Focusrite Logo

Information Security & Data Protection Manager

💰 $80k-$114k

Job Description

Information Security & Data Protection Manager

Based: Remote (UK)/High Wycombe/London (N7)/Hybrid

Term: Permanent, Full time

Reporting to: Chief Information Officer (CIO)

Salary: £60k - £85k pa + excellent benefits

The Role:

We’re looking for an Information Security Compliance Specialist to take ownership of our Information Security, Data Protection, and AI Governance programmes across the Focusrite Group. You will be the operational owner of our Information Security and Data Protection (ISDP) framework informed by ISO 27001 (ISMS), ISO 27701 (PIMS), Cyber Essentials and NIST CSF keeping us aligned to those standards and ready for certification and audit.

Working alongside development, IT, and business teams, you will advise on security and privacy requirements for new and changing systems, ensuring appropriate controls are designed in, evidenced, and verified after implementation. You will also own the Group’s response to emerging risks in AI, translating evolving regulation (EU AI Act, UK AI principles, ICO guidance) into practical governance.

About you:

Several years’ experience in Information Security and Data Protection, with a good understanding of IT systems, web operations, cloud platforms, and secure coding practices (including OWASP).

Comfortable engaging at all levels of the organisation and externally, with the gravitas to influence security and privacy outcomes and reduce the impact of change.

The position requires providing support and advice to all parts of the Group on Information Security and Data Protection.

You will be responsible for:

Information Security Systems:

o   Framework & advisory: own the Information Security and Data Protection Framework and its documentation, and advise IT, development, and business teams on security requirements

o   Tools & supplier assurance: run the Business Approved Tools process (including assessment of AI tools, vendors, and use cases), own designated Information Security tools, and conduct supplier audit assessments

o   Certification & standards: own certification readiness for Cyber Essentials and lead new certification efforts as the business requires

o   Threats, incidents & testing: monitor cyber threats and translate them for the business, own the incident management process (including phishing response and simulation exercises), and manage vulnerability scans and penetration testing (including external Red/Purple/Blue Team engagements)

o   Risk & resilience: conduct risk assessments across products, systems, and processes; own the Information Security and Data Protection risk register, contributing to the Group Risk Management process; and maintain and test the Business Continuity Plan (BCP)

o   AI Governance: own the AI Governance framework, AI system inventory, and alignment with ISO 42001, NIST AI RMF, and the EU AI Act where appropriate

Data Protection compliance primarily UK GDPR and Data Protection Act, EU GDPR, and US state privacy laws (including CCPA/CPRA), to own and maintain all requirements including:

o   Data subject rights & assessments: handle Data Subject Rights requests (Subject Access, erasure, rectification, restriction, objection, portability, and rights relating to automated decision-making) and run Data Protection Impact Assessments (DPIAs)

o   Records & registers: maintain the Records of Processing Activities (RoPA) under Article 30 for controller and processor activities, the lawful basis register, consent records, and Legitimate Interest Assessments (LIAs)

o   Notices, cookies & marketing: operate Privacy Notices and Cookie Tools (OneTrust), and advise on PECR and e-privacy compliance including direct marketing and electronic communications

o   Privacy by Design & training: help product managers and developers embed Privacy by Design, and design and deliver Data Protection training and awareness across the Group

o   Retention & breach management: own the retention schedule and deletion/anonymisation processes, and own personal data breach handling (including detection triage, 72-hour ICO/EU supervisory authority notification, data subject notification where required, and the breach register)

o   Third parties & international transfers: manage processor and sub-processor governance (Article 28 due diligence, Data Processing Agreements, processor register) and international data transfers (SCCs, the UK IDTA/Addendum, and Transfer Risk Assessments)

Change Management:

o   Review and provide security and data protection sign-off on changes to systems, products, and processes

o   Participate in the Change Advisory Board (CAB) and ensure security and privacy risks are assessed before changes are approved

o   Own change management procedures relating to Information Security and Data Protection, ensuring evidence is captured for audit

o   Ensure security and privacy requirements are embedded in the SDLC and release processes, working with development and operational teams

o   Track and report on the security impact of significant business, technology, and organisational change initiatives

Compliance:

o   Generate monthly compliance and activity reports and other reports as required by senior management

o   Internal Audit:

o   Reviewing Financial System compliance activities

o   Performing Internal Information Security Audits

o   Performing Internal Data Protection Audits

External audit:

o   Be the key contact for any IT / Data Protection related audits by external bodies, ensuring requested data is supplied, complete, and accurate

o   Take ownership of any related audit issues

o   Generate audit support documents

You will be expected to keep up to date with developments in the security, privacy, and AI regulatory landscape, translating these into practical actions for the Group.

We understand that not all candidates will have in depth experience of all these elements, so we welcome applications from candidates who meet most of the criteria and have a desire to learn the rest. Please provide details in your covering letter of additional training requirements / certifications in progress etc.

About Us

Focusrite plc is a global music and audio group that develops and markets music technology products. Used by audio professionals and amateur musicians alike, our solutions facilitate the high-quality production of recorded and live sound. Our audio technology brands stand together, seeking to enrich lives through music by removing barriers to creativity – ‘we make music easy to make’.

The Focusrite Group trades under thirteen established and rapidly growing brands: Focusrite, Focusrite Pro, Novation, ADAM Audio, Sequential, Oberheim, Martin Audio, Optimal Audio, Ampify Music, Linea Research, Sonnox, OutBoard and TiMax. With a high-quality reputation and a rich heritage spanning decades, its brands are category leaders in the music-making industry.

Music technology is an enriching space to work in and we enjoy a Group-wide open-door culture which encourages innovation. This culture, combined with a passion for the inspirational solutions we create, has led to the group winning numerous accolades, including six Queen’s Awards, the AIM Company of the Year Award 2021 and regular appearances in ‘The Sunday Times 100 Best Small Companies to Work For’.

The Focusrite Group is dedicated to building a great place to work and as an equal opportunity employer we are committed to Diversity and Inclusion. The group mission is to cultivate an equitable culture, internally and externally, where all people feel they are welcome, safe and positively represented, because at Focusrite they truly are. Equally, we recognise the major impact that climate change is having on our world and work every day towards being industry leaders in a carbon neutral future.

Benefits include flexible/hybrid working, company pension, life insurance, private healthcare, Health Cash Plan, enhanced Maternity and Paternity pay, employee purchase scheme, group bonus scheme, company music events, offsite company parties and free lunch in the canteen. We arrange company training sessions and encourage personal development.

Share this job:
Please let Focusrite know you found this job on Remote First Jobs 🙏

5219 similar remote jobs

Explore latest remote opportunities and join a team that values work flexibility.

Remote companies like Focusrite

Find your next opportunity with companies that specialize in Musical Instruments, Audio Interfaces, Microphone Preamps, and Keyboards. Explore remote-first companies like Focusrite that prioritize flexible work and home-office freedom.

Fender Musical Instruments Corporation Logo

Fender Musical Instruments Corporation

1001-5000 www.fender.com

Manufactures and distributes musical instruments, pro audio equipment, accessories, and digital products.

View company profile →
Universal Audio Logo

Universal Audio

Develops and manufactures audio interfaces, analog hardware, and digital audio plug-ins for music recording and production.

View company profile →
PreSonus Logo

PreSonus

Manufactures audio mixers, interfaces, studio monitors, loudspeakers, and software for audio production.

View company profile →
Biamp Logo

Biamp

501-1000 www.biamp.com

Provides networked media systems and professional AV equipment for audiovisual installations.

View company profile →
Emma – The Sleep Company Logo

Emma – The Sleep Company

Designs and manufactures sleep comfort products, available in over 35 countries with 25+ stores.

View company profile →
Astrodyne TDI Logo

Astrodyne TDI

Designs and manufactures custom power solutions and EMI filters for demanding applications worldwide.

View company profile →

Project: Career Search

Rev. 2026.5

[ Remote Jobs ]
Direct Access

We source jobs directly from 21,000+ company career pages. No intermediaries.

01

Discover Hidden Jobs

Unique jobs you won't find on other job boards.

02

Advanced Filters

Filter by category, benefits, seniority, and more.

03

Priority Job Alerts

Get timely alerts for new job openings every day.

04

Manage Your Job Hunt

Save jobs you like and keep a simple list of your applications.

21,000+ SOURCES UPDATED 24/7
Apply