Location
London
Hours
Full Time
Salary
Competitive salary package
About the Role
This role blends hands-on technical security expertise with risk management, governance, and assurance, ensuring business objectives are supported while minimising cyber and data protection risks. As an Information Security Manager, you will drive security architecture decisions, lead incident response and vulnerability management efforts, and support secure digital transformation initiatives. You will provide clear, risk-based guidance to stakeholders and senior leadership to strengthen the organisation’s overall security posture.
Key responsibilities include developing and implementing IT Security strategy, policies, programs and procedures, and driving their implementation and maintenance across Millennium Hotels and Resorts UK. You will manage daily IT Security operations within the UK region and provide IT Security consulting support across various business units. Promoting IT Security awareness among end users and collaborating with key business stakeholders to incorporate IT innovations and process improvements into their operations are also essential.
Additional responsibilities include managing and driving special projects or initiatives as assigned, leading the PCI-DSS compliance program with business stakeholders, staying current on emerging security technologies, tracking and documenting security incidents, and performing periodic IT Security audits across UK properties to ensure compliance with established policies, PCI-DSS, and regulatory requirements.
We offer a comprehensive benefits package including social events, wellbeing and team activities, training and development, pension salary sacrifice scheme, career development and salary reviews, interest-free season ticket loan scheme, one fully paid volunteer day per year in addition to annual leave, complimentary meals prepared by our chefs, length of service related holiday scheme, My Millennium discount perks, discounts on accommodation worldwide and food and beverage outlets, life assurance, and a recommend a friend scheme.
Experience
Proven experience in information security management, including hands-on technical security expertise, risk management, governance, and assurance. Experience leading incident response, vulnerability management, and PCI-DSS compliance programs is essential.
About you
Strong leadership and communication skills with the ability to provide clear, risk-based guidance to stakeholders and senior leadership. Proactive, detail-oriented, and able to manage multiple priorities and special projects. A collaborative approach to working with IT, HR, and business teams to promote security awareness and implement effective controls.
Qualifications
Relevant professional certifications in information security (e.g., CISSP, CISM, CISA) are highly desirable. A solid understanding of IT security frameworks, regulatory requirements, and emerging security technologies is required.
Millennium Hotel and Resorts UK










