> Markdown version of [/jobs/ext/3268378-head-of-information-security-deputy-ciso](https://www.wearedevelopers.com/jobs/ext/3268378-head-of-information-security-deputy-ciso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Head of Information Security (Deputy CISO) - **Company:** NewDay - **Location:** London, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Azure, Cyber Security, Disaster Recovery, PCI Data Security Standards, Software Vulnerability Management, Information Security Management System, Cloud Migration, Cyber Warfare - **Published:** September 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=9c22af7851e39ac2 ## About the Role You will be an established security leader who can combine strategic judgement with operational delivery. You will be comfortable leading broad, multidisciplinary teams while providing credible, concise advice to executives and Board-level stakeholders., * Significant experience leading a broad Information Security function within a regulated organisation, ideally financial services, consumer credit, cards, payments or FinTech. * Experience operating as a senior deputy to a CISO, or in an equivalent enterprise security leadership position. * Experience across security operations, governance, risk and compliance, architecture, engineering, third-party risk, assurance and operational resilience. * Strong practical knowledge of ISO/IEC 27001, PCI DSS, UK GDPR, the Data Protection Act 2018 and recognised control frameworks such as NIST. * A solid understanding of technology risk, risk appetite, control effectiveness and operational resilience. * Experience leading security incidents, audits, assurance programmes, regulatory engagement and senior-level reporting. * Excellent judgement, communication and influencing skills, with the confidence to make clear decisions and build alignment across complex stakeholder groups. Professional certifications such as CISSP, CISM, CRISC, CISA or ISO 27001 Lead Implementer or Auditor would be valuable. Experience of Microsoft Azure security, AI governance, cyber insurance, supplier assurance or major technology transformation would also be beneficial. ## Description * Lead, develop and bring together NewDay's Information Security teams, creating clear priorities, strong delivery and an accountable, high-performing culture. * Act as the CISO's delegate across executive, risk, governance, customer, supplier and regulatory forums. * Ensure the function has the right operating model, capabilities, technology and management information to protect NewDay and support future growth. Turn security strategy into action * Be responsible for the operational delivery of NewDay's security strategy, ensuring investment and activity are focused on reducing material cyber and technology risk. * Own the Information Security Management System and support continued alignment with ISO/IEC 27001:2022, the NIST Cybersecurity Framework and other recognised standards. * Maintain effective security policies, standards and controls, ensuring they are understood, embraced, evidenced and continuously improved. * Support compliance with PCI DSS, UK GDPR, the Data Protection Act 2018 and relevant FCA expectations. Strengthen cyber operations and resilience * Lead security monitoring, threat management, vulnerability management, incident response and cyber preparedness across NewDay's technology environment. * Maintain effective incident playbooks, escalation routes, exercises and lessons-learned processes. * Oversee the technology and security contribution to operational resilience, business continuity, disaster recovery and cyber recovery. * Drive improvements in security tooling, telemetry, automation and operational efficiency., * Own the technology and information risk framework, including risk appetite, assessment, quantification, treatment and reporting. * Ensure security risks and control effectiveness are clearly understood, challenged and transparent to the right decision-makers. * Embed security into major technology change, cloud adoption, platform engineering, digital delivery and supplier-led transformation. * Partner with technology and engineering leaders to make secure-by-design delivery practical, proportionate and commercially aligned. Lead assurance and emerging risk * Oversee third-party and supply-chain security risk across key suppliers, affiliates and strategic partners. * Coordinate internal and external assurance activity, including audits, independent assessments and regulatory engagement. * Ensure findings, control gaps and regulatory commitments have clear ownership and are delivered to the required standard. * Lead NewDay's approach to AI security and governance, establishing practical controls that enable safe and responsible adoption. ## Related Videos - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)