At a Glance
- Tasks: Lead a dynamic cybersecurity team to protect BII from evolving cyber threats.
- Company: Join British International Investment, a leader in safeguarding technology and data.
- Benefits: Enjoy a competitive salary and a commitment to diversity and inclusion.
- Other info: Be part of a collaborative culture that values tenacity and social goals.
- Why this job: Make a real impact in cybersecurity while developing your leadership skills.
- Qualifications: Proven experience in cybersecurity leadership and strong communication skills required.
The predicted salary is between 80000 - 100000 £ per year.
The Cybersecurity Team protects BII’s technology, people, and processes from cyber-attacks. With top-tier tools and a leading Managed Security Service Provider, the team maintains the confidentiality, availability, and integrity of BII’s assets and data, supporting operations across markets. As a core part of the security function, the team is crucial in defending against evolving cyber threats. Given its role, the team is highly visible to the senior leadership of the organisation.
The Head of Cyber Security provides operational leadership, governance and accountability for BII’s cybersecurity capability. The role manages a team of cybersecurity professionals responsible for protecting and defending BII from cyber-attacks, whilst similarly managing identity as a security enabler. The role holder will own core and emerging cyber risk domains—spanning cybersecurity operations, identity and AI—ensuring risks are identified early, governed effectively and managed within appetite. They will strengthen organisational resilience through incident readiness and response. The role also acts as Bronze Incident Manager for cybersecurity incidents.
BII’s technology and supplier landscape is evolving, increasing cyber risk. This role provides clear operational ownership of cyber defence, risk governance and incident readiness, embedding security into change and decision-making.
What Success Looks Like
- Cyber risks are detected early, managed appropriately, and reported to senior leadership.
- Controls are proven effective through monitoring, vulnerability management, and measurable resilience improvements.
- Incidents are handled with rehearsed responses and applied lessons learned.
How the Role Fits into the Organisation
Reporting to the Head of Security, the Head of Cyber Security leads day-to-day cybersecurity and works closely with Technology, senior stakeholders and key suppliers to ensure that the Cybersecurity of BII is maintained and endures. The role turns cyber risk into prioritised actions and provides clear input to senior leadership forums to protect services, enable change and strengthen resilience.
Responsibilities
- Define and implement Cybersecurity strategy for BII, in order to keep BII safe.
- Lead and manage the cybersecurity team by setting direction, priorities, performance standards and development plans.
- Deputise for the Head of Security when required by representing Security in senior forums and making decisions within delegated authority.
- Lead cybersecurity operations, including monitoring, vulnerability management, readiness and control health reporting.
- Act as Bronze Incident Manager for cyber incidents by coordinating response and escalating to Silver/Gold when required.
- Manage cyber risk within agreed appetite by assessing, treating and reporting risks with clear evidence and metrics.
- Set cybersecurity governance for key domains, including Identity, third-party security, AI risk and data sovereignty.
- Translate cyber risk into prioritised actions and report clearly to OpCo/ExCo/Audit and other forums.
- Manage the outsourced Managed Security service provider (MSSP) and specialist suppliers by setting expectations, reviewing SLAs/KPIs and driving remediation.
- Embed security into change by defining requirements and validating controls for patching, configuration and new services.
- Maintain cyber playbooks, runbooks and standards to improve consistency and reduce key-person dependency.
- Define and oversee cyber security training awareness across BII.
The candidate
The successful candidate brings a strong track record in senior cybersecurity roles, leading others to deliver effective security operations, incident management and risk governance in complex environments. The background includes working with outsourced security providers, influencing technology and business stakeholders, and embedding practical security controls into day-to-day operations and change. The ideal candidate has a technical background and can translate complex topics into clear, business-focused discussions.
Essential skills:
- Proven people leadership and the credibility to represent Security in senior forums and deputise for the Head of Security.
- Ability to set security standards and governance, and to present risk and control status clearly to senior stakeholders.
- Strong communication skills, with the ability to articulate complex technical matter to non-technical and senior audiences.
- Significant experience leading cybersecurity operations, including detection/monitoring and vulnerability management.
- Experience managing cyber incidents end-to-end, including communications, decision logs and lessons learned.
- Strong knowledge of current threats, identity security and third-party risk.
- Experience managing MSSPs and specialist suppliers through governance and SLAs/KPIs.
- Broad technical understanding across cloud, endpoints, networks and logging sufficient to challenge and guide technical teams.
- Demonstrable understanding of emerging AI-driven threats, their implications for cyber security and their mitigations.
- A relevant cybersecurity qualification and/or recognised certification (e.g., CISSP, CISM, SANS) with ongoing professional development.
Desirable criteria
- Experience with cloud security controls and monitoring (e.g., Microsoft 365/Azure).
- Experience with SIEM/SOAR, detection engineering or incident automation.
- Experience implementing IAM tooling and access governance (e.g., PAM, IGA).
- Experience commissioning security testing and remediation programmes (e.g., pen tests, scanning).
- Experience delivering security awareness and incident exercising programmes.
- Working knowledge of assurance frameworks and resilience expectations (e.g., ISO 27001, SOC 2, NIST CSF).
Candidates should be strongly motivated by BII’s development mission and ideally demonstrate some commitment to development or social goals through previous executive or non-executive activity.
Our cultural values
- Impact-led, commercially rigorous
- Tenacious in the face of challenges
- Collaborative and caring
British International Investment is committed to diversity and inclusion and welcomes all applicants regardless of age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race, religion or belief, sex, sexual orientation or educational background.
Please provide a cover letter with your application.
Salary: Competitive
Head of Cyber-Security in London employer: British International Investment
Contact Detail:
British International Investment Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Head of Cyber-Security in London
✨Tip Number 1
Network like a pro! Reach out to your connections in the cybersecurity field and let them know you're on the hunt for the Head of Cyber-Security role. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by brushing up on your knowledge of current cyber threats and risk management strategies. Be ready to discuss how you've tackled similar challenges in the past, as this will show your potential employer that you're the right fit for leading their cybersecurity team.
✨Tip Number 3
Don’t just wait for job postings to come to you! Keep an eye on our website and apply directly through it. This way, you’ll be one step ahead and show your enthusiasm for the role at BII.
✨Tip Number 4
Practice your communication skills! As a Head of Cyber-Security, you'll need to explain complex technical issues to non-technical stakeholders. Try explaining a recent cyber incident or risk management strategy to a friend or family member to refine your approach.
We think you need these skills to ace Head of Cyber-Security in London
Some tips for your application 🫡
Tailor Your Cover Letter: Make sure to customise your cover letter for the Head of Cyber-Security role. Highlight your relevant experience and how it aligns with BII’s mission. We want to see your passion for cybersecurity and how you can contribute to our team!
Showcase Your Leadership Skills: Since this role involves leading a team, don’t forget to emphasise your people leadership experience. Share specific examples of how you've successfully managed teams and driven results in previous roles. We love to see strong leaders!
Be Clear and Concise: When writing your application, keep it clear and to the point. Use straightforward language to explain complex topics, especially when discussing technical aspects. We appreciate clarity, and it helps us understand your thought process better.
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, it shows you’re serious about joining our team at StudySmarter!
How to prepare for a job interview at British International Investment
✨Know Your Cybersecurity Stuff
Make sure you brush up on the latest trends and threats in cybersecurity. Be ready to discuss your experience with incident management, vulnerability assessments, and how you've handled cyber risks in the past. This role is all about operational leadership, so showing that you can translate complex topics into clear strategies will impress the interviewers.
✨Showcase Your Leadership Skills
As the Head of Cyber Security, you'll be leading a team, so it's crucial to demonstrate your people management skills. Prepare examples of how you've set direction, developed team members, and managed performance. Highlight any experience you have in representing security in senior forums, as this will show your credibility and ability to influence at higher levels.
✨Prepare for Scenario-Based Questions
Expect questions that put you in hypothetical situations related to cyber incidents or risk management. Think through how you would coordinate responses, manage communications, and apply lessons learned from past incidents. Practising these scenarios will help you articulate your thought process clearly during the interview.
✨Understand BII’s Mission and Values
Familiarise yourself with British International Investment's development mission and cultural values. Be prepared to discuss how your personal values align with theirs, especially around being impact-led and collaborative. Showing that you're not just a fit for the role but also for the organisation will make a strong impression.