Senior Information Security Manager

Company: Currys plc
Apply for the Senior Information Security Manager
Location: Greater London
Job Description:

Senior Information Security Manager – iD Mobile

Location: Waterloo – Hybrid Working, employment: Full Time, Permanent, Grade 5.

iD Mobile is one of the UK’s leading mobile virtual network operators, part of Currys PLC.

We are looking to recruit a senior Information Security manager to act as the key interface between iD Mobile, Commercial, IT operations, and Currys information security & risk teams. The role will ensure the security and resilience of iD Mobile’s systems, applications and data, and lead iD Mobile’s response to the UK Telecommunications (Security) Act (TSA).

TSA Compliance & Governance

  • Lead the development and continuous improvement of the TSA compliance and control framework to improve iD Mobile’s risk posture
  • Embed TSA requirements & design checkpoints into Architecture Board, Portfolio governance, project teams and change processes
  • Provide structured TSA reporting, compliance insights, and risk updates to senior leadership and the Board
  • Deliver TSA‑aligned supplier audits and contract uplifts to reduce supply‑chain risk exposure
  • Establish a TSA Steering Forum with defined RACI, KPIs, and governance cadence

iD Mobile Security Leadership

  • Maintain an in-depth understanding of all iD systems, processes and people through hands‑on operations
  • Act as the Information Security & TSA SME within governance forums
  • Produce monthly iD Mobile Cyber dashboards, reporting on iD project delivery & assurance, incidents and alerts

Collaboration with iD Operations Teams

  • Regularly review IT asset inventories for accuracy and completeness in line with TSA compliance; annotate inventories with installed security tooling and coverage
  • Compile a register of iD Mobile third‑party suppliers, their criticality level and associated risks and any regulatory frameworks (such as TSA) required of them
  • Maintain an audit‑ready evidence repository
  • Provide security advisory input to Change Approval Board
  • Collaborate with technical leads, business analysts and project managers on a wide range of technology projects, including software development, package implementations and infrastructure upgrades/changes
  • Act as a Data Governance champion within iD Mobile ensuring data is classified and processed in an authorised manner

Collaboration with Currys Information Security Teams

  • Provide second‑line challenge for iD Mobile security incidents, crisis management and resilience planning
  • Lead post‑incident lessons learned reviews and enact improvements in incident playbooks and operational processes to reduce risk
  • Liaise with Security Operations to identify trending threat patterns, security tool uptime and SLAs
  • Design and schedule an annual programme of penetration testing / red‑team assessment aligned with TBEST for relevant iD Mobile environments
  • Review penetration test, vulnerability scans and exposure management tool output and determine appropriate risk scores and remedial activities
  • Assist Capex delivery within iD Mobile through provision of non‑functional security requirements, RFP scoring, architectural review and presentation to the Data & Security Approval Board
  • Regularly review the iD Mobile risk register, drive risk closure and management, monitor for ongoing non‑compliance, escalating where necessary
  • Lead the response to regulatory and business‑to‑business audits and security reviews of iD Mobile operations

Experience

  • Extensive experience in telecoms, cyber security, operational risk, or regulatory compliance
  • Deep knowledge of the UK Telecommunications (Security) Act and Ofcom Security Measures
  • Strong track record influencing senior governance forums and decision‑making bodies
  • Hands‑on experience with supplier assurance, third‑party risk management, and security audits
  • Ability to drive improvements that strengthen organisational risk posture
  • Certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Auditor
  • Knowledge of MNO / MVNO network environments and telecom operational processes
  • Experience in second‑line assurance or internal audit functions

Why Join Us

We’ll support you every step of the way, helping you shape your own future with new opportunities, ongoing training and skills development.

As the biggest recycler and repairer of tech in the UK, we’re in a position to make a real impact on people and the planet.

Every voice has a space at our table, and we’re committed to inclusion and diversity. If you need assistance with your application, please email careers@currys.co.uk.

#J-18808-Ljbffr…

Posted: April 17th, 2026