Summary
Linnworks is a SaaS company providing eCommerce automation for retail, inventory, and shipping processes. The Information Security Project Manager coordinates information security projects, ISO 27001 audits, customer security requests, policies, and governance while communicating risks and recommendations across technical and business teams.
Responsibilities
- Plan, coordinate, and execute internal audits and control reviews against ISO 27001 (and related frameworks where relevant)
- Maintain audit schedules, evidence repositories, and action logs so that we are consistently “audit ready” rather than scrambling before assessments
- Work with control owners across the business to ensure that required processes are in place, understood, and operating in a pragmatic way
- Track findings and remediation actions, ensuring owners are clear on what needs to be done and by when, and following up to completion
- Support external ISO 27001 surveillance and recertification audits, including planning, evidence collation, and managing auditor queries
- Coordinate discrete security improvement projects (for example, rolling out new security tooling, tightening access controls, or updating key policies)
- Break down security initiatives into clear tasks, owners, and timelines, and keep stakeholders informed on progress and risks
- Work with Technical Operations and Engineering to ensure technical changes are understood, documented, and reflected in our security posture
- Help prioritise security work by articulating risk, impact, and effort, while understanding the wider commercial and delivery context
- Partner with Sales, Pre-Sales, and Customer Success to respond to customer security questionnaires, RFPs, RFQs, and due diligence requests
- Maintain and continuously improve a central library of standard security responses and artefacts (for example, summaries of our controls, certifications, and processes)
- Coordinate input from Technical Operations, Engineering, and Legal where deeper technical or contractual responses are required
- Attend customer calls when needed to explain our security posture in clear, non-alarmist language and build confidence in our approach
- Develop and maintain a clear, concise view of our security posture that can be communicated internally and to customers (for example, how we handle data, access, monitoring, and incident response at a high level)
- Ensure that key facts (such as use of encryption at rest and in transit, SSO capabilities, backup approaches, and incident processes) are understood and kept up to date, even if technical details are owned by others
- Translate technical explanations from engineers into language suitable for non-technical audiences, including customers and internal stakeholders
- Help ensure that security-related messages are proportionate, avoiding both complacency and unnecessary drama
- Maintain a focused, manageable set of security policies and procedures that reflect how we actually operate
- Work with policy owners to keep documents current, usable, and aligned to ISO 27001 and customer expectations, avoiding policy sprawl and unnecessary complexity
- Coordinate periodic reviews of key policies and standards, ensuring changes are communicated and understood
- Provide recommendations to the Director of Technical Operations on improvements to policies, controls, or tooling, with clear reasoning and trade-offs
Skills
- 3–5 years of experience in information security, compliance, risk, or IT audit within a SaaS or technology environment
- Hands-on experience with ISO 27001 (or similar frameworks), including audits, evidence collection, and remediation tracking
- Solid project management skills — planning, tracking progress, managing stakeholders, and communicating clearly
- Working knowledge of core security concepts such as encryption (at rest/in transit), access control, SSO/identity providers, backup and recovery, logging, and incident response — enough to discuss confidently and know when to bring in a specialist
- Comfortable engaging directly with customers and auditors, answering questions calmly and credibly
- Strong writing skills for policies, reports, and customer communications, paired with clear verbal communication across technical and non-technical audiences
- Pragmatic and commercially aware: able to distinguish between theoretical risk and real-world impact
- Collaborative, working with teams to find workable solutions rather than simply saying “no”
- Organised and methodical, keeping track of multiple audits, projects, and requests without dropping details
- Calm and credible under pressure, especially during audits, customer escalations, or security-related incidents
- Comfortable asking questions, challenging assumptions, and highlighting risk while still respecting broader business priorities
Qualifications
Must Haves
- 3–5 years of experience in information security, compliance, risk, or IT audit within a SaaS or technology environment
- Hands-on experience with ISO 27001 (or similar frameworks), including audits, evidence collection, and remediation tracking
- Solid project management skills — planning, tracking progress, managing stakeholders, and communicating clearly
- Working knowledge of core security concepts such as encryption (at rest/in transit), access control, SSO/identity providers, backup and recovery, logging, and incident response — enough to discuss confidently and know when to bring in a specialist
- Comfortable engaging directly with customers and auditors, answering questions calmly and credibly
- Strong writing skills for policies, reports, and customer communications, paired with clear verbal communication across technical and non-technical audiences
- Pragmatic and commercially aware: able to distinguish between theoretical risk and real-world impact
- Collaborative, working with teams to find workable solutions rather than simply saying “no”
- Organised and methodical, keeping track of multiple audits, projects, and requests without dropping details
- Calm and credible under pressure, especially during audits, customer escalations, or security-related incidents
- Comfortable asking questions, challenging assumptions, and highlighting risk while still respecting broader business priorities
Benefits
- Remote & flexible working – with hybrid options in London or Chichester
- Fantastic team culture based on trust and belonging.
- Laptop & home office budget – 500 EUR to set up your ideal workspace.
- Private Medical Insurance with Aviva, including Dental & Optical.
- Group Life Insurance & Yulife Wellbeing & Rewards.
- Mental well-being support – Access therapy, mental health sessions, and yoga through a free premium subscription to Headspace.
- EAP confidential benefit – 24/7 access to compassionate guidance & expert advice
- 25 days holiday + bank holidays
- Training, support, and personal development