At a Glance
- Tasks: Lead and shape our information security strategy in a fast-paced RegTech environment.
- Company: Join CUBE, a global leader in Regulatory Technology with a dynamic culture.
- Benefits: Competitive salary, remote work options, and opportunities for personal growth.
- Why this job: Make a real impact in the world of compliance with cutting-edge AI technology.
- Qualifications: 10+ years in information security and proven leadership in regulated environments.
- Other info: Be part of a diverse team driving innovation across 19 countries.
The predicted salary is between 72000 - 108000 ÂŁ per year.
Join to apply for the Executive Head, Information Security role at CUBECUBE, a global RegTech business defining and implementing the gold standard of regulatory intelligence for the financial services industry. We deliver our services through intuitive SaaS solutions, powered by AI, to simplify the complex and everchanging world of compliance for our clients.
CUBE is a globally recognized brand at the forefront of Regulatory Technology. Our industryâleading SaaS solutions are trusted by the world's top financial institutions globally. In 2024, we achieved over 50% growth, both organically and through two strategic acquisitions. We're a fastâpaced, highâperforming team that thrives on pushing boundariesâcontinuously evolving our products, services, and operations. At CUBE, we donât just keep up; we stay ahead.
We believe our future is built by bold, ambitious individuals who are driven to make a real difference. Our "make it happen" culture empowers you to take ownership of your career and accelerate your personal and professional development from day one. With over 700 CUBERs across 19 countries spanning EMEA, the Americas, and APAC, we operate as one team with a shared mission to transform regulatory compliance. Diversity, collaboration, and purpose are the heartbeat of our success.
We were among the first to harness the power of AI in regulatory intelligence, and we continue to lead with our cuttingâedge technology. At CUBE, you will work alongside some of the brightest minds in AI research and engineering in developing impactful solutions that are reshaping the world of regulatory compliance.
We are seeking an experienced Exec Head of Information Security to join our leadership team, reporting directly to the Chief Technology Officer. This critical role will shape and execute our information security strategy as we scale our RegTech platform and expand our customer base in highly regulated markets. You will be responsible for safeguarding the company's information systems against evolving cyber threats. This includes ensuring the security of our diverse infrastructureâspanning private data centres, Office 365, and Azureâwhile maintaining bestâinâclass secure development practices and staying abreast of emerging AI security standards.
You will lead the development of a worldâclass security programme that not only protects our assets but also serves as a competitive differentiator for customers who demand the highest security standards. This role will be based in London and report into our CTO.
Key Responsibilities- Own and evolve the CUBE information security programme, aligning security initiatives with business objectives and regulatory requirements.
- Develop and maintain a multiâyear security roadmap that addresses current threats and anticipates future challenges.
- Collaborate with internal stakeholders and external partners to deliver complex security projects from initiation to completion.
- Lead secure development and AI security programmes, ensuring best practices are followed.
- Define, track, and monitor information security KPIs to enable effective oversight.
- Partner with the CTO to brief the CEO, Executive team, Board of Directors, and investors on information security posture, risks, and programme delivery.
- Design, implement, and continuously improve a comprehensive enterprise information security programme, encompassing preventive, detective, and responsive controls.
- Establish and maintain 24/7 security monitoring and incident response capabilities appropriate for a RegTech serving banking customers working with our outsourced MDR service.
- Lead the response to security incidents and breaches, including investigation, remediation, and lessons learned.
- Conduct regular risk assessments, vulnerability assessments, and security audits to identify and mitigate potential threats.
- Manage relationships with external security vendors, consultants, and managed security service providers.
- Oversee regular penetration testing of applications and infrastructure, including scoping, vendor management, and remediation tracking.
- Drive achievement and maintenance of critical certifications, including ISO 27001, SOC 2 Type II, and other relevant standards.
- Establish and govern comprehensive information security policies, procedures, and standards aligned with industry best practices.
- Support customer security assessments and due diligence processes, working closely with sales and customer success teams.
- Maintain and improve our investor cyber security score and other investorârequired security metrics.
- Lead supplier onboarding and ongoing security assessment/assurance activities, supporting Legal, Procurement, and Finance teams as required.
- Oversee security architecture and controls across our hybrid infrastructure, including multiâcloud environments (Azure primary, with AWS and GCP considerations), onâpremises data centres and colocation facilities, endpoint security for 800+ devices across multiple geographies, Office 365 and Microsoft ecosystem security, and infrastructure as code with DevSecOps practices using Kubernetes.
- Partner with Infrastructure, TechOps, and Platform teams to embed security into all layers of our technology stack.
- Lead security aspects of M&A due diligence and integration activities.
- Build, mentor, and lead a highâperforming information security team.
- Foster a securityâconscious culture across all CUBE teams through training, awareness programmes, and clear communication.
- Ensure all teams understand information security risks and their role in mitigation.
- Develop security champions across engineering teams to embed security thinking in daily operations.
- 10+ years of progressive experience in information security, risk management, and IT leadership roles.
- Proven track record of building and/or scaling information security functions in regulated firms, preferably in financial services or RegTech.
- Handsâon experience achieving and maintaining ISO 27001 and SOC 2 Type II certifications.
- Demonstrated success running the oversight of outsourced SOC/MDR and incident response teams.
- Experience managing and responding to security incidents in a dynamic global environment.
- Experience delivering multiâyear security transformation programmes in midâtoâlarge sized organisations (500â1000+ employees).
- Strong background in cloud security, particularly Azure, with working knowledge of AWS and multiâcloud strategies.
- Deep understanding of regulatory compliance requirements in banking and financial services.
- Engagement in M&A Due Diligence and integration activities.
- Working in Private Equity backed businesses understand the pace and pressure associated with high growth.
- Expert knowledge of security frameworks including ISO/IEC 27001, NIST Cybersecurity Framework, and CIS Controls.
- Proficiency in security technologies including SIEM/SOAR platforms; Identity and Access Management (particularly Microsoft Entra ID/Azure AD); Endpoint Detection and Response (EDR); Cloud Security Posture Management (CSPM); Application Security and DevSecOps tools.
- Understanding of modern threats, attack vectors, and defensive strategies.
- Experience with Zero Trust architecture principles and implementation.
- One or more professional certifications required: CISSP, CISM, CISA.
- Additional certifications valued: CCSP, Azure Security Engineer, AWS Security Specialty.
- Preferred - Bachelor's degree in Information Security or Computer Science.
- Exceptional leadership abilities with experience managing diverse, distributed teams.
- Outstanding communication skills with ability to translate technical security concepts for executive and board audiences.
- Strong business acumen with ability to balance security requirements with business enablement.
- Proven ability to influence and build consensus across technical and nonâtechnical stakeholders.
- Experience working with external auditors, regulators, and customer security teams.
- Cultural fit with fastâpaced, scaling technology company environment.
If you are passionate about leveraging technology to transform regulatory compliance and meet the qualifications outlined above, we invite you to apply. Please submit your resume detailing your relevant experience and interest in CUBE.
CUBE is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.
Executive Head, Information Security in London employer: CUBE
Contact Detail:
CUBE Recruiting Team
StudySmarter Expert Advice đ¤Ť
We think this is how you could land Executive Head, Information Security in London
â¨Tip Number 1
Network like a pro! Reach out to your connections in the industry, especially those who work at CUBE or similar companies. A friendly chat can open doors and give you insider info on the role.
â¨Tip Number 2
Prepare for the interview by researching CUBE's recent projects and achievements. Show us that youâre not just interested in the role but also in how you can contribute to our mission of transforming regulatory compliance.
â¨Tip Number 3
Practice your pitch! Be ready to explain how your experience aligns with the responsibilities of the Executive Head of Information Security. Highlight your hands-on experience with security frameworks and cloud security.
â¨Tip Number 4
Donât forget to apply through our website! Itâs the best way to ensure your application gets seen by the right people. Plus, it shows youâre serious about joining our team at CUBE.
We think you need these skills to ace Executive Head, Information Security in London
Some tips for your application đŤĄ
Tailor Your CV: Make sure your CV is tailored to the Executive Head, Information Security role. Highlight your experience in information security and risk management, especially in regulated environments like financial services. We want to see how your skills align with our mission at CUBE!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about regulatory technology and how you can contribute to our team. Be sure to mention specific achievements that demonstrate your leadership in security initiatives.
Showcase Your Technical Skills: Donât forget to highlight your technical competencies, especially around cloud security and compliance frameworks. Weâre looking for someone who knows their stuff when it comes to ISO 27001 and SOC 2 Type II certifications, so make sure these stand out!
Apply Through Our Website: We encourage you to apply directly through our website. Itâs the best way to ensure your application gets into the right hands. Plus, it shows us youâre serious about joining the CUBE team!
How to prepare for a job interview at CUBE
â¨Know Your Stuff
Make sure youâre well-versed in the latest trends and challenges in information security, especially within the financial services sector. Brush up on your knowledge of ISO 27001, SOC 2 Type II, and the NIST Cybersecurity Framework, as these are crucial for the role.
â¨Showcase Your Leadership Skills
As an Executive Head, you'll need to demonstrate strong leadership abilities. Prepare examples of how you've built and led high-performing teams in the past, and be ready to discuss how you foster a security-conscious culture within an organisation.
â¨Be Ready for Scenario Questions
Expect questions that put you in hypothetical situations related to security incidents or compliance challenges. Think through your responses ahead of time, focusing on your problem-solving skills and how you would handle real-world scenarios.
â¨Align with Their Vision
CUBE is all about pushing boundaries and staying ahead in RegTech. Familiarise yourself with their mission and values, and be prepared to discuss how your vision for information security aligns with their goals. Show them youâre not just a fit for the role, but for the company culture too.