Requirements
The ideal candidate will have extensive experience in information or cyber security, ideally within a large or complex organization, with strong leadership experience across several security disciplines. Proven knowledge of security operations, incident response, security architecture, cyber risk, regulatory compliance, and recognized security frameworks is required. Familiarity with cloud security, data protection, and third-party risk is also essential. Candidates should be confident communicators and decisive in managing security incidents, balancing strong security controls with operational and commercial needs.
Description
The Director of Information Security is responsible for protecting the organisation's technology, systems and information assets across a complex, multi-entity operating environment.The role combines strategic leadership with operational accountability. It will shape security priorities, strengthen resilience and ensure cyber risks are managed in a practical way that supports the organisation's objectives.Main ResponsibilitiesSet the organisation's cyber security strategy and priorities.Lead security operations, threat monitoring and incident management.Maintain appropriate security policies, controls and governance.Oversee cyber risk assessments, audits and compliance activities.Guide secure design across cloud, infrastructure, networks, applications and endpoints.Introduce security requirements early in technology projects and procurement.Direct vulnerability management and security testing programmes.Strengthen cyber recovery and crisis-response arrangements.Manage specialist security suppliers and outsourced services.Provide senior leadership with clear reporting on cyber risks and incidents.Coordinate security activities across different business areas.Build and develop an effective information security team.Promote a practical security culture that enables responsible innovation.Candidate ProfileExtensive experience in information or cyber security, ideally within a large or complex organisation.Strong leadership experience across several security disciplines.Proven knowledge of security operations, incident response and security architecture.Experience with cyber risk, regulatory compliance and recognised security frameworks.Familiarity with cloud security, data protection and third-party risk.Experience managing external security providers is advantageous.Confident communicating with executives, technical teams and business stakeholders.Calm and decisive when managing significant security incidents.Able to balance strong security controls with operational and commercial needs.QualificationsBachelor's degree in a relevant field.Master's degree is advantageous.Professional certifications such as CISSP, CISM or equivalent are preferred.Working ArrangementsThis is a full-time position. Further details about the organisation, location and reporting structure will be provided to shortlisted candidates.