Head of Information Security

Ai-driven
London, UK
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Cloud Computing Cyber Security Customer Data Management Data Security Intrusion Detection and Prevention PCI Data Security Standards Security Information and Event Management Software Vulnerability Management Data Classification Devsecops

Job description

Define, implement, and evolve information security strategy in line with business objectives, regulatory obligations, and risk appetite. Lead the development and maintenance of Information Security policies, standards, and controls, ensuring alignment with frameworks such as ISO27001, SOC2, and NIST CSF. Lead compliance efforts across GDPR, PCI DSS, and other applicable regulations. Embed secure-by-design principles and DevSecOps practices across engineering and delivery teams. Use AI and automation to improve detection, prevention, and response. Lead incident response and threat modelling with a practical, engineering-first mindset. Own and manage the Information Security Risk Register; ensure risks are assessed, documented, and mitigated effectively. Oversee third-party risk management, including supplier due diligence, onboarding, and continuous monitoring. Oversee operational security activities, including threat detection, vulnerability management, and incident response. Develop and maintain incident response playbooks and lead investigations where required. Collaborate with SOC and Systems teams to strengthen detection, response, and automation capabilities. Define and maintain the information classification and handling standard. Ensure security controls for customer data, employee data, and payment data are implemented and monitored. Support client assurance and audit activities, providing evidence of our security posture. Mentor and develop members of the Information Security team.

Requirements

Security certifications such as CISSP, CISM, or equivalent. A strong working knowledge of cyber and information security standards such as ISO 27001, NIST, CIS, PCI DSS, and GDPR. Experience leading cyber assurance or risk programmes at a strategic level. Strong technical grounding across key security domains: network, cloud, endpoint, application, and data security. Experience managing or working with vulnerability management tools, SIEM/SOC environments, and incident response processes. Excellent communication and stakeholder management skills, with the ability to influence at all levels of the organisation. Sound judgement, strong written skills, and confidence operating in ambiguity.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on apply4u.co.uk

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

4:04 min

Embedding data security and applied ethics into developer education

Daniel Tao +3 · WWC 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

2:12 min

Navigating technical clarity as a global black belt

Chris Heilmann +2 · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all