At a Glance
- Tasks: Lead and shape the organisation's security strategy across IT, Cyber, and Information Security.
- Company: Join Emeria, a leader in promoting diversity and inclusion in the workplace.
- Benefits: Enjoy competitive salaries, exclusive discounts, and comprehensive training support.
- Why this job: Be part of a dynamic environment where your expertise can make a real impact.
- Qualifications: Five years in cyber security leadership with a focus on Microsoft and Azure environments.
- Other info: Diversity is key; we welcome applications from all backgrounds.
The predicted salary is between 48000 - 84000 £ per year.
Location: London
Hours: 35 hours per week Monday to Friday
We are looking for a highly experienced and strategic Head of Information Security to lead and shape the organisation's security posture across IT Security, Cyber Security, and Information Security functions. You have a deep understanding of technical and governance-based security practices, with the ability to balance operational resilience, risk management, and business enablement. In this role which reports to our Chief Information Officer, you will drive the overall security strategy, ensuring that security controls, policies, and technologies effectively protect the organisation's assets, infrastructure, and data. You will work closely with senior leadership, providing expert guidance on threat mitigation and security best practices. If you thrive in a dynamic environment and have a passion for building and evolving enterprise security programs, we want to hear from you.
Main Responsibilities
- Define, implement, and oversee technical security controls across the organisation's Microsoft and Azure-based infrastructure, ensuring robust protection against cyber threats.
- Lead vulnerability management and remediation efforts, ensuring timely identification and mitigation of risks across cloud and on-premises environments.
- Enhance and manage security monitoring, detection, and response capabilities using Microsoft security tools such as Microsoft Defender, Sentinel, and Entra ID security features.
- Drive the security architecture and engineering strategy, ensuring secure design principles are embedded across cloud and hybrid infrastructure.
- Oversee identity and access management (IAM), enforcing least privilege principles and securing authentication processes across Microsoft platforms.
- Coordinate and lead incident response activities, working with internal teams and third-party providers to contain and remediate security breaches.
- Ensure endpoint security for end-user devices, virtual desktops, and cloud-based services, leveraging Microsoft Defender for Endpoint and other relevant tools.
- Support M&A security assessments and integrations, ensuring due diligence and risk mitigation for acquired environments.
- Maintain an understanding of evolving cyber threats and proactively adapt security measures to stay ahead of emerging risks.
- Provide oversight of governance and compliance requirements, ensuring security policies and regulatory obligations (e.g., ISO 27001, NIST, CIS benchmarks) are met.
About You
- At least five years' experience in cyber security leadership roles, with a strong focus on technical security operations and architecture.
- Proven track record of securing Microsoft and Azure-based environments, including cloud, hybrid, and on-premises infrastructure.
- Hands-on experience in managing and responding to security incidents, threat hunting, and vulnerability remediation.
- Strong background in implementing and overseeing security monitoring and detection capabilities using SIEM, EDR, and XDR solutions.
- Experience leading security initiatives in complex enterprise environments, including M&A integrations and security due diligence.
- Familiarity with security frameworks and compliance standards such as ISO 27001, NIST, CIS benchmarks, and Microsoft Security Best Practices.
- Strong stakeholder engagement experience, with the ability to communicate technical security risks and strategies to senior leadership and technical teams.
Technical Skills
- Relevant certifications such as CISSP, CISM, Security Blue Team, Microsoft Certified: Azure Security Engineer Associate AZ-500, Microsoft Certified: Security Operations Analyst Associate SC-200, and Microsoft Certified: Cybersecurity Architect Expert SC-100 are highly desirable.
- Expertise in Microsoft security solutions, including Microsoft Defender (Endpoint, Identity, Cloud), Microsoft Sentinel (SIEM), Entra ID Security Features, and Microsoft Purview.
- Strong knowledge of Azure security controls, including Azure Firewall, Key Vault, Conditional Access, and Azure Network Security.
- Deep understanding of identity and access management (IAM), MFA, and privileged access security in Microsoft environments.
- Hands-on experience with vulnerability management tools, security patching, and hardening of cloud and on-premises systems.
- Proficiency in security automation, scripting, and Infrastructure-as-Code (IaC) using PowerShell, Azure Policy, Azure Automation Accounts, and Logic App workflows.
- Experience with network security principles, including zero-trust architecture, segmentation, firewalls, and secure remote access solutions.
- Strong understanding of cyber threat intelligence, MITRE ATT&CK framework, and advanced threat detection methodologies.
The Benefits
Our customers deserve the best and the same applies to our people. We'll support you with all of the technology, training and support that you need to do your job well. We offer competitive salaries and a range of benefit packages. In addition to the core benefits, we also offer a range of exclusive discounts on extra benefits to help you and your family make the most of your money, safeguard your future and look after your health.
Diversity
We're committed to promoting diversity at Emeria and recruit on merit. We will consider applications from job share applicants.
Ready to Apply?
Click the below apply button to start your application for this role. We will ask you to upload your CV and answer a few questions. If you meet the criteria for the role we'll be in touch to arrange a short telephone interview and our shortlist of candidates will be invited to attend interviews with the hiring manager and up to three other key stakeholders.
Contact Detail:
Emeria UK Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Head of Information Security
✨Tip Number 1
Network with professionals in the cybersecurity field, especially those who have experience with Microsoft and Azure environments. Attend industry events or webinars to connect with potential colleagues and learn about the latest trends and challenges in information security.
✨Tip Number 2
Stay updated on the latest security threats and best practices by following relevant blogs, podcasts, and forums. This knowledge will not only help you in interviews but also demonstrate your commitment to staying ahead in the rapidly evolving cybersecurity landscape.
✨Tip Number 3
Consider obtaining additional certifications that are highly regarded in the industry, such as CISSP or Microsoft Certified: Cybersecurity Architect Expert. These credentials can enhance your profile and show your dedication to professional development.
✨Tip Number 4
Prepare for the interview by practising how to communicate complex security concepts clearly and effectively. Be ready to discuss your previous experiences in managing security incidents and leading teams, as well as how you would approach the specific challenges mentioned in the job description.
We think you need these skills to ace Head of Information Security
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights your experience in cyber security leadership, particularly focusing on technical security operations and architecture. Emphasise your familiarity with Microsoft and Azure environments, as well as any relevant certifications.
Craft a Compelling Cover Letter: Write a cover letter that showcases your passion for information security and your strategic vision for enhancing security posture. Mention specific experiences where you've successfully implemented security measures or led initiatives in complex environments.
Highlight Relevant Skills: In your application, clearly outline your technical skills related to Microsoft security solutions, vulnerability management, and incident response. Use specific examples to demonstrate your hands-on experience with tools like Microsoft Defender and Sentinel.
Showcase Stakeholder Engagement: Include examples of how you've effectively communicated technical security risks and strategies to senior leadership. This will demonstrate your ability to engage with stakeholders and lead security initiatives across the organisation.
How to prepare for a job interview at Emeria UK
✨Showcase Your Technical Expertise
As a Head of Information Security, it's crucial to demonstrate your deep understanding of technical security practices. Be prepared to discuss specific experiences with Microsoft and Azure security solutions, and how you've implemented security controls in previous roles.
✨Communicate Clearly with Stakeholders
You will need to engage with senior leadership and technical teams. Practice explaining complex security concepts in simple terms, ensuring that everyone understands the risks and strategies involved. This will showcase your ability to bridge the gap between technical and non-technical audiences.
✨Prepare for Scenario-Based Questions
Expect questions that assess your problem-solving skills in real-world scenarios. Think about past incidents you've managed, how you approached them, and what the outcomes were. This will help illustrate your hands-on experience and strategic thinking.
✨Stay Updated on Cyber Threats
Demonstrating knowledge of current cyber threats and trends is essential. Be ready to discuss recent developments in the cybersecurity landscape and how they might impact the organisation. This shows your proactive approach to security and your commitment to staying ahead of emerging risks.