> Markdown version of [/jobs/ext/2992455-head-of-information-security](https://www.wearedevelopers.com/jobs/ext/2992455-head-of-information-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Head of Information Security - **Company:** Ordnance Survey - **Location:** Southampton, UK - **Experience:** Expert - **Salary:** £89,411.0 - £104,313.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Computer Programming, Cyber Laws, Software Vulnerability Management, Information Technology - **Published:** September 19, 2026 - **Apply:** https://ordnancesurvey.wd3.myworkdayjobs.com/OS_Careers/job/Southampton-United-Kingdom/Head-of-Information-Security_JR003068 ## About the Role You'll be an experienced leader with a track record of developing and leading information security, cyber security or related risk capabilities within a complex environment. You will combine strategic thinking with practical delivery and be comfortable working across organisational boundaries to deliver meaningful outcomes., * Significant experience leading information security, cyber security or security operations functions. * Strong understanding of information security risk management, security assurance, threat management and vulnerability management. * Knowledge of recognised security frameworks, standards, maturity models and related industry good practice. * Experience developing capabilities, services or operating models through structured maturity approaches and continuous improvement. * The ability to influence senior leaders and translate complex security challenges into practical organisational outcomes. * Experience using data, reporting and insights to support decision-making and drive performance improvement. * Experience building productive relationships with government organisations, regulators, industry partners or external security communities. * A collaborative leadership style that develops capability, builds trust and enables others to succeed., A key requirement of this role is the ability to obtain and maintain Developed Vetting (DV) security clearance., Government Security, Information Technology Security, Information Technology Strategies, Line Management Experience, National Security Law, Security Management, Security Programming, Security Standards, Security Tools, Stakeholder Engagement, Strategy Development ## Description We're looking for an experienced and collaborative Head of Information Security to lead the delivery and continual improvement of our Information Security capability. Reporting to the Chief Information Security Officer, you will help shape the direction of Information Security at OS while leading the services, controls and operational activities that keep our organisation secure. As a member of the Security & Resilience Leadership Team, you'll contribute to the development of security strategy and be accountable for translating that strategy into effective capabilities, services and outcomes. Working closely with colleagues across technology, product, operations and corporate functions, you will ensure security is practical, proportionate and embedded in the way we deliver services and manage risk. What you'll be doing You'll lead the day-to-day operation, delivery and continual improvement of OS's Information Security capability, ensuring our security services, controls and processes remain effective, proportionate and aligned to organisational priorities. You will be accountable for: * Contributing to the development and delivery of the Security Strategy and roadmap. * Leading and continually improving Information Security capabilities, services and operating models, ensuring they meet organisational needs and support business objectives. * Providing expert Information Security advice, guidance and assurance, ensuring security is embedded in business change, projects, products and technology delivery. * Leading the response to cyber and information security incidents and ensuring emerging threats and vulnerabilities are effectively managed. * Leading cyber and information security risk management activities, ensuring risks and controls are managed in line with organisational risk appetite and governance requirements. * Developing security reporting, metrics and insights that support decision-making, provide visibility of Information security performance and demonstrate the effectiveness of security controls. * Leading the ongoing review and improvement of Information Security capabilities, services and operating models, ensuring they evolve in line with organisational priorities, emerging threats and industry good practice. * Building strong partnerships across OS and with external stakeholders to strengthen security outcomes, organisational awareness and shared accountability for security. As an OS Leader Operating at the Leading Other Leaders level within the OS Leadership Framework, you will lead through Engage, Grow and Deliver, creating the environment, capability and alignment needed for teams and leaders to succeed. * Engage - Build trust, alignment and shared purpose across teams, functions and stakeholders. * Grow - Develop leaders, strengthen capability and prepare the organisation for future challenges and opportunities. * Deliver - Drive joined-up outcomes through effective decision-making, collaboration, accountability and continuous improvement., OS conducts pre-employment checks for anyone made an offer of employment, including identity, right to work, employment history and criminal record checks via the Disclosure & Barring Service (DBS). ## Related Videos - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Photonic Computing: Programming a New Class of AI Accelerators (incl. Live Coding)](https://www.wearedevelopers.com/videos/100196-photonic-computing-programming-a-new-class-of-ai-accelerators-incl-live-coding) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [We (don't) need a software architect!?!](https://www.wearedevelopers.com/videos/663-we-don-t-need-a-software-architect) ## Related Articles - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [Data Engineer Salary UK](https://www.wearedevelopers.com/magazine/253-data-engineer-salary-uk) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk)