Overview
In this senior role you will set and evolve the organisation’s IT security direction, owning governance, risk, and assurance across a largely outsourced environment. You will shape the security strategy and improvement roadmap, hold technology partners to account, and translate technical risk into business impact for senior stakeholders. You’ll partner with IT, business, and external suppliers to embed secure decision-making and drive delivery of security improvements. This is a proactive, ownership-driven leadership role with a clear impact on overall security posture and organisational resilience.
Responsibilities
- Develop and evolve the organisation’s IT security strategy aligned with business objectives
- Own IT security governance, risk and assurance functions
- Create and improve security policies, standards and governance processes
- Define the security roadmap, prioritise improvements and drive changes
- Provide security leadership across programmes and organisational change
- Oversee key third-party technology and security suppliers
- Hold suppliers accountable for security delivery and remediation actions
- Challenge suppliers and stakeholders when security standards are not met
- Maintain oversight of risks, vulnerabilities, incidents and remediation via third parties
- Ensure controls, reporting and assurance across outsourced technology environment
- Offer clear security advice to senior stakeholders and translate risks into business impact
- Collaborate with IT, business and external partners to embed security in decision-making
- Identify opportunities to strengthen overall security posture and ensure improvements are delivered
Key requirements
- Significant experience in information security, cyber security or IT security management
- Experience developing or delivering an organisation-wide security strategy
- Strong governance, risk management, assurance and policy development experience
- Experience operating in outsourced or supplier-led technology environments
- Strong third-party supplier and vendor management experience with accountability for delivery
- Experience delivering security improvement, transformation or change roadmaps
- Broad understanding of cyber security controls, vulnerabilities, incidents and remediation
- Ability to assess security risk and translate technical issues into business risks
- Strong stakeholder management and senior-influencer capabilities
- Experience working across complex organisations with multiple stakeholders
- Proactive ownership mindset and drive to delivery
- Stakeholder influence and relationship management
- Proactivity and accountability
- Critical thinking and challenge culture
- Security governance
- Risk management
- Policy development
…
