Head of Security (CISO)

Company: ClearCourse
Apply for the Head of Security (CISO)
Location: London
Job Description:

Overview

As Head of Security, you will lead the group-wide security strategy and governance across a multi-portfolio tech environment. You’ll report to the CTO with a dotted line to the Board, shaping risk, compliance, and incident response at scale. You drive PCI-DSS adherence for payment platforms and oversee the GRC program to protect customers and enable growth. Your leadership ensures secure development practices and effective stakeholder communications during incidents. This is a pivotal executive role shaping security culture and delivery across acquisitions and evolving platforms.

Pay / Benefits

  • Competitive salary + benefits
  • 25 days holiday + your birthday off
  • Private medical insurance (Bupa) & health cash plan
  • Life assurance & income protection
  • Enhanced parental leave & family wellbeing support
  • Perkbox discounts & perks`,`Generous pension contributions’,’Hybrid working model

Responsibilities

  • Define and implement the Group’s security strategy, policies, and governance framework
  • Provide Board-level reporting on security posture, risks, and compliance
  • Oversee security operations including threat detection, incident response, and remediation
  • Act as executive lead during security incidents and manage external communications
  • Own PCI-DSS compliance across ClearAccept and ClearDebit payment platforms
  • Lead GRC function including ISO 27001, Cyber Essentials, PCI-DSS, and data protection obligations
  • Manage relationships with auditors, regulators, cyber insurers, and certification bodies
  • Lead security assessments and integration activities for acquisitions and align with Group standards
  • Partner with Platform Engineering to embed security in development lifecycles without slowing delivery
  • Lead and develop the GRC function to foster a proactive security culture

Key requirements

  • Previous CISO-level experience in a multi-product or multi-entity organization
  • Hands-on PCI-DSS compliance programmes and QSA assessments
  • Proven expertise in enterprise-wide GRC frameworks and risk registers
  • Experience integrating security functions post-M&A
  • Strong DevSecOps understanding and embedding security into engineering practices
  • Experience leading major security incidents and external communications
  • Ability to influence at Board and executive level
  • Strong leadership in building high-performing security teams
  • leadership
  • stakeholder management
  • communication
  • PCI-DSS
  • GRC (ISO 27001, data protection)
  • threat detection and incident response

Posted: September 14th, 2026