Chief Information Security Officer

Company: NTT DATA
Apply for the Chief Information Security Officer
Location: London
Job Description:

Overview

In this senior role, you will act as the primary security leader for a major client account, guiding governance, assurance, and strategic security across the service lifecycle. You’ll advise executives, align security with business and contractual goals, and drive improvements in security posture and resilience. You will influence senior stakeholders and ensure security requirements are embedded across delivery teams. This is a high-impact, cross-functional role that shapes security strategy and risk management for a large, regulated client environment.

Pay / Benefits

  • tailored benefits
  • flexible work options
  • Learning and Development opportunities
  • opportunity to grow with global client base
  • inclusive and diverse workplace

Responsibilities

  • Represent the account as the senior security voice across governance, delivery, and transformation forums
  • Provide strategic security guidance to client executives and delivery teams
  • Maintain and improve the Account Security Management Plan and governance structures
  • Oversee security controls, assurance activities, and remediation plans
  • Drive risk-based decision making and escalation for significant security issues
  • Ensure security requirements are embedded in service delivery and change initiatives
  • Support internal and external audits and client assurance activities
  • Provide security reporting and metrics to stakeholders
  • Promote a culture of security and continual improvement across the account
  • Challenge decisions that introduce unacceptable security risk
  • Collaborate with client security, architecture, and delivery teams to apply security-by-design principles
  • Advise on architecture, cloud, and transformation initiatives from resilience and risk perspectives

Key requirements

  • 7+ years in senior information security leadership (e.g., Security Director, CISO, or vCISO)
  • Proven strategic security leadership experience in large, regulated environments
  • Experience advising executive leadership and client senior stakeholders
  • Experience developing and leading governance, risk management, and assurance programmes
  • Experience owning Security Management Plans and governance/reporting frameworks
  • Experience leading security assurance activities and remediation delivery
  • Strong background in enterprise security architecture and security-by-design
  • Experience assessing technology, cloud, infrastructure, and transformation from security and risk perspectives
  • Ability to influence senior stakeholders without direct authority
  • Knowledge of regulatory, contractual, and third-party risk management requirements
  • Strong communication, negotiation, and stakeholder management skills
  • CISSP, CISM, CRISC, CCISO or equivalent; UK Cyber Security Council accreditation; CPD evidence
  • stakeholder management
  • negotiation
  • communication
  • security governance, risk management and assurance
  • enterprise security architecture
  • security-by-design

…

Posted: September 14th, 2026