At Skanska, we’re shaping the way we live, work and connect. As one of the world’s largest construction and development companies, we work together with customers, communities and partners to shape a better society.
You will be working in the HS2 Main Works, the SCS Joint Venture with Costain and Strabag, our HS2 Main Works South team is delivering one of the UK’s most ambitious infrastructure projects – 26 miles of tunnels from London Euston to West Ruislip, along with viaducts, bridges and embankments that will connect communities for generations.
We are currently looking for an Information Security Manager who will:
As the Information Security Manager, you will:
-
Lead the implementation, maintenance, and continual improvement of the Information Security Management System (ISMS) in line with ISO 27001
-
Achieve and maintain ISO 27001 certification, ensuring controls, evidence, and processes remain compliant year round
-
Maintain and communicate an effective information security risk management framework that enables informed decision making at senior levels
-
Drive proactive risk identification, assessment, treatment, and monitoring across the organisation
-
Champion a strong security culture across SCS JV, ensuring policies and expectations are understood and embedded
-
Influence and support process owners to improve their processes where security weaknesses are identified
-
Lead, mentor, and develop junior InfoSec team members, ensuring the team has the competence and capability to run an effective ISMS
-
Track emerging risks, threats, and compliance changes, ensuring the ISMS evolves to remain effective and relevant
We are looking for:
-
Demonstrable experience working with Cyber Essentials
-
Certified Information Security Manager (CISM) or equivalent qualification
-
Demonstrable understanding of cloud technology
-
Demonstrable working understanding of security technology and how it’s deployed to create effective technical controls for example; Firewalls, IDP, IAM, MFA, SSO, DLP, CASB, MDM, EDR etc
-
Demonstrable risk management knowledge and how to influence senior management to make informed decisions on risk treatment
-
Working knowledge of the UK Data Protection Act (DPA) / GDPR
-
Demonstrable good level of written and spoken English
-
A commonly identifiable security qualification i.e. CISA, CRISC, CDPSE, CGEIT, CCOA, CISSP etc
What we offer:
24/7 digital GP service for you and your family
Financial wellbeing and employee assistance
Professional development
Enhanced family benefits (including maternity, paternity, dependants and parental bereavement leave)
Inclusion and Diversity
We thrive through embracing differences as we know that diversity opens a rich potential for new ways of thinking, helping us to build successful and high-performing teams. We call it The Skanska Way.
Flexible working
Where possible, we offer a range of flexible working options, and we would be happy to discuss this at the application stage if this is something you’d like to explore.
Reasonable adjustments
We want you to feel confident and supported throughout every stage of our recruitment process. If you need any adjustments to help you during your application, please contact us at [email protected] or call 0330 105 2000 – Option 5 & 1.
Closing date
We encourage you to apply as early as possible, as the closing date may be subject to change.
If this role would be of interest, please click apply and join our team of 27,000 problem solvers and creative thinkers, where knowledge is our greatest creation. We share, listen and support your success – every step of the way.
If you are an internal candidate currently working on the SCS project, please apply through the SCS JV Careers Portal to avoid duplicate applications.