desirable Skills/Additional Information Description: --- Team Contact: @next-ventures.com... 
    Daily pay
    Fixed-term contract
    Immediate start

    Next Ventures

    London
    15 hours ago
  • £71k - £95k per annumEstimated
     ...Applications, Workplace Services and Cyber Security & Networking. Values:  Open, Trusted...  ...2 in the UK AWS: Advanced Solution & Managed Service Provider Program Job Description...  ...and service leadership. Additional Information At Telefónica Tech, we believe... 
    Long-term contract
    Full-time

    Telefonica Tech

    London
    12 days ago
  • £58k - £75k per annumEstimated
     ...deliver best-in-class advisory services in accounting, risk, cyber security, technology, and business transformation.    We pride...  ...including Audit Committees and Board of Directors. · Build risk management practices for clients, including policies, procedures, Risk Register... 
    Full-time
    Flexible hours

    cfgi

    London
    a month ago
  • £69k - £91k per annumEstimated
     ...Job Description Role: OT Cyber Security Senior Manager Location: UK Level: Senior Manager...  ...point of application. Note: The above information relates to a specific client...  ...workshops using industry frameworks and compliance mandates Identify and articulate risks... 
    Full-time
    Hybrid working
    On-site

    Accenture

    London
    more than 2 months ago
  • £94k - £120k per annumEstimated
     ...intelligence firm, helping organisations manage risk, spot opportunity, and build resilience...  ...We are looking for an experienced security Team Lead to join us in an embedded role...  ...trends, intellectual property protection, information leaks, competitor analysis, and emerging... 
    Full-time
    Hybrid working
    On-site
    Monday to Friday
    Shift work

    Sibylline Ltd

    London
    6 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Information Security & Compliance Manager. Be the first to apply!