Chief Information Security Officer (CISO)

Chief Information Security Officer (CISO)

Full-Time 84000 - 196000 £ / year (est.) No working from home possible
Golden Bees

At a Glance

  • Tasks: Lead Ripjar's global security strategy and manage cyber risk.
  • Company: Ripjar develops software to combat financial crime for governments and organisations.
  • Benefits: Enjoy remote work, 25 days leave, private healthcare, and a top MacBook Pro.
  • Other info: This is a hands-on leadership role with opportunities for growth and impact.
  • Why this job: Join a mission-driven team tackling serious financial crime with cutting-edge technology.
  • Qualifications: Proven leadership in security, expertise in ISO27001, and strong communication skills required.

The predicted salary is between 84000 - 196000 £ per year.

Ripjar specialises in the development of software and data products that help governments and organisations combat serious financial crime. Our technology is used to identify criminal activity such as money laundering and terrorist financing, enabling organisations to enforce sanctions at scale to help combat rogue entities and state actors.

As Chief Information Security Officer (CISO), you will be responsible for developing and executing our cyber risk strategy, driving alignment with international frameworks such as ISO27001, SOC2, DORA and regional frameworks like Cyber Essentials, and leading executive team engagement on security governance, regulatory readiness, and organisational resilience. You will be responsible for monitoring and improving the information security of Ripjar's technology infrastructure, products and services as we continue to scale.

This is a hands-on leadership role. You will be responsible not only for setting strategy, but also for directly executing core activities such as policy development, supporting audits and accreditations, incident response, and day-to-day security operations.

What you’ll be doing:

  • Strategic Security Leadership
    • Set the organisation-wide security vision and roadmap; act as security evangelist at the executive level.
    • Maintain and evolve our security and compliance posture to support international expansion and customer growth.
    • Manage and own the Information Security budget, investments, and ROI.
  • Governance, Risk, and Compliance
    • Maintain compliance with ISO27001, SOC2, Cyber Essentials and evolving DORA regulations.
    • Lead internal risk assessments, security audits, and regulatory readiness efforts.
    • Oversee third-party and supply chain security due diligence and assurance processes.
  • Operational Security & Infrastructure
    • Partner with infrastructure and engineering teams to drive secure architecture, code, and systems.
    • Identify vulnerabilities and lead remediation in hybrid environments (AWS, private cloud).
    • Ensure security principles are implemented and continuously improved.
  • Culture, Education, and Awareness
    • Embed a security-first culture across the business through education, training, and policy.
    • Support the commercial team in client conversations and security due diligence including contributing actively to RFI/RFP processes.
    • Act as the point of contact for external audits, client reviews, and incident communications.

About You:

We’re looking for a security leader who blends deep technical acumen with strong strategic and business leadership. You will take a pragmatic approach to information security and its practical application to our organisation as it scales.

Ideally, you will have:

  • Proven leadership in high-growth scale-up environments.
  • Expertise in ISO27001, SOC2, NIST CSF, Cyber Essentials, and DORA.
  • Experience with modern cloud infrastructure and security (AWS, Azure, GCP, PaaS/IaaS/SaaS).
  • Familiarity with IAM, DLP, and Linux-based environments.
  • Strong understanding of security architecture, governance, and regulatory trends.
  • Professional certifications such as CISSP, CISM, or CRISC (preferred).
  • Exceptional communication skills to engage senior internal and external stakeholders.
  • High level of integrity, resilience, and executive presence.

Benefits

Why we think you’ll enjoy it here:

  • Salary up to 140k DOE
  • 25 days annual leave + your birthday off, rising to 30 days after 5 years of service
  • Fully remote working with occasional travel
  • Life assurance
  • Private Family Healthcare
  • Employee Assistance Programme
  • Company contributions to your pension
  • Enhanced maternity/paternity pay
  • The latest tech including a top of the range MacBook Pro
  • Offices equipped with well-stocked pantries with food, snacks and drinks when in the office
Golden Bees

Contact Details:

Golden Bees Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Chief Information Security Officer (CISO)

Tip Number 1

Familiarise yourself with the specific security frameworks mentioned in the job description, such as ISO27001 and SOC2. Being able to discuss these frameworks in detail during interviews will demonstrate your expertise and alignment with Ripjar's needs.

Tip Number 2

Network with professionals in the cybersecurity field, especially those who have experience in high-growth environments. Engaging with industry peers can provide insights into the role and may even lead to referrals.

Tip Number 3

Prepare to showcase your leadership skills by gathering examples of how you've successfully managed security teams or projects in the past. Highlighting your hands-on experience will be crucial for a leadership role like CISO.

Tip Number 4

Stay updated on the latest trends in cloud security and regulatory changes. Being knowledgeable about current events and advancements in technology will help you engage in meaningful discussions during interviews.

We think you need these skills to ace Chief Information Security Officer (CISO)

Leadership in Cybersecurity
Strategic Security Planning
ISO27001 Compliance
SOC2 Compliance
Cyber Essentials Knowledge
DORA Regulations Familiarity
Risk Assessment and Management

Some tips for your application 🫡

Understand the Role:Before applying, make sure you fully understand the responsibilities and requirements of the Chief Information Security Officer position at Ripjar. Familiarise yourself with their mission and how your skills align with their needs.

Tailor Your CV:Craft your CV to highlight relevant experience in information security leadership, compliance with frameworks like ISO27001 and SOC2, and your expertise in cloud infrastructure. Use specific examples that demonstrate your strategic impact in previous roles.

Write a Compelling Cover Letter:In your cover letter, express your passion for combating financial crime and how your background makes you a perfect fit for Ripjar. Mention your leadership style and how you plan to foster a security-first culture within the organisation.

Showcase Your Certifications:If you hold any professional certifications such as CISSP, CISM, or CRISC, be sure to mention them prominently in your application. These credentials can significantly enhance your profile and demonstrate your commitment to the field.

How to prepare for a job interview at Golden Bees

Demonstrate Your Strategic Vision

As a CISO, you'll need to showcase your ability to set a security vision and roadmap. Prepare to discuss your previous experiences in leading security strategies and how you aligned them with business goals.

Showcase Technical Expertise

Be ready to dive deep into your knowledge of ISO27001, SOC2, and other relevant frameworks. Highlight specific instances where you've implemented these standards and the impact they had on your organisation's security posture.

Communicate Effectively

Exceptional communication skills are crucial for this role. Practice articulating complex security concepts in a way that is understandable to non-technical stakeholders, as you'll be engaging with senior executives and clients.

Prepare for Scenario-Based Questions

Expect questions that assess your problem-solving abilities in real-world scenarios. Think about past incidents you've managed, how you responded, and what you learned from those experiences to improve future security measures.