Overview
As Head of Security, you will lead the group-wide security strategy and governance across a multi-portfolio tech environment. You’ll report to the CTO with a dotted line to the Board, shaping risk, compliance, and incident response at scale. You drive PCI-DSS adherence for payment platforms and oversee the GRC program to protect customers and enable growth. Your leadership ensures secure development practices and effective stakeholder communications during incidents. This is a pivotal executive role shaping security culture and delivery across acquisitions and evolving platforms.
Pay / Benefits
- Competitive salary + benefits
- 25 days holiday + your birthday off
- Private medical insurance (Bupa) & health cash plan
- Life assurance & income protection
- Enhanced parental leave & family wellbeing support
- Perkbox discounts & perks`,`Generous pension contributions’,’Hybrid working model
Responsibilities
- Define and implement the Group’s security strategy, policies, and governance framework
- Provide Board-level reporting on security posture, risks, and compliance
- Oversee security operations including threat detection, incident response, and remediation
- Act as executive lead during security incidents and manage external communications
- Own PCI-DSS compliance across ClearAccept and ClearDebit payment platforms
- Lead GRC function including ISO 27001, Cyber Essentials, PCI-DSS, and data protection obligations
- Manage relationships with auditors, regulators, cyber insurers, and certification bodies
- Lead security assessments and integration activities for acquisitions and align with Group standards
- Partner with Platform Engineering to embed security in development lifecycles without slowing delivery
- Lead and develop the GRC function to foster a proactive security culture
Key requirements
- Previous CISO-level experience in a multi-product or multi-entity organization
- Hands-on PCI-DSS compliance programmes and QSA assessments
- Proven expertise in enterprise-wide GRC frameworks and risk registers
- Experience integrating security functions post-M&A
- Strong DevSecOps understanding and embedding security into engineering practices
- Experience leading major security incidents and external communications
- Ability to influence at Board and executive level
- Strong leadership in building high-performing security teams
- leadership
- stakeholder management
- communication
- PCI-DSS
- GRC (ISO 27001, data protection)
- threat detection and incident response
…
