Head of Information Security @ CFC (Basé à London)
Head of Information Security @ CFC (Basé à London)

Head of Information Security @ CFC (Basé à London)

Full-Time 72000 - 108000 £ / year (est.) No home office possible
Go Premium
G

At a Glance

  • Tasks: Lead and manage key security pillars, focusing on risk management and data protection.
  • Company: CFC offers innovative commercial insurance products tailored for modern risks.
  • Benefits: Enjoy a permanent full-time role in London with opportunities for growth and development.
  • Why this job: Join a passionate team that values improvement, diversity, and fun in the workplace.
  • Qualifications: Proven leadership in information security with knowledge of global regulatory frameworks required.
  • Other info: Work closely with the Group CISO and contribute to shaping security strategy.

The predicted salary is between 72000 - 108000 £ per year.

CFCCFC’s broad range of commercial insurance products are purpose-built for today’s risks, and we aim to give our customers everything they need in one, easy-to-understand policy. We specialize in cyber insurance, professional liability, and more.

As Head of Information Security, you will report directly into the Group CISO, and be responsible for leading and managing key pillars of our security programme, with a primary focus on Third-Party Security Risk Management, Data Loss Prevention (DLP), Policy Governance, Security Training & Awareness, and Identity & Access Management (IAM). You will work closely with the Group CISO to ensure high standards in your areas of responsibility and global adherence to security practices. The ideal candidate will have deep knowledge of regulatory frameworks such as NYDFS Cybersecurity Regulation, GDPR, and other European and Australian data protection laws, bringing a proactive, risk-based approach to security governance and operations.

This role involves contributing to security strategy, budgeting, and cross-functional planning as a member of the CISO’s leadership team. Key responsibilities include:

  • Managing Cyber Incidents and supporting global coordination of these events.
  • Managing vendor relationships, including renewals, negotiations, and contract updates.
  • Collaborating with legal, procurement, and operational resilience teams to support Third Party Risk Management and ensure proper due diligence and SLAs.
  • Leading third-party vendor assessments, onboarding, and continuous monitoring.
  • Implementing risk-based frameworks and tools to evaluate and monitor vendor security posture.
  • Maintaining and updating security policies, standards, and procedures to reflect evolving threats and regulations.
  • Overseeing DLP strategies to prevent unauthorized data access or transfer, and coordinating incident response activities.
  • Developing and implementing a company-wide security awareness and training program, tailored to emerging risks and regulatory obligations.
  • Directing IAM strategy and operations, including provisioning, access reviews, and privileged access management.
  • Partnering with IT to embed IAM best practices into enterprise systems.
  • Ensuring security controls meet compliance under NYDFS, GDPR, and other global regulations.

The ideal candidate will have proven leadership in information security governance within a regulated environment, with strong familiarity with UK, US, European, and Australian regulatory frameworks. You should be able to:

  • Translate complex regulatory and technical requirements into practical controls, policies, and processes.
  • Work effectively with audit and compliance stakeholders during assessments and investigations.
  • Possess a solid background in security frameworks, standards, and regulatory requirements, including enterprise IT, cloud security, data protection, threat management, and incident response.
  • Develop program and project management reporting and documentation.
  • Manage third-party vendors, MSSPs, and contract negotiations.

Core Values

  • Love what you do: We show up each day ready to take on the world. Our passion makes a difference to colleagues, customers, brokers, and carriers.
  • Challenge everything: We question the status quo and strive to improve.
  • Have fun, be good: We make work enjoyable, welcome diverse viewpoints, and treat everyone with respect.

Head of Information Security @ CFC (Basé à London) employer: Golden Bees

CFC is an exceptional employer, offering a dynamic work environment in the heart of London where innovation and collaboration thrive. As the Head of Information Security, you will benefit from a culture that values passion and challenges the status quo, alongside opportunities for professional growth through leadership in a cutting-edge security programme. With a commitment to employee well-being and a focus on fun and respect, CFC ensures that every team member feels valued and empowered to make a meaningful impact.
G

Contact Detail:

Golden Bees Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Head of Information Security @ CFC (Basé à London)

Tip Number 1

Network with professionals in the information security field, especially those who have experience with regulatory frameworks like GDPR and NYDFS. Attend industry events or webinars to connect with potential colleagues and learn about the latest trends in security management.

Tip Number 2

Familiarise yourself with CFC's specific security policies and recent initiatives. Understanding their approach to Third-Party Security Risk Management and Data Loss Prevention will help you demonstrate your alignment with their goals during discussions.

Tip Number 3

Prepare to discuss your leadership style and how you've successfully managed teams in previous roles. Highlight any experience you have in developing security training programmes, as this is a key responsibility for the Head of Information Security.

Tip Number 4

Stay updated on the latest developments in cybersecurity threats and compliance regulations. Being able to speak knowledgeably about current challenges and solutions will set you apart as a proactive candidate who can contribute to CFC's security strategy.

We think you need these skills to ace Head of Information Security @ CFC (Basé à London)

Leadership in Information Security Governance
Knowledge of Regulatory Frameworks (NYDFS, GDPR, etc.)
Risk Management
Third-Party Risk Management
Data Loss Prevention (DLP)
Policy Governance
Security Training & Awareness
Identity & Access Management (IAM)
Incident Response Management
Vendor Relationship Management
Contract Negotiation
Security Policy Development
Project Management
Collaboration with Legal and Compliance Teams
Ability to Translate Technical Requirements into Practical Controls

Some tips for your application 🫡

Understand the Role: Before applying, make sure you fully understand the responsibilities and requirements of the Head of Information Security position. Familiarise yourself with key areas such as Third-Party Security Risk Management and Data Loss Prevention.

Tailor Your CV: Customise your CV to highlight relevant experience in information security governance, particularly within regulated environments. Emphasise your familiarity with regulatory frameworks like GDPR and NYDFS.

Craft a Compelling Cover Letter: Write a cover letter that showcases your passion for information security and your leadership skills. Mention specific examples of how you've successfully managed security programmes or incidents in the past.

Highlight Soft Skills: In addition to technical expertise, emphasise your soft skills such as communication, teamwork, and problem-solving. These are crucial for collaborating with various teams and stakeholders in the role.

How to prepare for a job interview at Golden Bees

Understand Regulatory Frameworks

Make sure you have a solid grasp of key regulatory frameworks like NYDFS and GDPR. Be prepared to discuss how these regulations impact security governance and operations, as this role requires translating complex requirements into practical controls.

Showcase Leadership Experience

Highlight your previous leadership roles in information security, especially within regulated environments. Share specific examples of how you've managed teams or projects, particularly in areas like Third-Party Risk Management and Data Loss Prevention.

Prepare for Scenario-Based Questions

Expect scenario-based questions that assess your problem-solving skills in managing cyber incidents or vendor relationships. Think through past experiences where you successfully navigated challenges and be ready to explain your thought process.

Emphasise Collaboration Skills

This role involves working closely with various teams, including legal and procurement. Be prepared to discuss how you've effectively collaborated across departments in the past, and how you can foster strong relationships to support security initiatives.

Head of Information Security @ CFC (Basé à London)
Golden Bees
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

G
  • Head of Information Security @ CFC (Basé à London)

    Full-Time
    72000 - 108000 £ / year (est.)
  • G

    Golden Bees

    50-100
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>