> Markdown version of [/jobs/ext/346428-director-of-information-security](https://www.wearedevelopers.com/jobs/ext/346428-director-of-information-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director of Information Security - **Company:** Cabot UK Holdco Limited - **Location:** London, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Technology Audit, PCI Data Security Standards, Cybercrime - **Published:** June 17, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=6325e690ee9f62fd ## About the Role Do you have experience in NIST standards?, * 12+ years experience with Information Security preferably in a leadership role with executive and board reporting responsibilities * Must have 10+ years experience across common industry security policy areas, including, but not limited to ISO, NIST, COSO, COBIT, PCI, FFIEC, SOX, SSAE16, and others * Minimum 7+ years of experience in Information Security with an emphasis on IT audit, IT risk management, and/or IT compliance * Ability to translate technical risk and vulnerability data into business risk, and effectively communicate potential impacts to the business * Professional certification in information security or compliance (for example, CISSP, CISM, or CISA) required or achievable What happens next? If you bring the strategic vision, governance expertise, and leadership required to guide our information security agenda, we invite you to apply and explore this opportunity with us. ## Description We are seeking an exceptional Director of Information Security to lead and shape our security strategy across the UK and Europe, operating as a key member of our global Information Security leadership team. This high-profile role serves as the primary strategic partner for all Information Security matters, ensuring robust cyber and information security controls while aligning regional execution with global objectives. Reporting directly to the Chief Information Security Officer, you will collaborate closely with executive, IT, and risk leaders to strengthen our security posture, drive enterprise-wide compliance, and manage cyber risk across a complex, multi-entity environment. This is a unique opportunity for a forward-thinking, executive-level security leader to influence direction at scale - balancing regulatory expectations, operational delivery, and evolving cyber threats while enabling the business to achieve its goals securely., * Lead the end-to-end information security service for Cabot Business Units, ensuring effective delivery from internal teams, shared services, and external partners. * Provide enterprise-level security leadership across a complex, multi-entity organisation operating in four countries. * Influence and align diverse regulatory and organisational environments, maintaining strong executive presence and collaborative partnerships with senior stakeholders. * Act as the senior Information Security representative, driving risk-based decision-making and maintaining accountability across business units. * Exercise independent authority during security incidents, making time-critical decisions with material business and regulatory impact. * Partner with Cabot executives and IT leaders to support fulfilment of InfoSec responsibilities under SMCR, SEAR, and equivalent regimes, ensuring: * Timely resolution of risk events, audit findings, and compliance actions. * Delivery of regulatory obligations, including mandatory learning and accurate completion of Fitness & Propriety documentation. * Lead and develop both direct and matrixed team members, fostering high performance and professional growth. * Monitor emerging cybersecurity insurance requirements and drive maturity improvements aligned with business needs. * Oversee information security compliance programmes covering ISO 27001, SOC 2, PCI DSS, SOX 404, GDPR, CCPA, and other global regulatory frameworks. * Advise executives and business leaders on security trends, risks, and technologies. * Collaborate with Enterprise Risk, Privacy, and Compliance teams to strengthen information risk management standards, tools, and processes. * Coordinate security risk metrics, KRIs, and measurements across all business units. * Work closely with cross-functional IT and business teams to ensure security controls are appropriately designed, implemented, and operating effectively. ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [GitOps keeps focus on apps, not on infrastructure](https://www.wearedevelopers.com/videos/182-gitops-keeps-focus-on-apps-not-on-infrastructure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [UK Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/326-uk-business-culture-and-etiquette) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Best Companies to Work For in The UK: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/186-best-companies-to-work-for-in-the-uk-top-25-companies-in-2023) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)