Fractional Chief Information Security Officer in London
Fractional Chief Information Security Officer

Fractional Chief Information Security Officer in London

London Full-Time 36000 - 60000 £ / year (est.) Home office (partial)
Go Premium
G

At a Glance

  • Tasks: Lead our information security strategy and ensure compliance with industry standards.
  • Company: Join a growing international fintech company with a focus on security.
  • Benefits: Enjoy competitive pay, 26 days off, and remote work support.
  • Why this job: Make a real impact on security while shaping the future of our organisation.
  • Qualifications: 8+ years in information security, with experience in B2B SaaS and cloud environments.
  • Other info: Be part of a dynamic team with regular performance reviews and recognition rewards.

The predicted salary is between 36000 - 60000 £ per year.

We are seeking an experienced Fractional CISO to provide hands-on security leadership as we evolve our security function to support continued growth and European expansion. This is a permanent fractional engagement reporting directly to the CTO. You will own our information security strategy, maintain our ISO 27001 certification, build our security roadmap, and prepare the organisation for SOC 2 readiness in 2026-2027. This role requires someone who can operate both strategically and tactically — developing policy one day and reviewing cloud configurations the next.

Key Responsibilities

  • Strategy & Governance
    • Develop and own the Information Security strategy aligned with ApprovalMax's business objectives and European expansion plans.
    • Maintain and continuously improve the Information Security Management System (ISMS).
    • Create, review, and maintain core security policies, standards, and procedures.
    • Establish and chair a cross-functional Security Working Group (Engineering, Architecture, IT, HR).
    • Build and present a multi-year security roadmap with clear milestones, resource requirements, and priorities.
    • Serve as the central authority on risk assessment, risk treatment, and risk acceptance decisions.
    • Assess and provide guidance on secure AI adoption across the organisation, including AI-powered product features and internal AI tooling.
  • Compliance & Certification
    • Maintain ISO 27001 certification and prepare for the 2027 recertification audit.
    • Lead SOC 2 Type II readiness programme (target: 2026-2027), including gap analysis and control mapping.
    • Ensure compliance with GDPR and data protection requirements across EU/UK/US/AU/NZ/CA/ZA jurisdictions.
    • Collaborate with external DPO support provider on privacy-related matters and customer security questionnaires as needed.
  • Cloud & Technical Security
    • Provide security oversight across Azure, AWS, and Google Workspace environments.
    • Conduct access reviews and advise on identity and access management best practices.
    • Evaluate and guide implementation of security tooling (SIEM, vulnerability management, endpoint protection).
    • Oversee VMware Workspace ONE MDM deployment and device security policies.
    • Advise engineering teams on secure SDLC practices, DevSecOps integration, and application security principles.
  • Operational Security
    • Develop and maintain incident response plans and procedures.
    • Lead incident response tabletop exercises and post-incident reviews.
    • Provide guidance on business continuity and disaster recovery planning.
    • Advise on vendor security assessments and third-party risk management.
  • Awareness & Culture
    • Design and deliver company-wide security awareness training programmes.
    • Mentor and upskill internal staff on security best practices.
    • Foster a security-first culture across all departments.
    • Act as a trusted advisor to leadership on emerging threats and security trends.
  • Stakeholder Engagement
    • Report regularly to the CTO on security posture, risks, and programme progress.
    • Prepare board-level security presentations as required (infrequent).
    • Support commercial teams by contributing to customer security discussions when escalated.

Qualifications

  • 8+ years of progressive experience in information security, with at least 3 years in a CISO, Head of Security, or senior security leadership role.
  • Demonstrated experience in B2B SaaS environments, ideally in fintech, finance software, or similarly regulated industries.
  • Proven track record of achieving and maintaining ISO 27001 certification.
  • Experience preparing organisations for SOC 2 Type II certification.
  • Hands-on experience securing cloud environments (Azure and/or AWS required; GCP a plus).
  • Experience with Google Workspace security configuration and administration.
  • Background working with distributed, remote-first engineering teams.

Technical Knowledge

  • Strong understanding of cloud security architecture, identity management, and zero-trust principles.
  • Familiarity with secure software development lifecycle (SDLC) and DevSecOps practices.
  • Knowledge of MDM solutions (VMware Workspace ONE experience preferred).
  • Understanding of API security and integration risk management.
  • Practical experience with security tooling: SIEM, vulnerability scanners, endpoint protection, etc.
  • Awareness of AI/ML security risks, including secure AI adoption practices and emerging AI governance frameworks (desirable).

Compliance & Regulatory

  • Deep knowledge of ISO 27001:2022 requirements and audit processes.
  • Familiarity with SOC 2 Trust Service Criteria (Security, Availability, Confidentiality, Privacy).
  • Understanding of GDPR, UK Data Protection Act, and international data transfer mechanisms.
  • Awareness of regional requirements across EU, UK, US, Australia, New Zealand, Canada, and South Africa.

Additional Information

  • Growing international business with 10,000+ subscribers.
  • Regular performance-based compensation reviews.
  • 26 days paid time off.
  • 1 additional day off for your Birthday.
  • Remote office assistance.
  • Service years recognition financial reward.

Fractional Chief Information Security Officer in London employer: Gofractional

At ApprovalMax, we pride ourselves on being an exceptional employer that fosters a dynamic and inclusive work culture, particularly for our Fractional Chief Information Security Officer role. With a focus on employee growth, we offer regular performance-based compensation reviews, 26 days of paid time off, and unique benefits like remote office assistance and recognition rewards for service years, all while supporting your strategic leadership in a rapidly expanding international business.
G

Contact Detail:

Gofractional Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Fractional Chief Information Security Officer in London

✨Tip Number 1

Network like a pro! Reach out to your connections in the cybersecurity field, especially those who have experience as a CISO. Attend industry events or webinars to meet potential employers and get your name out there.

✨Tip Number 2

Showcase your expertise! Create a portfolio that highlights your achievements in information security, particularly around ISO 27001 and SOC 2 readiness. This will give you an edge when discussing your qualifications with potential employers.

✨Tip Number 3

Prepare for interviews by brushing up on both strategic and tactical aspects of security leadership. Be ready to discuss how you've developed security policies and managed cloud environments, as these are key areas for the Fractional CISO role.

✨Tip Number 4

Don’t forget to apply through our website! We’re always looking for talented individuals like you to join our team. Plus, it’s a great way to ensure your application gets the attention it deserves.

We think you need these skills to ace Fractional Chief Information Security Officer in London

Information Security Strategy Development
ISO 27001 Certification Maintenance
SOC 2 Type II Readiness
Risk Assessment and Management
Cloud Security Oversight (Azure, AWS, Google Workspace)
Identity and Access Management
Security Tooling Evaluation (SIEM, Vulnerability Management)
Secure Software Development Lifecycle (SDLC)
DevSecOps Integration
Incident Response Planning
Business Continuity and Disaster Recovery Planning
Security Awareness Training Design
Stakeholder Engagement and Reporting
GDPR Compliance Knowledge
Understanding of API Security

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience in information security, especially in relation to the responsibilities listed in the job description. We want to see how your skills align with our needs!

Showcase Your Achievements: Don’t just list your past roles; share specific achievements that demonstrate your ability to maintain ISO 27001 certification or lead SOC 2 readiness programmes. We love seeing quantifiable results!

Be Clear and Concise: Keep your application straightforward and to the point. Use bullet points for easy reading and make sure to address all key qualifications mentioned in the job description. We appreciate clarity!

Apply Through Our Website: We encourage you to submit your application directly through our website. It’s the best way for us to receive your details and ensures you’re considered for this exciting opportunity!

How to prepare for a job interview at Gofractional

✨Know Your Stuff

Make sure you brush up on your knowledge of ISO 27001 and SOC 2 requirements. Be ready to discuss how you've maintained certifications in the past and any specific challenges you've faced in B2B SaaS environments, especially in fintech or finance software.

✨Show Your Strategic Side

Prepare to talk about your experience in developing and owning information security strategies. Think of examples where you've aligned security initiatives with business objectives, particularly in relation to European expansion plans.

✨Hands-On Experience Matters

Be ready to share specific instances where you've operated both strategically and tactically. Whether it’s developing policies or reviewing cloud configurations, having concrete examples will demonstrate your versatility and hands-on approach.

✨Engage with Stakeholders

Think about how you've communicated security posture and risks to leadership in the past. Prepare to discuss how you would report to the CTO and present security updates to the board, as well as how you’ve supported commercial teams in customer security discussions.

Fractional Chief Information Security Officer in London
Gofractional
Location: London
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

G
  • Fractional Chief Information Security Officer in London

    London
    Full-Time
    36000 - 60000 £ / year (est.)
  • G

    Gofractional

    50-100
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>