IT Controls & Security Manager
Posted 4 hours 6 minutes ago by AXA Group
Drive Security, Resilience and Operational Excellence at Laya Healthcare
At Laya Healthcare, we're committed to delivering exceptional healthcare experiences through innovation, technology, and operational excellence. As part of our continued investment in technology and cyber resilience, we're looking for an experienced IT Controls & Security Manager to lead our operational security function and help safeguard the systems and services that support our members and colleagues every day.
Reporting to the Head of IT Operations, this is a key leadership role responsible for managing a team of security professionals, driving security best practices, strengthening operational controls, and ensuring compliance across our technology landscape.
What You'll DoAs our IT Controls & Security Manager, you will:
- Lead and develop a team of security and controls professionals, fostering a culture of excellence and continuous improvement.
- Drive the implementation and ongoing enhancement of IT operational security strategies, policies, and procedures.
- Own vulnerability and patch management programmes, ensuring compliance with service levels and security metrics.
- Optimise security technologies and operational tooling to support business and security objectives.
- Coordinate security incident response activities and lead post-incident reviews and lessons learned.
- Collaborate closely with Infrastructure, Applications, Architecture, and Information Security teams to deliver secure and resilient solutions.
- Support risk assessments, vulnerability management initiatives, and regulatory compliance activities.
- Ensure adherence to recognised frameworks and standards including ISO 27001, NIST, and GDPR.
- Act as a key stakeholder within Service Delivery and Incident Management processes.
- Build strong relationships with technology partners, vendors, auditors, and security consultants.
- Provide meaningful reporting and security insights to senior leadership.
- Participate in the Architecture Review Board, ensuring security considerations are embedded in technology decisions.
We're looking for a proven leader with a passion for cybersecurity, risk management, and operational excellence.
Essential Experience- 5+ years' experience leading IT teams within a security, infrastructure, or operational technology environment.
- Strong knowledge of cybersecurity frameworks, standards, and security best practices.
- Experience managing vulnerability management, security operations, and incident response activities.
- Proven ability to build strong stakeholder relationships and communicate effectively across technical and non-technical audiences.
- Experience working in a regulated environment such as healthcare, insurance, or financial services.
- Strong decision-making, problem-solving, and people leadership skills.
Experience with a number of the following technologies would be advantageous:
- SIEM platforms
- Qualys
- Microsoft Endpoint Configuration Manager (MECM)
- Microsoft Intune
- Data Loss Prevention (DLP) solutions
- Endpoint protection technologies
- Ansible
- Red Hat Enterprise Linux and Red Hat Satellite
- Cloud security across AWS, Azure, and/or GCP
- DevOps environments and CI/CD pipelines
- Bachelor's degree in Information Security, Computer Science, Information Technology, or a related discipline.
- Industry certifications such as CISSP, CISM, or equivalent are highly desirable.
At Laya Healthcare, you'll join a collaborative organisation where technology plays a critical role in delivering better healthcare outcomes. You'll have the opportunity to lead impactful security initiatives, influence strategic decisions, and work alongside talented colleagues who are passionate about innovation and continuous improvement.
If you're ready to take the next step in your cybersecurity leadership career and make a real difference in a purpose-driven organisation, we'd love to hear from you.
Application Close Date: 23rd August