
Location
London
Hours
Full Time
Salary
Competitive salary, commensurate with experience
About the Role
Security and Compliance are critical business functions within Charlotte Tilbury. As a company handling a large volume of sensitive customer data, it is imperative to adhere to modern security standards and remain compliant with relevant regulations across all operating regions. Protecting intellectual property and ensuring team productivity are essential to our continued success.
The Information Security & Compliance Manager will develop and oversee control systems to prevent or address breaches of data security and privacy. You will evaluate the efficiency of these controls and continuously improve them. Collaboration with IT, Legal, and other stakeholders to monitor and enforce compliance standards and regulations is key. You will also provide guidance and training on information security best practices to employees and partners.
Key responsibilities include:
- Coordinate development and regular review of IT security and data processing policies and standards.
- Manage technical security controls such as EDR, SIEM, DLP, SSE/SWG, CSPM, vulnerability management, identity security, and endpoint compliance.
- Partner with Technology Operations to ensure secure design, implementation, and support of workplace, identity, and endpoint technologies.
- Define and maintain build standards for Windows, MacOS, Android, and iOS devices.
- Establish security and compliance standards for cloud environments including AWS and GCP.
- Oversee penetration testing, bug bounty programs, and red team exercises.
- Investigate security events and contain incidents promptly.
- Manage technology risk activities and drive improvements in compliance.
- Develop security and compliance reporting for management and risk committees.
- Maintain an information security risk register and coordinate internal and external audits.
- Own vendor and third-party risk assessments and supply chain vulnerabilities.
- Lead information security awareness and training initiatives including phishing exercises.
- Stay updated on emerging information security risks and trends aligned with organizational objectives.
Reporting to the Technology Operations Director, you will lead the Information Security team consisting of two direct reports.
Experience
- Proven experience managing Cyber Security and Compliance in an enterprise environment.
- Practical hands-on experience delivering security improvements.
- Strong understanding of relevant security frameworks and regulations such as GDPR, CCPA, ISO27001, PCI-DSS.
About you
- Customer-focused with excellent communication skills, able to adapt style for different audiences.
- Skilled at managing relationships with third-party service providers.
- Highly organized with the ability to prioritize workload effectively.
- Proactive, self-motivated, and able to work independently.
- Influential communicator with the ability to advocate your point of view.
- Creative and unorthodox thinker, capable of driving projects forward in unstructured environments.
- Methodical, logical, calm under pressure.
- Excellent written and verbal English skills.
Qualifications
- Relevant certifications or qualifications in information security or compliance are advantageous but not mandatory.
- A passion for continuous learning and staying current with industry trends is essential.
Charlotte Tilbury





















