> Markdown version of [/jobs/ext/3042883-head-of-information-security](https://www.wearedevelopers.com/jobs/ext/3042883-head-of-information-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Head of Information Security - **Company:** Oakley Recruitment - **Location:** Birmingham, UK - **Experience:** Expert - **Salary:** £26,000.0 - £26,500.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Software as a Service, Cloud Computing, Cyber Security, Disaster Recovery, Open Web Application Security, Software Vulnerability Management, Information Security Management System, Google Cloud, Software Security, Cyber Threat Analysis, CIS Benchmarks, Devsecops - **Published:** September 24, 2026 - **Apply:** https://www.oakleyrecruitment.co.uk/contact-oakley ## About the Role * Demonstrating strong experience within information or cyber security, ideally at management or senior management level * Experience developing or contributing to security strategies, frameworks, policies and risk-based programmes * Working knowledge and experience of ISO 27001 and ISMS environments * Strong understanding of cloud, SaaS, identity, APIs, application security and data protection * Experience overseeing vulnerability management, penetration testing and incident response * Ability to translate technical security risks into clear commercial language for senior stakeholders * Experience assessing third-party and supply-chain security risks * Strong knowledge of UK data protection and cyber security requirements * Confident communication skills with the ability to influence and constructively challenge stakeholders * Leadership capability with the ambition to continue developing at a senior level * Experience within technology, SaaS, automotive, financial services, regulated or data-sensitive environments would be advantageous * Exposure to Cyber Essentials Plus, SOC 2, NIST, CIS Controls, OWASP, AWS, Azure or Google Cloud would be beneficial This is an excellent opportunity for an ambitious Information Security professional who is ready to take greater ownership and influence within a growing organisation. ## Description This is a growing, technology-led organisation operating across the UK and internationally. As the business continues to develop, information security will play an increasingly important role in supporting its future growth. This is an exciting opportunity to join at a pivotal stage. Rather than stepping into a large, established security function, you will have the opportunity to shape how information security operates across the organisation. Working closely with the CEO and senior leadership team, you will have genuine exposure at the highest level of the business, with the autonomy to develop the security strategy, strengthen governance and help shape the future security operating model. For someone ambitious about progressing their career, there is a clear opportunity to grow with the organisation and develop towards becoming its future CISO. Personality We are looking for someone who combines strong information and cyber security knowledge with the ambition and confidence to step into a broader leadership position. You will be commercially minded, pragmatic and comfortable constructively challenging stakeholders. You will be able to take complex technical risks and communicate them clearly to both technical and non-technical audiences. You will enjoy taking ownership, identifying where improvements can be made and building something for the future rather than simply maintaining what is already in place. You do not need to be an established CISO. This opportunity is about finding someone with strong technical and security foundations, leadership capability and the potential to develop into a senior executive security leader as the organisation grows. Package and Benefits * £70,000 salary * Additional benefits package * Birmingham based * Travel as required * Newly created senior leadership position * Direct exposure to the CEO and senior leadership team * Genuine autonomy to shape the organisation's security strategy and framework * Clear opportunity to develop into the organisation's future CISO Job Role * Developing and maintaining the organisation's information security strategy, policies and security roadmap * Leading and continually developing an ISO 27001-aligned Information Security Management System (ISMS) * Maintaining the security risk register and ensuring appropriate controls and mitigation plans are in place * Providing clear security reporting, insight and assurance to the CEO and senior leadership team * Overseeing security across cloud infrastructure, SaaS applications, APIs, identity, endpoints and data * Managing vulnerability management, penetration testing, monitoring and remediation activity * Working alongside technology and development teams to embed secure-by-design and DevSecOps principles * Owning and developing the cyber incident response framework * Supporting business continuity, disaster recovery and wider cyber resilience planning * Managing information security risks across suppliers and technology partners * Coordinating specialist external security providers where required * Developing security awareness and supporting a strong security culture across the organisation * Monitoring emerging cyber threats, regulatory requirements and technology risks, including those associated with AI * Continuing to develop the security function and operating model as the organisation grows * Building the capability and executive-level experience required to progress towards future CISO responsibility ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)