Information security lead

Company: BP
Apply for the Information security lead
Location: London
Job Description:

Overview

In this role you drive security delivery to enable fast business value within bp’s Supply, Trading and Shipping portfolio. You will lead technical security initiatives, shape secure architectures, and partner with cross-functional teams to reduce cyber risk. You’ll work to maintain a strong cyber posture while supporting bp’s transition to a broader energy company. You’ll engage with stakeholders to educate and advocate for security, guiding product development and incident response with impact-driven, calm leadership.

Pay / Benefits

  • flexible working options
  • generous paid parental leave
  • excellent retirement benefits
  • disability accommodations

Responsibilities

  • Act as primary point of contact for Digital Security inquiries within the ST&S portfolio and influence positive security-driven change.
  • Provide technical security expertise and implement security operating processes aligned to standards across value streams.
  • Improve cyber hygiene through architecture and process design, prioritising cyber and operational safety.
  • Monitor digital domains and collaborate on risk identification, assessment and management.
  • Develop and implement security measures to protect data and systems; craft a secure environment.
  • Lead incident response in partnership with customers to minimise impact and guide recovery.
  • Champion security awareness and advocate for security best practices across the organisation.
  • Provide strategic security insights to product teams to embed security in development and operations.
  • Coordinate remediation of findings from vulnerability scans, supplier assurance, and compliance reviews.
  • Support Delivery teams to maintain high levels of cyber hygiene and secure external partnerships.

Key requirements

  • Degree in a related field (preferably BSc in Information Security)
  • CISM or CISSP (or working towards)
  • Knowledge of ISO 27001/2, NIST, CIS frameworks
  • Proven experience in information security roles with leadership experience
  • Strong influencing and communication skills for technical and non-technical audiences
  • Deep technical knowledge and experience delivering security solutions and advisory
  • Track record balancing security with business operations
  • Experience with digital ecosystems and multi-partner environments
  • Understanding of risk management, governance, and compliance
  • Excellent project management and ability to handle multiple projects
  • Adaptability to shifting priorities and timelines
  • Ability to use data and insights for decision-making
  • Strong influencing skills
  • Communication to diverse audiences
  • Strategic thinking and collaboration
  • Information Security
  • Information Assurance
  • Incident Management

…

Posted: October 10th, 2026