> Markdown version of [/jobs/ext/36251-head-of-information-security](https://www.wearedevelopers.com/jobs/ext/36251-head-of-information-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Head of Information Security - **Company:** Ai-driven - **Location:** London, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cloud Computing, Cyber Security, Customer Data Management, Data Security, Intrusion Detection and Prevention, PCI Data Security Standards, Security Information and Event Management, Software Vulnerability Management, Data Classification, Devsecops - **Published:** May 31, 2026 - **Apply:** https://www.apply4u.co.uk/jobs/x/37789587/ ## About the Role Security certifications such as CISSP, CISM, or equivalent. A strong working knowledge of cyber and information security standards such as ISO 27001, NIST, CIS, PCI DSS, and GDPR. Experience leading cyber assurance or risk programmes at a strategic level. Strong technical grounding across key security domains: network, cloud, endpoint, application, and data security. Experience managing or working with vulnerability management tools, SIEM/SOC environments, and incident response processes. Excellent communication and stakeholder management skills, with the ability to influence at all levels of the organisation. Sound judgement, strong written skills, and confidence operating in ambiguity. ## Description Define, implement, and evolve information security strategy in line with business objectives, regulatory obligations, and risk appetite. Lead the development and maintenance of Information Security policies, standards, and controls, ensuring alignment with frameworks such as ISO27001, SOC2, and NIST CSF. Lead compliance efforts across GDPR, PCI DSS, and other applicable regulations. Embed secure-by-design principles and DevSecOps practices across engineering and delivery teams. Use AI and automation to improve detection, prevention, and response. Lead incident response and threat modelling with a practical, engineering-first mindset. Own and manage the Information Security Risk Register; ensure risks are assessed, documented, and mitigated effectively. Oversee third-party risk management, including supplier due diligence, onboarding, and continuous monitoring. Oversee operational security activities, including threat detection, vulnerability management, and incident response. Develop and maintain incident response playbooks and lead investigations where required. Collaborate with SOC and Systems teams to strengthen detection, response, and automation capabilities. Define and maintain the information classification and handling standard. Ensure security controls for customer data, employee data, and payment data are implemented and monitored. Support client assurance and audit activities, providing evidence of our security posture. Mentor and develop members of the Information Security team. ## Related Videos - [The New AI Security Stack: Observe, Detect, Protect](https://www.wearedevelopers.com/videos/100302-the-new-ai-security-stack-observe-detect-protect) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) ## Related Articles - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer)