Head of Information Security
Core
Rebuild security, privacy, and resilience capabilities from the ground up and lead the Business Continuity, Disaster Recovery, and Incident Response programme.
Role type
Head of Information Security (Strategic IC)
Builds
Security governance framework, incident response playbooks, DR/BC strategies, and cloud security posture.
Domain
E-commerce, Print & Merchandise, Cloud Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Information security strategy, security governance, incident response, business continuity, disaster recovery, GDPR compliance, cloud security, vendor risk management, data privacy, executive reporting
Preferred skills
AWS experience, UK Cyber Essentials, SOC 2 readiness, physical continuity planning
Technologies
Security Hub, Wiz, AWS
Responsibilities
Define and own information security strategy aligned with business objectives; Establish security governance framework including policies and risk management; Chair the Security Governance Forum and run board-level reporting; Build a security roadmap prioritizing compliance, privacy, AppSec, and resilience; Own and continuously improve the security incident response plan and act as incident commander; Create and maintain Business Impact Analysis (BIA) and risk assessments; Design and own DR strategy and data recovery strategy; Partner with Legal to own the GDPR programme end-to-end; Establish and run the vendor risk management programme; Drive cloud security posture management and foundational controls.
Seniority
Senior, hands-on IC with executive reporting