Information Security Manager
We’re looking for someone to join our small, busy team to be the person we turn to when it comes to anything about information security. Salary: £50,000 per annum full time Remote/hybrid working
We’re looking for someone to join our small, busy team to be the person we turn to when it comes to anything about information security.
You’ll be able to help us further develop our security stance, ensuring we continue to meet our existing compliance obligations while improving our defences, supporting our staff and delivering for customers. Security is a feature of our products and built into our company, we need a great person to pick up those responsibilities and help us build upon the importance we place on it.
What is the job?
We have a solid foundation in security policies and processes, but there's more work to be done. As our platform grows, so do the complexities of securing it. We need someone who can stay well-informed about security threats, understand and assess integrations, and ensure the safe flow of customer data. Your role will be crucial in prioritising these threats, determining their severity and likelihood, and knowing when to escalate them to our CISO.
Documentation is key—knowing what we need, who needs to know it, and where it applies. You’ll be responsible for improving existing documentation, creating new policies where necessary, and ensuring everything is clear and accessible. You'll also assist service owners in applying and verifying appropriate security controls, and you'll play an active role in our security incident response team, helping us learn and improve.
Security isn’t just about keeping the doors locked—it’s about making our products easier to sell and ensuring we comply with customer requirements. We’re committed to maintaining a solid security stance and to uphold our ethical and commercial responsibilities. Our operations and engineering teams have a good sense of right and wrong, but they need a trusted advisor—someone who can ensure we’re sticking to our rules and provide clarity when it’s needed most.
Responsibilities:
Daily Monitoring and Response: Monitor security intelligence sources, including vendor notifications, security announcements, and internal system alerts. Respond to incidents, triage effectively, and provide clear communication to internal and external stakeholders, including responding to customer questions.
Compliance and Audits: Manage our compliance obligations, including maintaining ISO certifications, Cyber Essentials, and handling external audits. Ensure that our policies and processes benefit the business without unnecessary bureaucracy.
Access Control and Documentation: Oversee access control, assist with the secure configuration of systems, and ensure accurate, up-to-date documentation is available for staff and customers. Support service owners in applying appropriate security controls.
Continuous Improvement: Identify and implement improvements in our security processes, from internal drills and staff training to refining incident response procedures and reporting mechanisms. Regularly review and update security documentation to reflect current best practices.
What you need to know:
Cyber Security Background: You should have a background in cyber security. While we’re not expecting you to be a 20-year veteran, this shouldn’t be your first rodeo.
Cloud Infrastructure Security: You should have a solid understanding of what operating and securing a cloud infrastructure environment looks like—or should look like. This includes knowledge of operational aspects, cost considerations, functionality, and identifying and mitigating risks.
Third-Party Cloud Services: You should know what safely integrating and operating third-party cloud services (SaaS) entails. This includes conducting risk assessments, managing access control, and overseeing user management.
Compliance Frameworks: A working knowledge of compliance frameworks, particularly ISO27001 and its associated ISMS, is essential. Experience with other frameworks, such as Cyber Essentials, would also be beneficial. You should understand how these frameworks work and how to manage the trade-offs they present.
International Data Privacy: You should have an awareness of international data privacy regimes and their impact on operating in multiple territories simultaneously. We don’t expect you to be an expert in all of them, but you should know their existence and how to operate around them.
In this role, you will be the primary point of contact for security-related enquiries, ensuring that our security posture remains robust, effective, and aligned with both internal and external requirements.
What is Delib?
Delib’s mission is to:
1: Make democratic processes easier to run for governments, and;
2. Improve access to democracy for citizens.
We think it makes sense for people to be involved in decisions made by democratic leadership, especially on matters affecting their lives. We want these decisions to be open, transparent and collaborative.
We do this by making engagement software for public sector organisations.
Democratic engagement can be difficult to access and can put a burden of work on citizens, discouraging them from participating. Via our platforms, we want to make it easier for people to take part, and for public sector organisations to achieve their goals: providing clear information, getting better response data, leading to better, more informed, and actionable decisions. Our software has been used for some of the most high-profile public consultations and engagement exercises in the past 20 years, by organisations ranging from federal and central government departments, through to smaller regulators and local authorities. We care about the things we do and the people we do it for, and - while we don’t take ourselves too seriously - we are very serious about the work.
Hiring and Salary Information
Salary: £50,000 per annum full time
Remote/hybrid working
If you're interested, please complete the application form linked from this advert, and include your CV and an optional cover letter so that we can get to know a bit about you and why you want this role.
Our hiring process can involve a short phone interview, but will usually be a video interview followed by a paid trial session. Each stage of the application and process is used to establish a good fit for both parties.
Please contact us if you have any reasonable adjustment requirements.
We follow personnel security standards equivalent to UK Baseline Personnel Security Standard and you will therefore need to satisfy basic eligibility criteria/certain conditions of employment (e.g. nationality rules/right to work); and provide appropriate documentation to verify ID, nationality, employment and/or academic history, criminal record (unspent convictions only).
We look forward to hearing from you
- Department
- Studio Services / Admin
- Locations
- Bristol HQ (UK Distributed)
- Remote status
- Hybrid Remote
What you can expect
-
Autonomous working 🎈
We're all grown-ups doing grown-up things. We've created an environment where you can work independently, without micromanagement but with accountability and support.
-
Meet ups and away days 🎉
We regularly meet up throughout the year on working and non-working trips. This helps us stay connected, get stuff done and also just have fun. It's not mandatory, but it is usually memorable.
-
Flexibility 👍
Life happens 🤷🏼♀️ and it doesn't always fit neatly outside of the 9-5. Do the work you do best, in the way that suits you.
Democracy isn't just voting every four or five years
21st century democracy involves citizens more directly, more often in the issues that affect their lives. Together, we can create a more citizen-centric world.
About Delib
Delib is building the next generation of digital tools to improve citizen engagement within democracy, and we need talented people to help us do that.
Information Security Manager
We’re looking for someone to join our small, busy team to be the person we turn to when it comes to anything about information security. Salary: £50,000 per annum full time Remote/hybrid working
Loading application form