Head of Information Security - #2151016
Oakley Recruitment Limited
Oakley Recruitment is working in partnership with an expanding organisation based in Birmingham. This is an excellent opportunity to join the team as a Head of Information Security on a full-time, permanent basis.
Culture and Environment
This is a growing, technology-led organisation operating across the UK and internationally. As the business continues to develop, information security will play an increasingly important role in supporting its future growth.
This is an exciting opportunity to join at a pivotal stage. Rather than stepping into a large, established security function, you will have the opportunity to shape how information security operates across the organisation.
Working closely with the CEO and senior leadership team, you will have genuine exposure at the highest level of the business, with the autonomy to develop the security strategy, strengthen governance and help shape the future security operating model.
For someone ambitious about progressing their career, there is a clear opportunity to grow with the organisation and develop towards becoming its future CISO.
Personality
We are looking for someone who combines strong information and cyber security knowledge with the ambition and confidence to step into a broader leadership position.
You will be commercially minded, pragmatic and comfortable constructively challenging stakeholders. You will be able to take complex technical risks and communicate them clearly to both technical and non-technical audiences.
You will enjoy taking ownership, identifying where improvements can be made and building something for the future rather than simply maintaining what is already in place.
You do not need to be an established CISO. This opportunity is about finding someone with strong technical and security foundations, leadership capability and the potential to develop into a senior executive security leader as the organisation grows.
Package and Benefits
- Additional benefits package
- Travel as required
- Newly created senior leadership position
- Direct exposure to the CEO and senior leadership team
- Genuine autonomy to shape the organisation’s security strategy and framework
- Clear opportunity to develop into the organisation’s future CISO
Job Role
- Leading and continually developing an ISO 27001-aligned Information Security Management System (ISMS)
- Maintaining the security risk register and ensuring appropriate controls and mitigation plans are in place
- Providing clear security reporting, insight and assurance to the CEO and senior leadership team
- Overseeing security across cloud infrastructure, SaaS applications, APIs, identity, endpoints and data
- Managing vulnerability management, penetration testing, monitoring and remediation activity
- Working alongside technology and development teams to embed secure-by-design and DevSecOps principles
- Coordinating specialist external security providers where required
- Developing security awareness and supporting a strong security culture across the organisation
- Monitoring emerging cyber threats, regulatory requirements and technology risks, including those associated with AI
- Continuing to develop the security function and operating model as the organisation grows
- Building the capability and executive-level experience required to progress towards future CISO responsibility
Skills and Experience
- Demonstrating strong experience within information or cyber security, ideally at management or senior management level
- Experience developing or contributing to security strategies, frameworks, policies and risk-based programmes
- Working knowledge and experience of ISO 27001 and ISMS environments
- Strong understanding of cloud, SaaS, identity, APIs, application security and data protection
- Experience overseeing vulnerability management, penetration testing and incident response
- Ability to translate technical security risks into clear commercial language for senior stakeholders
- Experience assessing third-party and supply-chain security risks
- Strong knowledge of UK data protection and cyber security requirements
- Confident communication skills with the ability to influence and constructively challenge stakeholders
- Leadership capability with the ambition to continue developing at a senior level
- Experience within technology, SaaS, automotive, financial services, regulated or data-sensitive environments would be advantageous
- Exposure to Cyber Essentials Plus, SOC 2, NIST, CIS Controls, OWASP, AWS, Azure or Google Cloud would be beneficial
Please Note: We do not contact or write to unsuccessful candidates. If we have not contacted you within 48 hours of your application, you should presume that your application was unsuccessful. By applying for this vacancy, you are permitting Oakley Recruitment to contact you and retain your details. In compliance with the regulations (April 2004) in place under the Employment Agencies Act, Oakley Recruitment will require proof of identification. A copy of your passport, birth certificate and NI number will be required as part of your interview process.
How to apply
To apply for this job you need to authorize on our website. If you don't have an account yet, please register.
Post a resumeSimilar jobs
iOS Engineer
Maintenance Manager
Temporary Part Time Customer Service Representative-Birmingham