Description
The Role Leadthe organisation's cybersecurity and information security programme, ensuringthe confidentiality, integrity, and availability of information assets across a regulated financial services environment. Define and executesecurity strategy, own and manage cyber risk within Board-approved appetite,and maintain regulatory compliance within a cloud-native payments and storedvalue facility (SVF) operation. The role advises and recommends on security risk, with independent authority to escalate unresolved risk to the CTO, CEO, and Board Risk Committee.Operates within an approved annual security budget; spend proposals requirecost-benefit justification and are prioritised within the allocated envelope. Key Responsibilities Security Strategy & Governance Define and maintain a multi-year cybersecurity strategy aligned with business growth, risk appetite, and regulatoryobligations. Establish and maintain the information security policy framework, reviewed at least annually. Maintain the cyber risk register and own the security maturity roadmap against a recognised control framework (NIST CSF, CIS Controls,or ISO 27001). Own the security risk acceptance and exception register. P rov ide secu rity leadership and advisory to executive management and regulatory stakeholders. Threat & Vulnerability Management Direct the enterprise vulnerability management programme, including scanning, risk-based prioritisation, and remediationSLA enforcement. Oversee the penetration testing programme and ensure findings are remediated and retested within defined timelines. Maintain threat intelligence capability relevant to financial services and payments, and translate it into detection and controlimprovements. Security Operations Oversee security monitoring, detection, and response capabilities including SIEM, EDR/XDR, and SOC operations(internal or MSSP-managed). Own incident response endto end: maintain and test playbooks, run tabletop exercises, lead containment and recovery, and coordinate regulatory notification within applicable deadlines. Manage identity and access governance including RBAC design, privileged access management, joiner/mover/leaver controls,and periodic access recertification. Define and enforce data loss prevention and data classification standards across all platforms.