Chief Information Security Officer (CISO)

Chief Information Security Officer (CISO)

Full-Time 45000 - 55000 £ / year (est.) Home office (partial)
D

At a Glance

  • Tasks: Lead the information security strategy and protect sensitive client data.
  • Company: Join a forward-thinking organisation prioritising cyber resilience and client trust.
  • Benefits: Enjoy private medical insurance, income protection, gym discounts, and remote work options.
  • Other info: Opportunity to shape security governance and drive awareness across the organisation.
  • Why this job: Make a real impact on data security and compliance in a dynamic environment.
  • Qualifications: Extensive experience in information security and strong leadership skills required.

The predicted salary is between 45000 - 55000 £ per year.

Overview

As CISO you’ll own the information security strategy and risk program to protect sensitive client data and maintain regulatory compliance.

You’ll partner with senior leadership to mature security posture, lead incident response with MSSP support, and oversee governance for GDPR, SRA, and data protection.

The role combines strategic leadership with hands-on governance, aiming to strengthen cyber resilience and client trust across the organization.

  • Pay / Benefits
  • private medical insurance
  • income protection insurance
  • discounted gym membership
  • professional funding
  • remote work
  • ESG activities

Responsibilities

  • Develop and own the information security strategy, roadmap, and risk management framework
  • Coordinate security incident response with MSSP, leading investigations and remediation
  • Implement governance for GDPR, data protection, DPIAs, data processing agreements, and data subject requests
  • Ensure SRA compliance and alignment with information security standards
  • Manage third-party security assessments and vendor risk reviews (technology, finance, AI providers)
  • Maintain security controls for data classification, access, encryption, monitoring, and logging
  • Drive security awareness through training and incident response exercises
  • Oversee relationships with external MSSPs for governance and service delivery
  • Provide clear risk reporting to executive leadership and regulators as required
  • Key requirements
  • Significant information security experience with leadership roles (CISO/Head of Security)
  • Strong knowledge of GDPR, UK GDPR, Data Protection Act 2018, and UK regulatory requirements
  • Experience in highly regulated environments
  • Proven incident response, breach management, and digital forensics skills
  • Solid understanding of security technologies and best practices, especially in Microsoft Azure
  • Excellent communication and stakeholder management; ability to translate risks for business
  • Experience developing security strategies, policies, and governance frameworks
  • excellent communication
  • stakeholder management
  • ability to translate technical risks into business language
  • Microsoft Azure
  • incident response and breach management
  • digital forensics

Chief Information Security Officer (CISO) employer: DAC Beachcroft

Join our prestigious London-based Construction Professional Indemnity team, where you will be part of a collaborative and dynamic work culture that values professional growth and development. As a Junior Project Associate, you will have the opportunity to work on complex, high-value matters alongside experienced colleagues, gaining invaluable insights into the construction and insurance sectors. With a strong focus on employee well-being and a hybrid working model, we offer a supportive environment that encourages innovation and teamwork, making us an excellent employer for those seeking meaningful and rewarding careers.

D

Contact Details:

DAC Beachcroft Recruitment Team

We think you need these skills to ace Chief Information Security Officer (CISO)

Information Security Strategy Development
Risk Management Framework
Incident Response Coordination
GDPR Compliance
Data Protection Governance
Security Awareness Training
Third-Party Security Assessments