Haystack
← Back to Jobs
Full time
Technology
SR

IT Security Manager

Sanderson Recruitment PlcWiltshire🇬🇧United KingdomPosted 29 Sept 2026

Quick Overview

Salary
£75k/yr
Seniority
Mid Senior
Employment type
Full Time
Work mode
On Site
Location
Wiltshire, United Kingdom
Stakeholder Management

Job Description

IT Security Manager

Location: Wiltshire (once a week on site)
Salary: £75,000
Contract: Permanent

The Role

We are looking for an experienced IT Security Manager to take strategic ownership of IT security across a large and complex organisation.

This is a senior and influential security role, but it is not a traditional hands-on technical security position. The organisation operates within a predominantly outsourced IT environment, so the focus will be on setting the security direction, owning governance and risk, shaping the security strategy and improvement roadmap, and ensuring key technology partners deliver against agreed security requirements.

You will work across internal stakeholders and external suppliers to provide oversight, challenge and assurance. A major part of the role will be ensuring suppliers are held accountable, security improvements are delivered and identified risks are actively managed.

We are looking for someone proactive who is comfortable taking ownership, challenging where necessary and driving activity through to completion.

Key Responsibilities
  • Own, develop and continually evolve the organisation's IT security strategy, ensuring it supports wider technology and business objectives.

  • Take ownership of IT security governance, risk and assurance.

  • Develop, maintain and improve security policies, standards and governance processes.

  • Define and shape the IT security roadmap, identifying priorities and driving security improvements and change.

  • Provide security leadership and guidance across technology programmes, projects and wider organisational change.

  • Manage and provide oversight of key third-party technology and security suppliers.

  • Hold suppliers accountable for security delivery, agreed actions, service levels and remediation activity.

  • Proactively challenge suppliers and stakeholders where security standards or delivery are not meeting expectations.

  • Maintain oversight of security risks, vulnerabilities, incidents and remediation activities delivered through third-party providers.

  • Ensure appropriate controls, reporting and assurance are in place across the outsourced technology environment.

  • Provide clear security advice and recommendations to senior stakeholders, translating technical risks into understandable business impacts.

  • Work collaboratively with IT, business stakeholders and external partners to ensure security is Embedded within technology decision-making and change.

  • Identify opportunities to strengthen the organisation's overall security posture and ensure agreed improvements are delivered.


Skills & Experience
  • Significant experience within information security, cyber security or IT security management.

  • Experience developing, owning or delivering an organisation-wide security strategy.

  • Strong experience across security governance, risk management, assurance and policy development.

  • Experience operating within an outsourced or supplier-led technology environment.

  • Strong third-party supplier and vendor management experience, with the confidence to challenge delivery and hold partners accountable.

  • Experience developing and delivering security improvement, transformation or change roadmaps.

  • Broad understanding of cyber security controls, vulnerabilities, incidents and remediation, without necessarily being responsible for hands-on technical implementation.

  • Ability to assess security risk and translate technical issues into clear business risks and priorities.

  • Strong stakeholder management skills, including the ability to influence and provide constructive challenge at a senior level.

  • Experience working across complex organisations with multiple internal and external stakeholders.

  • A proactive approach, with the ability to identify what needs to happen, take ownership and ensure activity is driven through to completion.


The Person

This role would suit an experienced IT Security Manager, Information Security Manager, Cyber Security Manager, Security Governance Manager or Information Security Lead, as well as someone currently operating at Head of Information Security level within a smaller organisation.

You do not need to be the person configuring security tooling or personally delivering every technical security control. Instead, you will need enough technical understanding to ask the right questions, challenge suppliers and provide credible security leadership.

You will be comfortable working in an environment where much of the technical delivery sits with third parties, while retaining ownership for ensuring the appropriate security strategy, governance, controls and improvement plans are in place.

Above all, we are looking for someone who will take ownership, provide direction and drive change through to delivery.

Reasonable Adjustments:

Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.

If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.

Similar jobs