Head of Information Security
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Define, implement, and evolve information security strategy in line with business objectives, regulatory obligations, and risk appetite. Lead the development and maintenance of Information Security policies, standards, and controls, ensuring alignment with frameworks such as ISO27001, SOC2, and NIST CSF. Lead compliance efforts across GDPR, PCI DSS, and other applicable regulations. Embed secure-by-design principles and DevSecOps practices across engineering and delivery teams. Use AI and automation to improve detection, prevention, and response. Lead incident response and threat modelling with a practical, engineering-first mindset. Own and manage the Information Security Risk Register; ensure risks are assessed, documented, and mitigated effectively. Oversee third-party risk management, including supplier due diligence, onboarding, and continuous monitoring. Oversee operational security activities, including threat detection, vulnerability management, and incident response. Develop and maintain incident response playbooks and lead investigations where required. Collaborate with SOC and Systems teams to strengthen detection, response, and automation capabilities. Define and maintain the information classification and handling standard. Ensure security controls for customer data, employee data, and payment data are implemented and monitored. Support client assurance and audit activities, providing evidence of our security posture. Mentor and develop members of the Information Security team.
Requirements
Security certifications such as CISSP, CISM, or equivalent. A strong working knowledge of cyber and information security standards such as ISO 27001, NIST, CIS, PCI DSS, and GDPR. Experience leading cyber assurance or risk programmes at a strategic level. Strong technical grounding across key security domains: network, cloud, endpoint, application, and data security. Experience managing or working with vulnerability management tools, SIEM/SOC environments, and incident response processes. Excellent communication and stakeholder management skills, with the ability to influence at all levels of the organisation. Sound judgement, strong written skills, and confidence operating in ambiguity.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on apply4u.co.ukGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production
Understanding and Mitigating Common Web Vulnerabilities
Stephan Gillich - Bringing AI Everywhere