Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Wealth Dynamix

Information Security Manager

Wealth Dynamix

. Define, operate and evidence the information security governance framework .

Posted 9/15/2026full-timeLondon • United KingdomMid-LevelSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in information security governance, risk management, and compliance, with a strong focus on ISO 27001-aligned ISMS and GDPR compliance. Capable of embedding security into the software development lifecycle and managing third-party risk processes effectively.

Highest-signal resume keywords
ISO 27001 ISMS ManagementInformation Security Risk ManagementSecurity Incident Response GovernanceSaaS Security and ComplianceGDPR Compliance and Privacy Principles

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Information Security GovernanceRisk Assessment and TreatmentSecurity Policy DevelopmentIncident Response ManagementSupplier Security AssuranceControl Framework ImprovementSecurity Awareness TrainingSecurity KPI/KRI DevelopmentCloud Security ManagementSecure Software Development Lifecycle
Soft Skills
Stakeholder CommunicationLeadership and Team CoordinationProblem SolvingTraining and Mentoring
Tools & Technologies
Microsoft DynamicsAzure SecuritySaaS PlatformsCloud Security Controls
Certifications & Qualifications
CISSPCISMCISACRISCISO 27001 Lead ImplementerISO 27001 Lead Auditor
Industry Keywords
FintechFinancial ServicesRegulated TechnologyB2B Enterprise SoftwareDORAFCA Operational Resilience

Tech Stack

Tools & technologies
AzureCloudCyber SecuritySDLC

About the role

Key responsibilities & impact
  • Define, operate and evidence the information security governance framework
  • Own the company’s information security governance, risk and compliance programme, including the ISMS, client security assurance, security policy framework, incident governance, supplier security assurance and security reporting
  • Work with Technology, Product, Operations, Legal and senior leadership to meet internal, regulatory, contractual and client security expectations
  • Provide security input into UK GDPR and EU GDPR compliance activities, DPIAs, data protection by design and incident response
  • Maintain and continuously improve the ISMS, firmwide information security programme, security policies, certifications and control framework
  • Embed security into the software development lifecycle through secure design reviews, threat modelling, secure coding standards, dependency scanning, SAST/DAST, secrets management, penetration testing, vulnerability remediation and release security governance
  • Support DORA-related client and contractual obligations, including ICT risk evidence, incident response and notification, resilience testing, third-party risk controls, subcontractor oversight, exit planning and audit evidence
  • Govern cloud and SaaS security, including identity and access management, logging and monitoring, encryption, key management, backup, tenant and environment segregation, secure configuration and cloud security posture management
  • Own and test the security incident response framework, including severity classification, escalation, communications, evidence preservation, lessons learned and remediation tracking
  • Support Legal and Sales with information security, privacy, audit, incident notification, resilience, subcontracting and data protection contract clauses
  • Coordinate internal, external, client and certification audits, including planning, evidence collection, stakeholder coordination, remediation and management reporting
  • Manage the information security budget
  • Operate the risk-based third-party security assurance framework
  • Own the client security assurance process, including questionnaires, RFP/RFI responses, client audits, evidence packs and security artefacts
  • Plan and maintain the annual security roadmap
  • Assess emerging technology and market trends for security risk
  • Provide quarterly security updates to the Board and monthly updates to the Executive Committee
  • Provide security awareness training to employees
  • Support Board and Executive Committee understanding of cyber risk, regulatory expectations, risk appetite, control gaps and governance responsibilities
  • Develop and report security KPIs/KRIs
  • Partner with Technology and Operations on business continuity, disaster recovery and digital operational resilience controls, including dependency mapping, backup/restore testing, RTO/RPO validation and remediation tracking

Requirements

What you’ll need
  • Demonstrable experience owning or materially operating an ISO 27001-aligned or certified ISMS
  • Experience supporting SOC 2, client security assurance, external audits or certification evidence processes
  • Strong understanding of information security risk management, control assessment, risk treatment and governance reporting
  • Experience coordinating security incident response governance, including escalation, communications and remediation tracking
  • Experience operating or improving supplier security assurance and third-party risk processes
  • Ability to report security risks, control performance and remediation priorities to senior stakeholders, including ExCo or Board-level audiences
  • Experience in a SaaS, fintech, financial services, regulated technology or B2B enterprise software environment
  • Exposure to DORA, FCA operational resilience, outsourcing/third-party risk or financial services client assurance requirements
  • Experience with Microsoft Dynamics, Azure security, SaaS platforms or Microsoft cloud security controls
  • Working knowledge of UK GDPR/EU GDPR and privacy-by-design principles
  • Familiarity with secure SDLC, application security testing, DevSecOps or product security governance
  • Relevant professional certification such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer/Lead Auditor or equivalent experience
  • Degree in cybersecurity, computer science, risk management or a related discipline, or equivalent practical experience

Benefits

Comp & perks
  • Excellent career progression opportunities
  • Investment into the WDX Academy for new and existing employee learning and development
  • Exposure to multiple complex client needs and digital transformation projects
  • Diverse and inclusive culture