Application Deadline: 6 February 2026
Department: Office of the CIO
Employment Type: Permanent - Full Time
Location: Newquay, Cornwall, UK
DescriptionOverview of role: The Information Security Assurance Manager is responsible for maintaining and maturing the university's Information Security Management System (ISMS) in alignment with ISO/IEC 27001:2022 and related standards, such as ISO 9001, ISO 27005 and ISO 31000. The role oversees the effective operation and continual improvement of the ISMS, including the expansion of its scope across additional faculties, services, and operational areas where appropriate, with an ultimate goal of implementing an integrated management system for the university.
The postholder will lead a team, providing expert guidance on information security governance, risk management, compliance, and assurance, while working closely with university stakeholders to embed robust security practices.
This role is based within the IT Assurance team at King's Service Centre in Cornwall, however, there will be some need to travel to the London campuses.
Key ResponsibilitiesThe role holder will have in-depth knowledge of information security management systems (ISMS), including their design, implementation, operation, and continual improvement, ideally within a complex higher education environment. They will demonstrate a strong understanding of relevant international standards, particularly ISO/IEC 27001:2022, ISO/IEC 27002:2022 , and ISO/IEC 27005:2022, and how these can be applied pragmatically to support institutional governance, assurance, and risk management while enabling teaching, research, and professional services activity.
Professional information security certifications, such as ISO/IEC 27001 Lead Implementer or Lead Auditor, CISSP, CISM, or an equivalent qualification will be held, and they will have demonstrable experience of expanding the scope of an ISMS or implementing security frameworks across diverse operational, academic, or research environments. Familiarity with data protection requirements, research security considerations, and third party assurance activities is desirable, including the ability to assess and manage supplier and partner risk.
In addition to strong technical and professional expertise, the postholder will be highly organised, thorough, and attentive to detail, with the ability to work independently and exercise sound professional judgement. They must be an effective communicator, capable of engaging confidently with staff at all levels, including influencing and negotiating outcomes with senior management. A well developed understanding of risk management is essential, including a practical appreciation of risk appetite and the ability to apply it proportionately to support informed decision making.
Key Skills & Experience RequiredEssential Criteria:
Desirable Criteria:
We are an inclusive and welcoming employer that encourages a wide range of applicants. We embrace diversity and want everyone to be able to bring their whole selves to work and succeed.
This is in line with King's College London (KCL).