> Markdown version of [/jobs/ext/2239230-information-security-lead](https://www.wearedevelopers.com/jobs/ext/2239230-information-security-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Lead - **Company:** Harvey Nash - **Location:** Birmingham, UK - **Experience:** Expert - **Salary:** £80,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Software as a Service, CompTIA Security+, Cyber Security, Software Engineering, Software Vulnerability Management, Web Applications, Information Technology - **Published:** August 26, 2026 - **Apply:** https://www.collegerecruiter.com/job/2815172607-information-security-lead ## About the Role * Strong knowledge of security frameworks (ISO 27001, NIST). * Experience with GDPR and corporate client compliance requirements. * Technical understanding of web app vulnerabilities and testing methodologies. * Proven ability to develop and implement security policies and procedures. * Skilled in risk assessment and stakeholder communication. * Excellent interpersonal and influencing skills across all levels. * Collaborative mindset with experience working across Engineering, IT, Legal, etc. * Security certifications (CISSP, CISM, CompTIA Security+) are highly desirable. * SaaS experience is a plus. ## Description Overview Consultant | Cyber Security / Tech Recruitment | Harvey Nash Title: Information Security Lead Location: Birmingham, West Midlands Salary: Up to £80,000 + 10% Bonus Working arrangements: Hybrid - 1/2 days on site Harvey Nash is partnering with an exciting B2B SaaS scaleup to recruit an Information Security Lead. The organisation is innovative in the logistics space. This role is responsible for maturing the security posture across the business and reporting to the CPTO. Responsibilities * Own and evolve the information security strategy, policies, and procedures. * Lead risk assessments and manage the security risk register. * Drive compliance initiatives including ISO 27001, GDPR, and client-specific standards. * Oversee vulnerability management and coordinate penetration testing. * Develop and execute incident response plans. * Deliver engaging security awareness training across the business. * Evaluate and manage third-party vendor security risks. * Collaborate with engineering teams on monitoring and alerting systems. * Stay ahead of emerging threats and industry trends. * Support business continuity and disaster recovery planning. * Be the go-to contact for security queries from corporate clients, prospects, and auditors. Qualifications * Strong knowledge of security frameworks (ISO 27001, NIST). * Experience with GDPR and corporate client compliance requirements. * Technical understanding of web app vulnerabilities and testing methodologies. * Proven ability to develop and implement security policies and procedures. * Skilled in risk assessment and stakeholder communication. * Excellent interpersonal and influencing skills across all levels. * Collaborative mindset with experience working across Engineering, IT, Legal, etc. * Security certifications (CISSP, CISM, CompTIA Security+) are highly desirable. * SaaS experience is a plus. Additional details Seniority level: Not Applicable Employment type: Full-time Job function: Information Technology Industries: Software Development How to apply If this sounds like you or you would like to know more, apply directly or email an updated CV for a confidential chat around this exciting role and company ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Generate AI in the Browser with Chrome AI - Raymond Camden](https://www.wearedevelopers.com/videos/1770-generate-ai-in-the-browser-with-chrome-ai-raymond-camden) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [WebXR: Enabling Virtual and Augmented Reality on the Web](https://www.wearedevelopers.com/videos/965-webxr-enabling-virtual-and-augmented-reality-on-the-web) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)