Head of Information Security

Head of Information Security

Full-Time 80000 - 100000 £ / year (est.) No working from home possible
Aurora Energy Research Limited

At a Glance

  • Tasks: Lead and evolve Aurora's Information Security strategy to support global growth and product development.
  • Company: Join a fast-growing, innovative software company at the forefront of technology.
  • Benefits: Enjoy private medical insurance, dental cover, parental support, and more perks.
  • Other info: Collaborate with diverse teams and drive security culture across the organisation.
  • Why this job: Make a significant impact on security strategy in a dynamic, data-rich environment.
  • Qualifications: Proven leadership in Information Security with strong technical credibility and strategic judgement.

The predicted salary is between 80000 - 100000 £ per year.

Aurora is a fast-growing, software-focused global business. We are looking for an experienced Head of Information Security to shape and deliver the next phase of our Information Security strategy. This is a high-impact leadership role at the centre of Aurora’s continued growth as a global, data-rich and increasingly software-led business.

You will lead and evolve our Information Security function, ensuring that security strategy, governance, controls and culture remain effective, proportionate, and aligned to business priorities. You will work closely with senior leaders and operational teams across the business to ensure that security is embedded into how Aurora builds products, operates services, protects information, supports clients and scales internationally. This role requires a leader who can combine strategic judgement, strong technical credibility and pragmatic delivery.

You will help Aurora make sound risk-based decisions, strengthen cyber resilience, and support the continued evolution of Aurora’s wider security and compliance operating model. The successful candidate will thrive in a creative and intellectually stimulating environment, enjoy a high degree of autonomy, and have the opportunity to make a significant contribution to our digital strategy and long-term resilience.

Key Responsibilities
  • Define, maintain and evolve Aurora’s Information Security strategy, roadmap and target operating model to support business growth, product development and international expansion.
  • Lead and develop the Information Security function, building organisational capability through a combination of central leadership, cross-functional influence and clear ownership across the business.
  • Lead Information Security governance, risk and assurance activities, ensuring clear reporting, effective escalation and risk-informed decision-making at executive level.
  • Maintain Aurora’s Information Security risk management framework and risk register, ensuring key risks are identified, prioritised, communicated and addressed appropriately.
  • Provide assurance to internal and external stakeholders that Aurora’s security controls are effective, proportionate and aligned to business, customer and regulatory requirements.
  • Lead security assurance and certification activities, including ISO 27001, SOC 2, and related audit readiness, while contributing to the continued evolution of Aurora’s wider security and compliance operating model.
  • Partner with Legal and other relevant stakeholders on data protection, customer and supplier due diligence, contractual security commitments and third-party risk management.
  • Help define how security responsibilities and capabilities are allocated across Aurora’s technology, legal/compliance and business functions, ensuring clear accountability, effective challenge and strong delivery.
  • Drive security by design across Aurora’s products, platforms, systems and infrastructure, working closely with engineering and technology leaders to embed secure architecture, secure development lifecycle practices and appropriate technical controls.
  • Strengthen capabilities across core security domains including identity and access management, privileged access, vulnerability management, incident response, disaster recovery, data protection, security awareness and supplier security.
  • Work closely with stakeholders at all levels of the organisation, including operational teams such as People & Culture, Business Infrastructure & Operations and Finance, to support audits, evidence gathering, control improvement and the effective adoption of security requirements across the organisation.
  • Lead response to significant information security incidents, acting as a senior decision-maker during crisis situations and driving post-incident learning and improvement.
  • Build a strong, pragmatic security culture across the organisation through effective awareness, engagement, coaching and leadership.
  • Manage the Information Security budget, financial forecasts and investment cases, ensuring that spend is aligned to Aurora’s risk profile and strategic priorities.
  • Provide trusted advice and challenge to senior stakeholders on emerging risks and opportunities, including those related to AI adoption, shadow IT, cloud services and evolving regulatory expectations.
Skills, Knowledge and Expertise Required attributes
  • Significant leadership experience in Information Security, Cyber Security, or a closely related role within a technology-led, software-oriented and internationally operating business.
  • Strong technical credibility and sound judgement across key security domains, with sufficient depth to guide strategy, challenge decisions and work effectively with specialist software engineering and IT teams.
  • Broad experience across areas such as product/application security, cloud/infrastructure security, identity and access management, incident response, vulnerability management and security governance.
  • Proven experience developing and delivering an Information Security strategy in a way that balances risk reduction, business enablement and operational pragmatism.
  • Strong experience leading security risk assessments, threat modelling, incident management and remediation of security weaknesses in a structured, risk-based way.
  • Significant experience managing external audits, customer assurance and recognised security standards/certifications such as ISO 27001 and SOC 2.
  • Experience influencing senior stakeholders and communicating clearly at executive level, including the ability to translate technical risk into clear business decisions and trade-offs.
  • Able to lead effectively through subject-matter experts, building strong partnerships with engineering, IT and business leaders to drive security outcomes across a shared-responsibility model.
  • A pragmatic, delivery-oriented mindset, with the judgement to know when to stay strategic and when to be hands-on.
  • Excellent communication, collaboration and relationship-building skills, with the ability to work effectively across technical, operational and non-technical functions, and to engage confidently with stakeholders at different levels of seniority.
  • Strong problem-solving skills, sound judgement and a bias for action.
Desirable attributes
  • Experience in a fast-growing global software or SaaS business.
  • Experience embedding security by design / DevSecOps practices into software engineering and platform teams.
  • Experience supporting security requirements for enterprise customers, regulated sectors or complex supplier ecosystems.
  • Familiarity with emerging security challenges around AI adoption, shadow AI, API security and third-party SaaS risk.
  • Experience operating in an environment with multiple international offices and evolving regulatory requirements.
What we offer
  • Private Medical Insurance
  • Dental Insurance
  • Parental Support
  • Salary-Exchange Pension
  • Employee Assistance Programme (EAP)
  • Local Oxford Discounts
  • Cycle-to-work Scheme
  • Flu Jabs

The Company is committed to the principle that no employee or job applicant shall receive unfavourable treatment on grounds of age, disability, gender reassignment, race, religion or belief, sex, sexual orientation, marriage or civil partnership, pregnancy, and maternity.

Head of Information Security employer: Aurora Energy Research Limited

Aurora is an exceptional employer, offering a dynamic and intellectually stimulating environment in Oxford where you can lead the charge in shaping our Information Security strategy. With a strong focus on employee growth, we provide comprehensive benefits including private medical insurance and a cycle-to-work scheme, alongside opportunities for professional development and a culture that values innovation and collaboration. Join us to make a meaningful impact in a fast-growing, software-focused global business that prioritises security and resilience.

Aurora Energy Research Limited

Contact Details:

Aurora Energy Research Limited Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Head of Information Security

Tip Number 1

Network like a pro! Reach out to your connections in the industry, attend relevant events, and engage with professionals on platforms like LinkedIn. We all know that sometimes it’s not just what you know, but who you know that can help you land that dream job.

Tip Number 2

Prepare for interviews by researching the company and its culture. Understand their security challenges and be ready to discuss how your experience aligns with their needs. We want you to shine, so practice common interview questions and have your own questions ready to show your interest!

Tip Number 3

Showcase your expertise! Create a portfolio or a presentation that highlights your past achievements in information security. We love seeing tangible results, so include metrics and examples of how you've improved security measures in previous roles.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, we’re always looking for passionate individuals who can contribute to our mission, so make sure you put your best foot forward!

We think you need these skills to ace Head of Information Security

Leadership in Information Security
Cyber Security Expertise
Technical Credibility
Information Security Strategy Development
Risk Management Frameworks
ISO 27001 Certification
SOC 2 Compliance

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in Information Security. Use keywords from the job description to show that you understand what we're looking for.

Showcase Your Leadership Skills:As a Head of Information Security, we want to see your leadership experience shine through. Share examples of how you've led teams or projects, especially in tech-focused environments.

Be Clear and Concise:When writing your application, keep it straightforward. We appreciate clarity, so avoid jargon and get straight to the point about your skills and experiences.

Apply Through Our Website:Don't forget to submit your application through our website! It’s the best way for us to receive your details and ensures you’re considered for this exciting opportunity.

How to prepare for a job interview at Aurora Energy Research Limited

Know Your Stuff

Make sure you brush up on the latest trends and challenges in information security, especially those relevant to software and cloud environments. Be ready to discuss your experience with ISO 27001, SOC 2, and how you've handled security incidents in the past.

Show Your Leadership Skills

This role is all about leadership, so be prepared to share examples of how you've led teams and influenced stakeholders. Think about times when you’ve successfully driven security initiatives or built a strong security culture within an organisation.

Align with Business Goals

Aurora is looking for someone who can align security strategies with business priorities. Be ready to discuss how you've balanced risk management with business enablement in previous roles, and how you plan to do this at Aurora.

Ask Smart Questions

Prepare insightful questions that show your understanding of the company’s challenges and goals. Ask about their current security posture, how they handle emerging threats, or what their vision is for integrating security into product development.