Head of Information Security
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+5 more
Job description
This is a growing, technology-led organisation operating across the UK and internationally. As the business continues to develop, information security will play an increasingly important role in supporting its future growth.
This is an exciting opportunity to join at a pivotal stage. Rather than stepping into a large, established security function, you will have the opportunity to shape how information security operates across the organisation.
Working closely with the CEO and senior leadership team, you will have genuine exposure at the highest level of the business, with the autonomy to develop the security strategy, strengthen governance and help shape the future security operating model.
For someone ambitious about progressing their career, there is a clear opportunity to grow with the organisation and develop towards becoming its future CISO.
Personality
We are looking for someone who combines strong information and cyber security knowledge with the ambition and confidence to step into a broader leadership position.
You will be commercially minded, pragmatic and comfortable constructively challenging stakeholders. You will be able to take complex technical risks and communicate them clearly to both technical and non-technical audiences.
You will enjoy taking ownership, identifying where improvements can be made and building something for the future rather than simply maintaining what is already in place.
You do not need to be an established CISO. This opportunity is about finding someone with strong technical and security foundations, leadership capability and the potential to develop into a senior executive security leader as the organisation grows.
Package and Benefits
- £70,000 salary
- Additional benefits package
- Birmingham based
- Travel as required
- Newly created senior leadership position
- Direct exposure to the CEO and senior leadership team
- Genuine autonomy to shape the organisation’s security strategy and framework
- Clear opportunity to develop into the organisation’s future CISO
Job Role
- Developing and maintaining the organisation’s information security strategy, policies and security roadmap
- Leading and continually developing an ISO 27001-aligned Information Security Management System (ISMS)
- Maintaining the security risk register and ensuring appropriate controls and mitigation plans are in place
- Providing clear security reporting, insight and assurance to the CEO and senior leadership team
- Overseeing security across cloud infrastructure, SaaS applications, APIs, identity, endpoints and data
- Managing vulnerability management, penetration testing, monitoring and remediation activity
- Working alongside technology and development teams to embed secure-by-design and DevSecOps principles
- Owning and developing the cyber incident response framework
- Supporting business continuity, disaster recovery and wider cyber resilience planning
- Managing information security risks across suppliers and technology partners
- Coordinating specialist external security providers where required
- Developing security awareness and supporting a strong security culture across the organisation
- Monitoring emerging cyber threats, regulatory requirements and technology risks, including those associated with AI
- Continuing to develop the security function and operating model as the organisation grows
- Building the capability and executive-level experience required to progress towards future CISO responsibility
Requirements
- Demonstrating strong experience within information or cyber security, ideally at management or senior management level
- Experience developing or contributing to security strategies, frameworks, policies and risk-based programmes
- Working knowledge and experience of ISO 27001 and ISMS environments
- Strong understanding of cloud, SaaS, identity, APIs, application security and data protection
- Experience overseeing vulnerability management, penetration testing and incident response
- Ability to translate technical security risks into clear commercial language for senior stakeholders
- Experience assessing third-party and supply-chain security risks
- Strong knowledge of UK data protection and cyber security requirements
- Confident communication skills with the ability to influence and constructively challenge stakeholders
- Leadership capability with the ambition to continue developing at a senior level
- Experience within technology, SaaS, automotive, financial services, regulated or data-sensitive environments would be advantageous
- Exposure to Cyber Essentials Plus, SOC 2, NIST, CIS Controls, OWASP, AWS, Azure or Google Cloud would be beneficial
This is an excellent opportunity for an ambitious Information Security professional who is ready to take greater ownership and influence within a growing organisation.
About the company
Oakley Recruitment is working in partnership with an expanding organisation based in Birmingham. This is an excellent opportunity to join the team as a Customer Service Advisor on a full-time permanen Customer Service Advisor - Coventry - £26,000 to £26,500
Oakley Recruitment is working in partnership with an expanding organisation based in Coventry. This is an excellent opportunity to join the team as a Customer Service Advisor on a full-time permanent
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
IT Salaries in UK
Understanding and Mitigating Common Web Vulnerabilities
The 12 Best Jobs for Software Engineers
Is Software Engineering Over-Saturated?