Chief Information Security Officer in Edinburgh

Chief Information Security Officer in Edinburgh

Edinburgh Full-Time 70000 - 90000 £ / year (est.) No working from home possible
Grant Thornton UK

At a Glance

  • Tasks: Lead the security strategy and governance for a pioneering professional services firm.
  • Company: Join Grant Thornton, a forward-thinking firm transforming the industry with innovative solutions.
  • Benefits: Enjoy flexible working, tailored development, and a competitive salary package.
  • Other info: Be part of an inclusive culture that values your unique contributions and promotes work-life balance.
  • Why this job: Make a real impact in security while shaping the future of our industry.
  • Qualifications: Proven experience in information security leadership and a strong grasp of compliance frameworks.

The predicted salary is between 70000 - 90000 £ per year.

At Grant Thornton we do things differently – looking to the future, driving ambitious growth, and pioneering positive change in our industry. Providing audit, tax and advisory services, we empower clients through strategic insight, curiosity, and genuine partnership. We also empower our people with real opportunity, an inclusive culture, and work‑life balance.

Grant Thornton UK is a leading professional services firm providing audit, tax and advisory services. The firm is undergoing a significant technology‑led transformation, including the enterprise deployment of generative AI, a product‑centric IT operating model, and the modernisation of data platforms. Combined with the firm’s obligations to regulators, clients, and professional standards bodies, security governance and risk management is a critical discipline. The CISO will be the firm’s senior IT security authority, reporting directly to the CIO. The role bridges strategic risk ownership and hands‑on governance, ensuring security is embedded by design into platforms, products and processes. This is not a purely advisory role; the CISO will own the security framework, lead a team, and be a visible and influential voice at senior leadership level.

Key Responsibilities

  • Security Strategy and Governance: Develop and maintain the firm’s Information Security strategy, aligned to the IT strategy, CDO priorities and the broader digital transformation programme. Own and operate the Information Security Management System (ISMS), ensuring compliance with ISO 27001 and other applicable standards. Provide senior input to the risk committees on AI and information security, and represent security at the AI Governance Board. Maintain and report on a cyber risk register, providing regular risk posture updates to the CIO, CDO and relevant governance forums.
  • AI and Digital Transformation Security: Lead security governance for the firm’s generative AI programme. Assess and govern emerging risks from AI‑generated outputs, including artefact hosting, client‑facing microsites, and third‑party MCP integrations.
  • Risk, Compliance and Regulatory Obligations: Ensure the firm’s security posture meets obligations to professional standards bodies (ICAEW, FRC), client contractual requirements, and applicable regulation. Lead incident response governance, including classification, escalation, investigation and lessons‑learned processes for cyber and information security incidents. Oversee third‑party and supplier security risk management, including due diligence on SaaS platforms (ESM, GRC, LMS, HR systems) and cloud infrastructure providers. Support or lead engagement with cyber insurers, clients, external auditors and any regulatory enquiries related to information security.
  • Security Culture and Awareness: Drive a security‑aware culture across the firm, developing and maintaining the training and awareness programme so it is engaging, practical and proportionate. Champion a ‘secure by design’ mindset across IT, the digital team and the wider business, particularly as new products and platforms are introduced.
  • Leadership and Stakeholder Engagement: Lead, manage and develop the security function, including GRC, security engineering and awareness roles. Act as the primary escalation point and senior authority for all security matters, providing clear and credible advice to the CIO, CDO and firm leadership. Represent Grant Thornton UK in external forums, industry bodies and client conversations where security governance or assurance is relevant. Build influence and effective working relationships with the CISO community across the Grant Thornton International network.

Essential Experience

  • Proven experience as a CISO or senior information security leader in a professional services, financial services or similarly regulated environment.
  • Demonstrable track record of developing and operating an ISMS, managing a cyber risk register, and reporting to senior leadership and governance forums.
  • Hands‑on experience governing AI platforms from a security and compliance perspective, including data governance, audit logging and acceptable use.
  • Experience owning DLP controls, incident response processes and third‑party security risk management in a cloud‑first environment.
  • Strong grasp of relevant compliance frameworks: ISO 27001, NIST CSF, UK GDPR, and professional services regulatory obligations.

Desirable Experience

  • Familiarity with generative AI platforms, LLM governance, and emerging risks from AI‑generated content and tool integrations (MCP, API gateways).
  • Experience with CrowdStrike or equivalent EDR/SIEM platforms, including integration with compliance logging pipelines.
  • Exposure to Microsoft Fabric, Databricks or similar data platform environments.
  • Experience operating within a Big Four or Top Ten professional services firm, including understanding of client confidentiality obligations and engagement letter governance.

Qualifications

  • CISSP, CISM, or equivalent professional certification.
  • ISO 27001 Lead Implementer or Auditor (desirable).
  • Degree in Information Technology, Cybersecurity, Computer Science or a related discipline, or equivalent professional experience.

Benefits

In addition to a competitive salary and reward package, you’ll also get tailored development programmes and access to coaching, flexible bank holidays, benefits including pension, life assurance and private medical, additional holiday purchasing and health benefits, and more.

How We Work

We have a trust‑based way of working, driven by responsible people who have the best interests of our firm and our clients at heart. Our framework gives flexibility in where, how and when we work to deliver the best results for our clients, whilst helping you keep a balance between work and life.

Chief Information Security Officer in Edinburgh employer: Grant Thornton UK

At Grant Thornton, we pride ourselves on fostering an inclusive culture that empowers our employees to thrive both personally and professionally. As a Chief Information Security Officer in London, you will be at the forefront of our ambitious technology-led transformation, with access to tailored development programmes, flexible working options, and a supportive environment that values your unique contributions. Join us in redefining the future of our industry while enjoying a competitive benefits package that prioritises work-life balance and personal growth.

Grant Thornton UK

Contact Details:

Grant Thornton UK Recruitment Team

We think you need these skills to ace Chief Information Security Officer in Edinburgh

Information Security Management System (ISMS)
ISO 27001
Cyber Risk Management
AI Governance
Incident Response Management
Third-Party Security Risk Management
Data Governance