> Markdown version of [/jobs/ext/1123911-head-of-it-security](https://www.wearedevelopers.com/jobs/ext/1123911-head-of-it-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Head of IT Security - **Company:** Capsticks - **Location:** London, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software as a Service, Cloud Computing, Encodings, Cyber Security, Identity and Access Management, Network Security, Zero Trust Network Access, Security Information and Event Management, Software Vulnerability Management, Information Security Management System, CIS Benchmarks - **Published:** July 2, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=1ac0367b5b2cef4c ## About the Role We are looking for someone who combines senior security expertise with pragmatic leadership and strong stakeholder engagement. You will bring: * Senior IT security leadership experience, ideally with exposure to CISO-level responsibilities. * Strong knowledge of security operations, identity and access management, cloud and network security, endpoint protection, email security and modern models such as Zero Trust / ZTNA. * Experience working with ISO27001, Cyber Essentials Plus and recognised security frameworks such as CIS Controls or NIST. * The ability to translate risk and compliance requirements into practical controls, services and improvement plans. * Experience managing teams, vendors and managed security services, ideally in a SaaS-focused professional services environment. * Clear communication skills, with the confidence to explain complex security topics to senior stakeholders, technical teams and external parties. * A pragmatic, outcome-focused and forward-looking approach, with the resilience to work effectively under pressure. ## Description We are looking for a senior IT security leader to define, implement and assure our information and cyber security posture across the firm. This is a new leadership role with broad responsibility for security strategy, standards, controls and services, operating at a level aligned to CISO capability. You will lead a proactive, risk-based approach to security, ensuring it is embedded into technology design, delivery and operations. Working closely with Governance & Risk, Architecture & Data, Platforms and Operations, you will help protect the firm against evolving threats while enabling secure innovation and service delivery., * Defining and implementing security strategy, standards and controls aligned to ISO27001, Cyber Essentials Plus and the firm's wider data, AI and innovation strategies. * Overseeing security operations, monitoring, detection and response across areas such as SOC, SIEM, XDR, vulnerability management and incident response. * Embedding security by design into projects, change and solution architecture, including identity, endpoint, cloud, network, email and secure remote access controls. * Working with Governance & Risk to maintain and improve the ISMS, support audits and ensure regulatory and client expectations are met. * Providing clear reporting on security posture, risks, incidents and improvement plans to technical and non-technical stakeholders. * Promoting a strong security culture through awareness, training and practical guidance on secure behaviours. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [A Brief History of Data Storage](https://www.wearedevelopers.com/videos/974-a-brief-history-of-data-storage) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london)