At a Glance
- Tasks: Lead our cyber security strategy and protect critical business services in a fast-paced fintech environment.
- Company: Join ISX Financial, a leading fintech company revolutionising payment solutions.
- Benefits: Competitive salary, career growth, and a chance to shape the future of finance.
- Other info: Dynamic team culture focused on collaboration and continuous improvement.
- Why this job: Make a real impact by safeguarding sensitive data and driving innovation in cyber security.
- Qualifications: 8+ years in cyber security with leadership experience in regulated environments.
The predicted salary is between 70000 - 80000 £ per year.
ISX Financial is a leading financial technology company that provides secure and efficient payment solutions.
We are looking for talented individuals to join our team and help us continue to innovate in the fintech industry.
ISX Financial UK Ltd is a UK FCA Authorised e Money Institution (under the Electronic Money Regulations 2011, Firm Reference 901034, for the issuing of electronic money) that provides transactional banking solutions and also multi-currency online payment solutions to businesses around the world.
ISX Financial UK Ltd is a wholly owned subsidiary of Xryma Plc and operates independently of its parent.
Join us and be part of a team that is committed to delivering exceptional customer service and innovative solutions shaping the future of finance.
The Role
We are looking for an experienced and hands-on Head of Cyber Security to lead our cyber security function within a fast-growing, FCA-regulated fintech environment.
You will be responsible for defining and delivering our cyber security strategy, protecting critical business services, and ensuring our security posture supports both business growth and regulatory compliance.
You are required to combine strong technical expertise with proven leadership, governance, and stakeholder management skills, enabling you to translate cyber risk into business decisions while fostering a security-first culture across the organisation.
You will work closely with IT, Engineering, Dev Ops, Product Management and Risk teams to ensure cyber security is embedded into every stage of technology delivery and business operations.
This is a hands-on leadership role, requiring a strategic thinker who remains technically credible and actively engaged in solving complex security challenges alongside their team.
This role offers an excellent opportunity to shape and mature the cyber security capability within a growing FCA-regulated fintech business, while making a significant contribution to the organisations' long-term success.
Key Responsibilities
- Developing, implementing and continually improving the organisation's cyber security strategy, roadmap and governance framework.
- Maintaining compliance with FCA regulatory expectations and international security standards including PCI DSS, ISO 27001, DORA, PSD2, NIST and CIS Controls.
- Building and maintaining an effective cyber security governance framework, including policies, standards, risk management processes and security metrics.
- Leading enterprise cyber risk management, maintaining security risk registers, assessing emerging threats, and providing regular reporting to senior leadership and Board committees.
- Protecting sensitive customer and business data by implementing effective identity, access management and data protection controls.
- Leading the design and implementation of secure cloud, infrastructure and application architectures in partnership with Engineering, Dev Ops, Product and Infrastructure teams.
- Embedding security throughout the software development lifecycle by implementing secure-by-design principles, threat modelling, code security, automated testing and Dev Sec Ops practices.
- Leading cyber incident response, crisis management, threat intelligence, vulnerability management and continuous security monitoring activities.
- Driving operational resilience initiatives, including Business Continuity, Disaster Recovery planning, cyber resilience testing and tabletop exercises.
- Managing third-party cyber risk, supplier assurance and security due diligence for strategic technology partners.
- Defining meaningful security KPIs and KRIs, reporting organisational cyber risk and security performance to executive leadership and Board stakeholders.
- Managing relationships with regulators, auditors, certification bodies and external security partners.
- Leading, mentoring and developing the cyber security team while fostering a strong security culture across the organisation.
- Acting as the organisations' trusted cyber security advisor, contributing to business informed decisions.
- Minimum 8 years' experience in cyber security, with at least 3–5 years leading cyber security teams within financial services, fintech, payments, banking or another highly regulated environment.
- Demonstrable experience working within an FCA-regulated organization or a similarly regulated financial services environment, with a strong understanding of regulatory expectations, operational resilience and cyber risk management.
- Proven experience developing and delivering a cyber security strategy aligned to business objectives, regulatory requirements and industry best practice.
- Experience implementing and maintaining cyber security governance frameworks, policies, standards, procedures and security roadmaps.
- Experience managing security programs aligned to recognized frameworks such as PCI DSS, ISO 27001, NIST CSF, CIS Controls, SOC 2, DORA, PSD2 and SWIFT CSCF (where applicable).
- Experience leading regulatory, customer and certification audits, including managing relationships with regulators, external auditors and internal audit functions.
- Excellent knowledge of English - verbal and written communication skills.
- Nice-to-have Requirements
- Strong understanding of secure software development, Dev Sec Ops and application security, including secure SDLC, CI/CD security, SAST, DAST, Software Composition Analysis (SCA), container security, API security and threat modelling.
- Strong technical knowledge of Identity and Access Management (IAM), Identity Providers (Id P), Single Sign-On (SSO), Privileged Access Management (PAM), Conditional Access and Zero Trust security principles.
- Experience implementing and optimising enterprise security technologies including SIEM, EDR/XDR, vulnerability management, endpoint protection, cloud security tooling, security monitoring and threat intelligence platforms.
- Strong understanding of cyber threat frameworks including MITRE ATT&CK, Cyber Kill Chain and the evolving cyber threat landscape affecting financial institutions.
- Experience managing third-party and supplier cyber security risk, including due diligence, security assessments and ongoing assurance activities.
- Demonstrated ability to recruit, mentor and develop high-performing cyber security teams while promoting collaboration across Technology, Product and Business functions.
- Excellent communication skills with the ability to present technical concepts, security risks and strategic recommendations to executive leadership, Board members and non-technical stakeholders.
- *****
All applications will be treated with the strictest confidence.
Personal information provided by applicants will be used solely for recruitment and selection purposes and will be handled in accordance with applicable data protection and privacy laws.
Due to the high volume of applications received, only shortlisted candidates will be contacted.
To find out more about how we process your data, please read our privacy policy (Privacy Notice & Disclosure section) at
*****
Please note that our company works with recruitment agencies on a pre-approved basis only.
A recruitment agency that wishes to submit candidate profiles or resumes for consideration must obtain prior written consent from our HR team.
We do not accept unsolicited resumes from recruitment agencies, and we will not be responsible for any fees related to unsolicited CVs.
#J-18808-Ljbffr
Head of Cyber Security (UK based) employer: ISX Financial®
ISX Financial is an exceptional employer, offering a dynamic work environment in the heart of the UK's fintech sector. With a strong commitment to employee growth and a culture that prioritises innovation and collaboration, we empower our team members to lead impactful projects in cyber security while ensuring compliance with regulatory standards. Join us to be part of a forward-thinking organisation that values your expertise and fosters a security-first mindset across all operations.
StudySmarter Expert Advice🤫
We think this is how you could land Head of Cyber Security (UK based)
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including ISX Financial®, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through ISX Financial®
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at ISX Financial®. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Head of Cyber Security (UK based)
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at ISX Financial® insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to ISX Financial® that you’re committed to staying ahead in the game.
How to prepare for a job interview at ISX Financial®
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at ISX Financial® to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at ISX Financial®.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.