Information Security Lead
Edinburgh
abrdn
abrdn is a global investment company and asset manager committed to helping our customers achieve their financial goals.Job Description
At abrdn, our purpose is to enable our clients to be better investors. Clients worldwide trust us to find future-fit investment opportunities that deliver the outcomes they seek. We empower clients with technology and insight to make informed decisions, build powerful partnerships to enhance expertise, and invest responsibly to help build a better world.
About the Department
The Information Security Assurance function is part of the Security, Resilience, and Protection team. It plays a vital role in defining, assessing, and reporting on abrdn's Information and Cyber Security control posture. This team ensures that security controls are effective, vulnerabilities are addressed, and risks are managed within acceptable levels. It also leads an Education and Awareness programme to strengthen abrdn’s security culture, continuously improving the effectiveness of our security measures.
About the Role
As an Information Security Lead, you will oversee and enhance the operations of the Information Security Assurance team, ensuring the organisation’s Information and Cyber Security risks are understood, controlled, and improved. Leading a team of Information Security Consultants, you will develop a robust Security Assurance Plan, manage the control library, and ensure continual improvement across security processes.
Reporting to the Head of Information Security Assurance, you will work with autonomy within a clear accountability framework and use your influencing skills to achieve successful outcomes. This role requires innovative thinking and the ability to navigate complex environments to deliver impactful solutions.
Key Responsibilities
Lead and develop a high-performing team, fostering growth and ensuring quality deliverables.
Establish a robust Security Assurance Plan to assess controls, manage threats, and mitigate risks.
Maintain a consumable control library aligned with threats and risks for systematic assurance.
Understand and manage internal and external Information and Cyber Security risks and requirements.
Ensure reporting reflects the organisation’s security posture, driving continual improvement.
Build and maintain strong relationships with stakeholders, translating their needs into actionable deliverables.
About the Candidate
The ideal candidate will possess the following:
Essential Skills and Experience:
Demonstrable experience in Information Security, including topics such as testing, assurance, cyber security, and resilience.
Strong knowledge of risk management and control processes, with an ability to make informed risk judgments.
Expertise in applying risk management practices in global organisations, including assurance and reporting on cyber threats and vulnerabilities.
Excellent planning and organisational skills with the ability to meet objectives.
Experience in governance principles, security frameworks, and standards (e.g., ISF SoGP, ISO 27001, NIST).
Proven leadership skills, with experience in managing and coaching teams.
Strong communication and presentation skills for both technical and business audiences.
Desirable Skills and Experience:
Recognised professional certifications such as Security+, CISMP, CISM, or CISSP.
Experience in financial services or asset management environments.
Familiarity with gaining and maintaining accreditation for secure systems or certifications like ISO 27001.
We are proud to be a Disability Confident Committed employer. If you have a disability and would like to apply to one of our UK roles under the Disability Confident Scheme, please notify us by completing the relevant section in our candidate questionnaire. One of our team will reach out to support you through your application process.
Our benefits
There's more to working life than coming home with a good salary. We have an environment where you can learn, get involved and be supported.
When you join us, your reward will be one of the best around. This includes 40 days’ annual leave, a 16% employer pension contribution, a discretionary performance based bonus (where applicable), private healthcare and a range of flexible benefits – including gym discounts, season ticket loans and access to an employee discount portal. You can read more about our benefits here.
Our business
Enabling our clients to be better investors drives everything we do. Our business is structured around three distinct areas – our vectors of growth – focused on our clients’ changing needs. You can find out more about what we do here.
An inclusive way of working
Whatever way you like to work, if you have the talent and commitment to join our team, we’d like to hear from you.
At abrdn we’ve adopted a ‘blended working’ approach. This approach combines the benefits of face-to-face collaboration, coaching and connecting in our offices with the flexibility of working from home. It enables colleagues to find a balance that works for their roles, their teams, our clients and our business.
An inclusive culture, where diverse perspectives drive our actions, is at the core of who we are and what we do. If you need assistance with your application, or a reasonable adjustment to your interview arrangements – for example, because you are neurodivergent, or have a physical, sensory, cognitive, mental, visible or invisible disability – please let us know and we’ll be happy to help.
We’re committed to providing an inclusive workplace where all forms of difference are valued and which is free from any form of unfair or unlawful treatment. We define diversity in its broadest sense – this includes but is not limited to our diversity of educational and professional backgrounds, experience, cognitive and neurodiversity, age, gender, gender identity, sexual orientation, disability, religion or belief and ethnicity and geographical provenance. We support a culture that values meritocracy, fairness and transparency and welcomes enquiries from everyone.
If you need assistance or an adjustment due to a disability please let us know as part of your application and we will assist.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: CISM CISSP Governance ISO 27001 NIST Risk management Vulnerabilities
Perks/benefits: Career development Flex hours Salary bonus Transparency
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.