← Back to Directory

Information Security Manager - Risk Management

Babcock International · Portsmouth, UK
Clearance Level
SC
Salary Range
Competitive
Employment Type
FULL TIME
Work Style
hybrid

// Role Summary

Lead and enhance information security risk management practices across a global organization supporting critical defence, aerospace, and engineering programs. This role is key to protecting sensitive information and ensuring cyber resilience.

// Key Responsibilities

  • Develop and implement robust cyber security risk management frameworks.
  • Collaborate with senior stakeholders to identify, assess, and manage risks.
  • Influence strategic decision-making and support regulatory compliance.
  • Present risk insights and assurance reporting to leadership.
  • Requires BPSS and SC security clearance.
  • Flexible and hybrid working arrangements available across multiple UK locations.

// Role Specification

About the Role

As an Information Security Manager focusing on Risk Management at Babcock, you will be instrumental in bolstering the cyber resilience of a global enterprise engaged in defence, aerospace, and national engineering initiatives. This position offers a significant opportunity to spearhead the evolution and enhancement of information and cyber security risk management strategies, thereby safeguarding vital services, infrastructure, and confidential data.

You will engage with senior leadership, project teams, and technical experts across the business to ensure that cyber and information security risks are meticulously identified, evaluated, and managed. Your insights will be crucial in shaping strategic decisions, ensuring adherence to regulatory standards, and advancing Babcock's overall cyber security objectives.

Key Responsibilities:

  • Lead the comprehensive identification, assessment, and management of cyber and information security risks throughout the organisation.
  • Develop and continuously refine the cyber security risk management framework, including policies and governance processes.
  • Collaborate with business leaders, project teams, and technical specialists to ensure effective risk mitigation and informed decision-making.
  • Deliver risk analyses, recommendations, and assurance reports to senior management.
  • Support security assurance activities and confirm alignment with regulatory, contractual, and business necessities.

What We're Looking For:

Essential Experience:

  • Substantial experience in Information Security, Cyber Security, Risk Management, or Governance roles.
  • Proven experience in operating enterprise-level risk management processes.
  • A strong grasp of cyber risk assessment methodologies, information security governance, security controls, and assurance practices.
  • Experience in developing risk treatment and remediation plans within complex organisational structures.
  • The ability to articulate technical security matters in clear business risk terms and present findings effectively to senior stakeholders.

Qualifications:

  • Essential: Relevant professional experience demonstrating expertise in information security, cyber security, or risk management.
  • Advantageous: Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), or equivalent qualifications.

Security Clearance:

The successful candidate must be eligible to obtain and maintain Standard (BPSS) and Security Check (SC) security clearance.

Working Arrangements:

This is a full-time, permanent role working 37.5 hours per week. The position is based in the UK, with flexible and hybrid working arrangements available at our main locations including Bristol, Devonport, London, Leicester, Portsmouth, Rosyth, or Warrington.