Head of Information Security

Head of Information Security

Full-Time 80000 - 100000 £ / year (est.) Home office (partial)
hackajob

At a Glance

  • Tasks: Lead and enhance Moneybox's information security strategy and operations.
  • Company: Join an award-winning wealth management platform with a mission to empower individuals.
  • Benefits: Enjoy competitive pay, hybrid work, personal development budget, and health perks.
  • Other info: Collaborative culture with opportunities for career growth and innovation.
  • Why this job: Make a real impact in a fast-growing company while shaping its security landscape.
  • Qualifications: Proven experience in information security leadership and risk management.

The predicted salary is between 80000 - 100000 £ per year.

About Moneybox

At Moneybox, our mission is to give everyone the means to get more out of life. We're guided by our belief that wealth isn't about the money, it's about the means to more - more freedom, opportunities, possibilities, and peace of mind. Moneybox is an award-winning wealth management platform, helping over one and a half million people build wealth throughout their lives, whether they’re saving and investing, buying their first home, or planning for retirement.

Job Brief

Moneybox is looking for a Head of Information Security to lead and mature our information security function. Reporting to the Engineering Director, this role will own Moneybox’s Information Security Programme and be accountable for reducing security risk across our people, systems, products and third‑party ecosystem as the business continues to scale. This is a hands‑on leadership role. The successful candidate will need to think strategically, set direction and influence senior stakeholders whilst also being close enough to the detail to get things done. We are looking for someone who can build a small, high‑performing and nimble security function, using technology, automation and AI to increase the breadth, quality and pace of what the team can achieve. The role will suit an experienced information security leader who is pragmatic, commercially aware and focused on reducing meaningful risk, not creating unnecessary bureaucracy or replicating a big‑bank security model.

What you’ll do

  • Owning and delivering Moneybox’s information security strategy, roadmap and operating model.
  • Leading the ongoing development of Moneybox’s Information Security Programme, using NIST CSF as the practical risk‑management framework while aligning with ISO 27001 for governance, control maturity and assurance.
  • Reducing real security risk across Moneybox’s technology estate, people processes, suppliers and products.
  • Building a small, effective and high‑leverage security function that uses technology, automation and AI to scale its impact.
  • Providing clear, practical security leadership to senior stakeholders, including regular reporting on security posture, risks, incidents and priorities.
  • Making proportionate, risk‑based decisions that support business growth while protecting customers and the organisation.
  • Developing, maintaining and embedding practical information security policies, standards and procedures.
  • Leading security awareness and training programmes that improve behaviours and strengthen Moneybox’s security culture.
  • Owning Moneybox’s security incident response framework, ensuring the business is prepared to identify, contain, respond to and recover from security incidents effectively.
  • Overseeing vulnerability management, including scanning, remediation, patching and risk‑based prioritisation.
  • Leading third‑party security risk management for key vendors, partners and technology providers.
  • Defining and tracking security metrics that focus on risk reduction and meaningful outcomes, not vanity reporting.
  • Partnering with Engineering and Product teams to ensure security is built into systems, services and ways of working.
  • Monitoring emerging threats, regulatory expectations and industry practice, then applying them pragmatically to Moneybox’s environment.
  • Continuously improving the security function without adding unnecessary complexity or bureaucracy.

Who you are

  • A strategic but hands‑on information security leader.
  • A doer who is comfortable owning outcomes directly, not just delegating, advising or writing papers.
  • Pragmatic and risk‑led with strong judgement on where security effort will have the greatest impact.
  • Comfortable working in a small, nimble team where leverage comes from focus, automation, technology and strong prioritisation.
  • Able to separate meaningful security risk from theoretical or low‑value control activity.
  • Commercially aware, with the ability to balance security, customer experience, regulation and delivery.
  • Clear and concise with senior stakeholders, able to translate security issues into business impact.
  • Collaborative and able to influence across Engineering, Compliance, Legal, Product, Workplace Technology and the wider business.
  • Strong understanding of current and emerging threats, and how to manage them proportionately in a fast‑moving organisation.
  • Interested in how AI and automation can improve security operations, assurance, monitoring, reporting and decision‑making.
  • Motivated by building a high‑quality security function that fits Moneybox, rather than importing a large‑enterprise or big‑bank model.

Experience & skills

  • Proven experience leading or significantly contributing to an information security function.
  • Strong working knowledge of risk‑based security management and the NIST Cyber Security Framework.
  • Experience developing and delivering information security strategy, roadmaps, policies and controls.
  • Practical knowledge of security technologies and business systems, including identity and access management, SIEM, endpoint security, cloud security, vulnerability management and remote working technologies.
  • Experience using technology, automation or AI to improve security outcomes or operational efficiency.
  • Experience managing security risk in cloud‑based environments, ideally including Azure.
  • Strong understanding of third‑party security risk management.
  • Experience with incident response planning, testing and improvement.
  • Experience reporting security risks, controls and metrics to senior management.
  • Strong communication skills, with the ability to translate technical security issues into clear business risks, recommendations and trade‑offs for senior stakeholders.
  • Good understanding of financial services security, risk and regulatory expectations.
  • Demonstrated leadership skills with the ability to influence, collaborate and drive change across teams.
  • Excellent written and spoken English.
  • Relevant professional certifications such as CISSP, CISM or CRISC are desirable, but practical judgement and delivery experience matter more.

What’s in it for you

  • Opportunity to join a fast‑growing, award‑winning and super ambitious company.
  • Work with a friendly team of highly motivated individuals.
  • Be in an environment where you are listened to and can actually have an impact.
  • Thriving collaborative and inclusive company culture.
  • Competitive remuneration package.
  • Company pension scheme.
  • Company bonus scheme.
  • Hybrid working environment.
  • Home office furniture allowance.
  • Personal annual learning and development budget.
  • Private medical insurance.
  • Health cash plan (cashback on visits to the dentist & opticians etc).
  • Cycle‑to‑work scheme.
  • Wellhub subscription to a variety of gyms and wellbeing apps.
  • Enhanced parental pay & leave.
  • 25 days holiday + bank holidays with additional days added with length of service.

This is a hybrid role. Our office is in London, by the Oxo Tower.

Head of Information Security employer: hackajob

At Moneybox, we pride ourselves on being an exceptional employer, offering a dynamic and inclusive work culture that empowers our employees to make a real impact. As the Head of Information Security, you'll join a fast-growing, award-winning team in a vibrant London location, where your contributions will be valued and supported through competitive remuneration, a personal development budget, and a range of health and wellbeing benefits. With a focus on collaboration and innovation, we provide a unique opportunity for professional growth while ensuring a healthy work-life balance in a hybrid working environment.

hackajob

Contact Details:

hackajob Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Head of Information Security

Tip Number 1

Network like a pro! Reach out to your connections in the industry, attend relevant events, and engage with professionals on platforms like LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Prepare for interviews by researching Moneybox and its culture. Understand their mission and values, and think about how your experience aligns with their goals. This will help you stand out as a candidate who truly gets what they’re about.

Tip Number 3

Showcase your skills through practical examples. Be ready to discuss specific projects or challenges you've tackled in the past that relate to information security. This hands-on approach will demonstrate your capability and readiness for the role.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in being part of the Moneybox team.

We think you need these skills to ace Head of Information Security

Information Security Leadership
NIST Cyber Security Framework
ISO 27001
Risk Management
Security Incident Response
Vulnerability Management
Third-Party Security Risk Management

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Head of Information Security role. Highlight your experience with risk management frameworks like NIST CSF and ISO 27001, as well as any hands-on leadership roles you've had. We want to see how your skills align with our mission at Moneybox!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how you can contribute to our team. Be sure to mention your pragmatic approach and how you’ve successfully reduced security risks in previous roles.

Showcase Your Achievements:When detailing your experience, focus on specific achievements rather than just responsibilities. Did you implement a new security protocol that reduced incidents? Share those metrics! We love seeing tangible results that demonstrate your impact.

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows you’re keen on joining our awesome team at Moneybox!

How to prepare for a job interview at hackajob

Know Your Stuff

Make sure you have a solid understanding of the NIST Cyber Security Framework and ISO 27001. Be ready to discuss how you've applied these frameworks in your previous roles, especially in terms of risk management and governance.

Show Your Leadership Skills

Prepare examples that showcase your hands-on leadership style. Talk about how you've built effective teams and influenced senior stakeholders, focusing on real outcomes rather than just delegating tasks.

Be Pragmatic and Commercially Aware

Demonstrate your ability to balance security needs with business growth. Share instances where you've made risk-based decisions that supported organisational objectives while protecting customers.

Communicate Clearly

Practice translating complex security issues into clear business impacts. Be prepared to explain how you've reported security risks and metrics to senior management in a way that resonates with them.