Overview
In this role you lead and mature Vitality’s cyber security operations, reporting to the CISO and guiding cross-functional teams to protect member data. You’ll manage the CSIRT, develop response playbooks, and drive continuous improvement of security controls and technology roadmaps. The role combines hands-on security with strategic oversight, ensuring compliance with ISMS frameworks and regulatory requirements. This is a values-driven, collaborative opportunity to shape security capabilities at scale.
Pay / Benefits
- Bonus scheme
- Pension up to 12% with 6% employer match
- Vitality health insurance and rewards
- Life assurance 4x salary
Responsibilities
- Lead the Cyber Security Operations team and a service delivery manager
- Conduct cyber security maturity assessments and continuously improve controls
- Perform cyber risk assessments and create reporting metrics for Senior Management
- Lead cyber security incidents, coordinate investigations, and mature detection/response capabilities
- Engage with internal stakeholders, vendors, forensic partners, and regulatory bodies
- Threat hunting and monitoring for emerging threats
- Ensure compliance with ISMS, regulatory frameworks (ISO27001, GDPR, NIST, Cyber Essentials, ITIL)
- Oversee penetration testing and vulnerability management governance
- Deliver security initiatives aligned with InfoSec and Enterprise Risk Management
- Advise on information and cyber security best practices across Vitality
- Provide training and awareness sessions
Key requirements
- Degree or professional security qualifications (e.g., MSc, CISSP, CISM, CISA) or equivalent
- Minimum 5 years’ experience in Cyber Security
- Excellent verbal and written communication; ability to convey technical concepts to non-technical audiences
- Hands-on experience configuring security tools
- Experience designing, implementing and managing information security initiatives
- Solid understanding of frameworks (ISO27001/2, PCI DSS, NIST) and data protection/compliance (GDPR, FCA, ICO, PRA)
- Strong communication skills
- Leadership and people management
- Stakeholder engagement
- Security operations and incident response
- Threat detection and monitoring
- Penetration testing and vulnerability management governance
…
