> Markdown version of [/jobs/ext/3242977-head-of-information-security](https://www.wearedevelopers.com/jobs/ext/3242977-head-of-information-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Head of Information Security - **Company:** Mattioli Woods - **Location:** Leicester, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cyber Security, Data Security, Software Vulnerability Management - **Published:** September 22, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=71a732270c855b69 ## About the Role * Proven experience as a security leader, combining strong risk judgement with hands-on delivery capability * The ability to assess an environment quickly, distinguish genuine business risk from noise, and focus resources on the controls that materially improve resilience * Comfortable engaging ExCo on cyber risk strategy while working directly with technology teams and suppliers to ensure issues get resolved * Strong capability across identity, access, endpoint, infrastructure, cloud, application and data security, with a track record of building governance, policy and incident response frameworks * Experience operating in financial services or another highly regulated environment; wealth management experience is advantageous but not essential * A hands-on, delivery-focused approach - someone who identifies what matters most, prioritises it clearly and sees remediation through to completion ## Description Mattioli Woods is looking for a seasoned security leader to take ownership of information and cyber security across the Group. This is a senior, Group-level appointment - you will define and execute our security strategy, lead our response to cyber risk, and position security as an enabler of a simpler, scalable and trusted business rather than a function that sits around it. The Group operates in an FCA-regulated environment, continues to grow through acquisition, and is actively adopting AI, data and automation across its operations. We need someone with the judgement to focus on what genuinely matters, the credibility to engage both ExCo and engineering teams, and the delivery capability to drive remediation through to completion. This is a role for a practitioner, not a policy writer. What you'll be doing * Define and execute the Group information and cybersecurity strategy and roadmap, establishing a clear, evidence-based view of current maturity and risk exposure * Strengthen and standardise security controls - across identity, access, endpoint, infrastructure, cloud, application and data - across businesses brought together through acquisition * Establish effective vulnerability management, monitoring, incident response and cyber resilience, including independent testing and assurance exercises * Ensure security is embedded into the future enterprise architecture and technology change lifecycle, working closely with Enterprise Architecture and technology teams * Support the secure adoption of AI, data and automation, balancing innovation with appropriate controls, and own third-party and supplier security risk * Translate technical cyber risk into clear decisions for the CIO, ExCo and senior business leaders, and ensure the Group meets FCA and UK regulatory expectations including relevant certifications