Information Security and Compliance Risk Manager

Posted 4 Days Ago
Be an Early Applicant
3 Locations
In-Office
64K-64K Annually
Entry level
Healthtech
The Role
Manage and continuously improve the organisation’s ISO 27001 ISMS, coordinate external audits, oversee security compliance and assurance reviews, monitor risk remediation and control effectiveness, and produce governance reporting. The role supports regulatory readiness involving FCA, PRA and ICO requirements, advises stakeholders on information security risks, and promotes effective security governance across technology programmes and strategic initiatives.
Summary Generated by Built In

Job Description:

Information Security Risk & Compliance Manager
Salary: from £64,000 (Negotiable depending on experience)
Location: London (EC2R 7HJ), Leeds (LS5 3BF), Salford (M50 3SP)
Permanent
Shift pattern: Full time, 37.5 hours per week
Role specific benefits: 10% Bonus

We make health happen

At Bupa, our purpose is simple: helping people live longer, healthier, happier lives and making a better world. As an organisation focused on health and care, information security plays a vital role in protecting our customers, colleagues and business operations.

We're looking for an Information Security Risk & Compliance Manager to join our Technology Governance, Risk & Control team. This is an exciting opportunity to influence how information security risk is managed across the organisation, helping to strengthen security maturity, maintain compliance with recognised industry standards, and support regulatory requirements.

Working closely with senior stakeholders across the business, you'll be at the centre of driving effective governance, risk management and compliance activities. You'll help ensure our Information Security Management System (ISMS) remains aligned to best practice, support regulatory readiness, and contribute to a culture where security risk management is embedded into everyday decision-making.

How you’ll help us make health happen:

As an Information Security Risk & Compliance Manager, you will:

  • Lead the management and continuous improvement of Bupa's ISO27001 Information Security Management System (ISMS).

  • Act as the primary liaison for external ISO27001 audits and certification activities.

  • Coordinate and oversee information security compliance, assurance and control review activities.

  • Monitor and report on remediation plans, control effectiveness and compliance obligations.

  • Support risk management activities across technology and information security programmes and strategic initiatives.

  • Produce high-quality reporting and management information for governance forums, executive committees and risk committees.

  • Build strong relationships with stakeholders across the business to drive effective security governance.

  • Challenge and support the identification, prioritisation and escalation of information security risks.

  • Contribute to integrated assurance activities and track risk remediation commitments.

  • Support responses to regulatory requirements and external standards, including engagement with bodies such as the FCA and PRA.

  • Promote a customer-focused approach, ensuring good customer and regulatory outcomes remain central to decision-making.

Key Skills & Experience

To be successful as an Information Security Risk & Compliance Manager, you'll bring:

  • Experience managing an Information Security Management System (ISMS), ideally including ISO27001 certification and audit activities.

  • Strong knowledge of information security governance, risk and compliance practices.

  • Experience delivering information security audits, assurance programmes or IT control reviews.

  • A solid understanding of recognised security frameworks and standards, including ISO27001, ISO27002, NIST, CIS Controls and PCI DSS.

  • Knowledge of UK regulatory environments, including organisations such as the FCA, PRA and ICO.

  • The ability to build credibility and influence stakeholders at all levels.

  • Strong analytical, reporting and communication skills, with the ability to explain complex security concepts clearly to both technical and non-technical audiences.

  • Experience developing management information, dashboards and committee reporting.

  • High levels of integrity, professionalism and sound judgement when handling sensitive information.

  • Experience within a regulated industry, particularly financial services, would be beneficial but is not essential.

  • An understanding of cloud security risks and controls.

  • The ability to manage competing priorities and deliver against deadlines in a fast-paced environment.

Benefits

Our benefits are designed to make health happen for our people. Viva is our global wellbeing programme and includes all aspects of our health – from mental and physical, to financial, social and environmental wellbeing. We support flexible working and have a range of family friendly benefits.

Joining Bupa in this role you will receive the following benefits and more:

  • Annual performance bonus

  • Private medical insurance

  • Generous pension contribution

  • 25 days holiday, increasing with service

  • Access to our Viva wellbeing programme

  • Flexible and hybrid working opportunities

  • Access to discounts and wellbeing support services

  • Enhanced family friendly benefits

Why Bupa

We're a health insurer and provider. With no shareholders, our customers are our focus. Our people are all driven by the same purpose – helping people live longer, healthier, happier lives and making a better world. We make health happen by being brave, caring and responsible in everything we do.

We encourage all of our people to "Be you at Bupa". We champion diversity and understand the importance of our people representing the communities and customers we serve. That's why we especially encourage applications from people with diverse backgrounds and experiences.

Bupa is a Level 2 Disability Confident Employer. This means we aim to offer an interview/assessment to every disabled applicant who meets the minimum criteria for the role. We'll make sure you are treated fairly and offer reasonable adjustments as part of our recruitment process to anyone who needs them.

If you require information regarding this role in an alternative format, please email: [email protected]

Time Type:

Full time

Job Area:

Legal, Risk & Audit

Locations:

Angel Court, London, Bupa Place, Kirkstall Forge

Skills Required

  • Experience managing an Information Security Management System (ISMS), ideally including ISO 27001 certification and audit activities.
  • Strong knowledge of information security governance, risk and compliance practices.
  • Experience delivering information security audits, assurance programmes or IT control reviews.
  • Understanding of security frameworks and standards including ISO 27001, ISO 27002, NIST, CIS Controls and PCI DSS.
  • Knowledge of UK regulatory environments, including the FCA, PRA and ICO.
  • Ability to build credibility and influence stakeholders at all levels.
  • Strong analytical, reporting and communication skills, including explaining complex security concepts to technical and non-technical audiences.
  • Experience developing management information, dashboards and committee reporting.
  • High integrity, professionalism and sound judgement when handling sensitive information.
  • Experience within a regulated industry, particularly financial services.
  • Understanding of cloud security risks and controls.
  • Ability to manage competing priorities and deliver against deadlines in a fast-paced environment.

Bupa Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Bupa and has not been reviewed or approved by Bupa.

  • Healthcare Strength Health cover via the UK Health Trust, day‑one medical support for frontline roles, and dedicated women’s health initiatives indicate a robust, health‑centric package. Access to digital GP, nurse lines, and options such as dental and health cash plans further reinforce medical and preventive care breadth.
  • Wellbeing & Lifestyle Benefits Wellbeing programs span mental, physical, emotional, and financial support, with offerings like EAP access, gym discounts, and health assessments. Flexible work and wellbeing programs highlighted in some regions add to lifestyle value.
  • Parental & Family Support Policies include enhanced parental leave in certain UK business units and a family mental‑health support line. Options to extend medical coverage to dependants and family‑oriented allowances strengthen support beyond the individual.

Bupa Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: London
23,800 Employees
Year Founded: 1947

What We Do

Bupa's purpose is helping people live longer, healthier, happier lives and making a better world. We are an international healthcare company serving over 38 million customers worldwide. With no shareholders, we reinvest profits into providing more and better healthcare for the benefit of current and future customers. We directly employ around 85,000 people, principally in the UK, Australia, Spain, Chile, Poland, New Zealand, Hong Kong SAR, Türkiye, Brazil, Mexico, the US, Middle East and Ireland. We also have associate businesses in Saudi Arabia and India. For more information, visit www.bupa.com

Similar Jobs

Boeing Logo Boeing

Data Cell Operative

Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
In-Office
Wattisham, Babergh, Suffolk, England, GBR
170000 Employees

Boeing Logo Boeing

Project Management Specialist - Fixed Wing Strategic Growth

Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
In-Office
Bristol, England, GBR
170000 Employees
Hybrid
London, Greater London, England, GBR
289097 Employees
Hybrid
Bournemouth, Dorset, England, GBR
289097 Employees

Similar Companies Hiring

Sailor Health Thumbnail
Healthtech • Social Impact • Telehealth
New York City, NY
20 Employees
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
OneImaging Thumbnail
Healthtech
Miami, FL
62 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account