About this role
Ideas | People | Trust
We’re BDO. An accountancy and business advisory firm, providing the advice and solutions entrepreneurial organisations need to navigate today’s changing world.
We work with the companies that are Britain’s economic engine – ambitious, entrepreneurially-spirited and high‑growth businesses that fuel the economy - and directly advise the owners and management teams that lead them.
We’ll broaden your horizons
The Quality and Risk Management Team (QRMT) at BDO comprises several sub-teams including the Legal Team, CISO, Enterprise Risk Management, Economic Crime, Quality Management, Ethics and Independence and Advisory and Compliance. It provides Partners and staff with the guidance, tools and support to enable them to identify and manage quality and risk issues. The QRMT is led by the Head of Quality and Risk Management Team, who is a partner who reports into the Head of Quality and Risk for the firm and sits on the BDO Leadership Team.
We’ll help you succeed
Leading organisations trust us because of the quality of our advice. That quality grows from a thorough understanding of their business, and that understanding comes from working closely with them and building long-lasting relationships.
You’ll be someone who is both comfortable working proactively and managing your own tasks, as well as confident collaborating with others and communicating regularly with senior managers, directors, and BDO’s partners to help businesses effectively. You’ll be encouraged to identify and draw attention to opportunities for enhancing our delivery and providing additional services to organisations we work with.
Role purpose:
Reporting to CISO the Information Security Senior Manager is a subject-matter role responsible for designing and maintaining a structured, documented and evidence-based ISO27001 information security management systems and professional services aligned controls framework across the firm. The role provides strong expertise in Information security risk management to ensure controls are appropriately designed, implemented, operated and demonstrably effective.
Principal accountabilities:
- Design, maintain and continuously improve an information security controls framework aligned with the firm’s strategy, risk appetite, policies, legislation, regulatory obligations, client commitments and recognised standards.
- Develop and maintain information security policies and the supporting standards, procedures and guidance that form part of the firm’s Information Security Management System.
- Coordinate and evidence the annual review of the Information Security Management System, identify improvements, agree proportionate actions and monitor findings through to closure.
- Plan, coordinate and support internal audits of compliance with ISO 27001 and related requirements, ensuring identified exposures and non-conformities are assessed, remediated and verified.
- Define clear control objectives, requirements, ownership, evidence standards, compliance approaches and effectiveness criteria, ensuring traceability from risks, policies, legislation and standards to control implementation.
- Lead compliance reporting and remediation initiatives, coordinating across Information Technology, Human Resources, Risk, Legal, Data Protection, Internal Audit and business functions.
- Ensure partners and employees understand their information security obligations by developing practical guidance, communications and stakeholder engagement that embed controls into day-to-day business processes.
- Provide authoritative information security advice and constructive challenge to control owners and stakeholders, involving relevant specialists where required.
- Produce clear, concise reporting on control coverage, maturity, exceptions, effectiveness, remediation and residual risk for senior management, governance committees, clients, auditors and assurance providers.
- Lead complex cross-functional projects within the role’s area of expertise, establishing plans, managing dependencies and contingencies, and delivering high-quality outcomes through influence rather than direct line-management authority.
Behaviours and attitude:
- Demonstrates a quality mindset, strong technical expertise and diligent professional judgement when evaluating complex information security matters.
- Builds trusted relationships across functions and uses evidence, reasoned argument and diverse viewpoints to influence outcomes without relying on formal authority.
- Communicates complex control issues clearly and credibly, adapting the message for technical, operational, executive, client and assurance audiences.
- Provides constructive challenge, remains composed in difficult situations and makes balanced recommendations based on risk, evidence and business context.
- Plans and delivers complex work with clear priorities, contingencies, measurable outcomes and high-quality outputs.
- Shares expertise proactively, supports the development of colleagues and contributes to an inclusive learning culture, without direct line-management accountability.
- Champions continuous improvement by testing assumptions, analysing gaps and ensuring lessons learned are incorporated into future control design and operation.
Technical competencies:
- Essential professional-services experience, with a strong understanding of client confidentiality, regulatory scrutiny, contractual assurance, partnership environments and proportionate risk management.
- Demonstrable experience designing, documenting and maintaining enterprise information security controls and control frameworks.
- Strong knowledge of control design and operating-effectiveness assessment, including control objectives, risks, evidence requirements, test procedures, sampling, deficiency evaluation and remediation tracking.
- Experience creating structured, traceable and auditable control libraries that map policies, standards, risks, obligations and assurance evidence.
- Strong working knowledge of ISO 27001 and relevant control or risk frameworks such as NIST CSF, NIST 800-53, CIS Controls or COBIT.
- Ability to analyse complex technical and business information, identify root causes and translate findings into prioritised, practical recommendations.
- Experience reporting control effectiveness, exceptions and residual risk to senior stakeholders, governance forums, clients, auditors or regulators.
- Experience leading complex cross-functional security, assurance or remediation projects through influence rather than direct managerial authority.
- Knowledge of relevant UK data protection, security and professional-services obligations.
- Relevant professional certification such as CISSP, CISM, CISA, CRISC or ISO 27001 Lead Implementer/Lead Auditor is desirable.
You’ll be able to be yourself; we’ll recognise and value you for who you are and celebrate and reward your contributions to the business. We’re committed to agile working, and we offer every colleague the opportunity to work in ways that suit you, your teams, and the task at hand.
At BDO, we’ll help you achieve your personal goals and career ambitions, and we have programmes, resources, and frameworks that provide clarity and structure around career development.
We’re in it together
Mutual support and respect is one of BDO’s core values and we’re proud of our distinctive, people-centred culture. From informal success conversations to formal mentoring and coaching, we’ll support you at every stage in your career, whatever your personal and professional needs.
Our agile working framework helps us stay connected, bringing teams together where and when it counts so they can share ideas and help one another. At BDO, you’ll always have access to the people and resources you need to do your best work.
We know that collaboration is the key to creating value for the companies we work with and satisfying experiences for our colleagues, so we’ve invested in state-of-the-art collaboration spaces in our offices. BDO’s people represent a wealth of knowledge and expertise, and we’ll encourage you to build your network, work alongside others, and share your skills and experiences. With a range of multidisciplinary events and dedicated resources, you’ll never stop learning at BDO.
We’re looking forward to the future
At BDO, we help entrepreneurial businesses to succeed, fuelling the UK economy. Our success is powered by our people, which is why we’re always finding new ways to invest in you. Across the UK thousands of unique minds continue to come together to help companies we work with to achieve their ambitions
We’ve got a clear purpose, and we’re confident in our future, because we’re adapting and evolving to build on our strengths, ensuring we continue to find the right combination of global reach, integrity and expertise. We shape the future together with openness and clarity, because we believe in empowering people to think creatively about how we can do things better.