R04 · Senior Manager
Senior Manager, Information Security & Data Risk
Role purpose
Lead client advisory engagements on information security, data risk, classification, resilience and compliance while preserving the client's ownership of risk acceptance and control decisions.
Key responsibilities
- Deliver QDKC-aligned client work using the official guides, templates and frameworks relevant to the engagement.
- Assess client evidence, facilitate workshops and produce traceable recommendations or implementation deliverables.
- Advise client leaders on security and information-risk priorities aligned with national requirements.
- For client engagements, embed risk assessment, classification, access control, incident response and resilience into data processes.
- For client engagements, oversee security monitoring, assurance, exceptions and remediation.
- For client engagements, advise data and technology leaders on secure architecture and operational controls.
- Transfer knowledge to client personnel and document decisions, assumptions, dependencies and handover requirements.
- Respect client governance: consultants advise, facilitate and deliver, but do not replace the client's accountable owners, approvers or governance bodies.
Recommended minimum requirements
Education: Bachelor's degree in cybersecurity, information security, computer science or a related field; master's degree preferred.
Experience: Typically 10+ years in information security or technology risk, including 4+ years in leadership.
Core competencies: Security governance, Risk assessment, Data classification, Identity and access management, Resilience, Regulatory compliance
Preferred certifications
Preferred, but not mandatory:
- CISSP
- CISM
- IAPP CIPP or CIPM
Ready to apply for this role?
Apply for Senior Manager, Information Security & Data RiskDon't see the perfect fit?
We're always looking for exceptional people. Send us your CV and tell us how you'd contribute to the DAI mission.

