Information Security Lead

Harvey Nash
Birmingham, UK
18 days ago
Apply on www.collegerecruiter.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
£80,000.0
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Software as a Service CompTIA Security+ Cyber Security Software Engineering Software Vulnerability Management Web Applications Information Technology

Job description

Overview

Consultant Cyber Security / Tech Recruitment Harvey Nash

Title: Information Security Lead

Location: Birmingham, West Midlands

Salary: Up to £80,000 + 10% Bonus

Working arrangements: Hybrid - 1/2 days on site

Harvey Nash is partnering with an exciting B2B SaaS scaleup to recruit an Information Security Lead. The organisation is innovative in the logistics space. This role is responsible for maturing the security posture across the business and reporting to the CPTO.

Responsibilities

  • Own and evolve the information security strategy, policies, and procedures.
  • Lead risk assessments and manage the security risk register.
  • Drive compliance initiatives including ISO 27001, GDPR, and client-specific standards.
  • Oversee vulnerability management and coordinate penetration testing.
  • Develop and execute incident response plans.
  • Deliver engaging security awareness training across the business.
  • Evaluate and manage third-party vendor security risks.
  • Collaborate with engineering teams on monitoring and alerting systems.
  • Stay ahead of emerging threats and industry trends.
  • Support business continuity and disaster recovery planning.
  • Be the go-to contact for security queries from corporate clients, prospects, and auditors.

Qualifications

  • Strong knowledge of security frameworks (ISO 27001, NIST).
  • Experience with GDPR and corporate client compliance requirements.
  • Technical understanding of web app vulnerabilities and testing methodologies.
  • Proven ability to develop and implement security policies and procedures.
  • Skilled in risk assessment and stakeholder communication.
  • Excellent interpersonal and influencing skills across all levels.
  • Collaborative mindset with experience working across Engineering, IT, Legal, etc.
  • Security certifications (CISSP, CISM, CompTIA Security+) are highly desirable.
  • SaaS experience is a plus.

Additional details

Seniority level: Not Applicable

Employment type: Full-time

Job function: Information Technology

Industries: Software Development

How to apply

If this sounds like you or you would like to know more, apply directly or email an updated CV for a confidential chat around this exciting role and company

Requirements

  • Strong knowledge of security frameworks (ISO 27001, NIST).
  • Experience with GDPR and corporate client compliance requirements.
  • Technical understanding of web app vulnerabilities and testing methodologies.
  • Proven ability to develop and implement security policies and procedures.
  • Skilled in risk assessment and stakeholder communication.
  • Excellent interpersonal and influencing skills across all levels.
  • Collaborative mindset with experience working across Engineering, IT, Legal, etc.
  • Security certifications (CISSP, CISM, CompTIA Security+) are highly desirable.
  • SaaS experience is a plus.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.collegerecruiter.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

6:13 min

Analyzing test coverage gaps in standard web applications

Jorge Gonzalez Pliego Jorge Gonzalez Pliego · Europe 2026 Virtual

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:36 min

Running AI applications with PWAs and background web workers

Maxim Salnikov Maxim Salnikov · World Congress 2025

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all