VACANCY
Information Security Manager
The Information Security Manager is responsible for managing the company’s Information Security programme and coordinating security efforts across the organisation. The role leads the development, implementation, and maintenance of an Information Security Management System (ISMS) aligned with ISO 27001, relevant gambling regulations, and other applicable frameworks.
Working closely with multiple teams across the organisation, the Information Security Manager will prioritise, plan, design, and oversee the implementation of appropriate security controls to strengthen the confidentiality, integrity, and availability of the company’s information assets.
Essential Duties
- Take ownership of and lead the company’s Information Security function to support and achieve business objectives.
- Contribute to the development of short-term and long-term global security strategies in support of the Group’s overall business goals.
- Lead the risk management programme across the entire risk lifecycle, from risk assessments through to risk treatment and mitigation.
- Coordinate the vulnerability management programme from end to end.
- Ensure the Information Security Management System (ISMS) operates effectively and meets its defined objectives.
- Maintain Information Security regulatory compliance with applicable gaming and government regulations, contractual obligations, and relevant security standards and frameworks.
- Drive and continuously improve the company’s Information Security awareness and training programme.
- Liaise with the global Security Operations Centre (SOC) and coordinate security incident response and escalations as required.
- Coordinate internal and external audits, assessments, security reviews, and related remediation activities.
- Collaborate closely with IT teams to design, implement, and ensure the effectiveness of technical security controls.
- Monitor and report agreed Information Security KPIs periodically to global security leadership and management.
- Support security-related activities outside normal working hours when required by the systems and services being supported.
- Carry out assignments provided by Global Information Security leadership, IT leadership, and Management.
Qualifications & Requirements
- Minimum 5 years of experience across Information Security and IT domains.
- Strong ability to collaborate effectively with teams across multiple functions and disciplines.
- Comfortable working within a matrix reporting environment.
- Experience implementing Information Security and compliance frameworks such as ISO 27001/27002, GDPR, NIST, SOC 2, PCI DSS, and gambling regulations across multiple markets.
- Hands-on experience conducting risk assessments and developing appropriate risk treatment plans.
- Project and process management experience, preferably within Agile environments.
- Experience developing and maintaining Information Security documentation, including policies, procedures, standards, and guidelines.
- Professional Information Security certification such as CISSP, CRISC, C|CISO, CISM, or another relevant certification.
- ISO 27001 Lead Auditor or Lead Implementer certification is considered an advantage.
- Bachelor’s degree in IT, Business, or a related field. A Master’s degree is considered an advantage.
- Excellent written and spoken English.
- Ability to communicate technical and security-related information clearly and concisely to non-technical stakeholders.
- Strong commitment to continuous personal and professional development.
Key Skills & Competencies
- Strong organisational and results-oriented mindset.
- Strategic and analytical thinking.
- Excellent interpersonal and stakeholder management skills.
- Ability to take initiative and work effectively under pressure.
- Strong problem-solving and decision-making abilities.
- Ability to manage multiple priorities and responsibilities simultaneously.
- Clear and effective communication with both technical and non-technical stakeholders.
Travel Requirements
Travel may be required from time to time according to business needs. The role may also require work outside normal working hours in response to security incidents or the operational needs of supported systems.