At a Glance
- Tasks: Lead and develop Moneybox's information security strategy and programme.
- Company: Join Moneybox, an award-winning wealth management platform transforming lives.
- Benefits: Competitive salary, flexible working, and opportunities for professional growth.
- Other info: Dynamic role with a focus on innovation, technology, and team collaboration.
- Why this job: Make a real impact on security while shaping the future of wealth management.
- Qualifications: Proven experience in information security leadership and strategic decision-making.
The predicted salary is between 80000 - 100000 £ per year.
hackajob is collaborating with Moneybox to connect them with exceptional professionals for this role.
About Moneybox
At Moneybox, our mission is to give everyone the means to get more out of life. We're guided by our belief that wealth isn't about the money, it's about the means to more - more freedom, opportunities, possibilities, and peace of mind. Moneybox is an award-winning wealth management platform, helping over one and a half million people build wealth throughout their lives, whether they’re saving and investing, buying their first home, or planning for retirement.
Job Brief
Moneybox is looking for a Head of Information Security to lead and mature our information security function. Reporting to the Engineering Director, this role will own Moneybox’s Information Security Programme and be accountable for reducing security risk across our people, systems, products and third‑party ecosystem as the business continues to scale. This is a hands‑on leadership role. The successful candidate will need to think strategically, set direction and influence senior stakeholders whilst also being close enough to the detail to get things done. We are looking for someone who can build a small, high‑performing and nimble security function, using technology, automation and AI to increase the breadth, quality and pace of what the team can achieve. The role will suit an experienced information security leader who is pragmatic, commercially aware and focused on reducing meaningful risk, not creating unnecessary bureaucracy or replicating a big‑bank security model.
What you'll do
- Owning and delivering Moneybox’s information security strategy, roadmap and operating model.
- Leading the ongoing development of Moneybox’s Information Security Programme, using NIST CSF as the practical risk‑management framework while aligning with ISO 27001 for governance, control maturity and assurance.
- Reducing real security risk across Moneybox’s technology estate, people processes, suppliers and products.
- Building a small, effective and high‑leverage security function that uses technology, automation and AI to scale its impact.
- Providing clear, practical security leadership to senior stakeholders, including regular reporting on security posture, risks, incidents and priorities.
- Making proportionate, risk‑based decisions that support business growth while protecting customers and the organisation.
- Developing, maintaining and embedding practical information security policies, standards and procedures.
- Leading security awareness and training programmes that improve behaviours and strengthen Moneybox’s security culture.
- Owning Moneybox’s security incident response framework, ensuring the business is prepared to identify, contain, respond to and recover from security incidents effectively.
- Overseeing vulnerability management, including scanning, remediation, patching and risk‑based prioritisation.
- Leading third‑party security risk management for key vendors, partners and technology providers.
- Defining and tracking security metrics that focus on risk reduction and meaningful outcomes, not vanity reporting.
- Partnering with Engineering and Product teams to ensure security is built into systems, services and ways of working.
- Monitoring emerging threats, regulatory expectations and industry practice, then applying them pragmatically to Moneybox’s environment.
- Continuously improving the security function without adding unnecessary complexity or bureaucracy.
Who you are
- A strategic but hands‑on information security leader.
- A doer who is comfortable owning outcomes directly, not just delegating, advising or writing papers.
- Pragmatic and risk‑led with strong judgement on where security effort will have the greatest impact.
- Comfortable working in a small, nimble team where leverage comes from focus, automation, technology and strong prioritisation.
- Able to separate meaningful security risk from theoretical or low‑value control activity.
- Commercially aware, with the ability to balance security, customer experience, regulation and delivery.
- Clear and concise with senior stakeholders, able to translate security issues into business impact.
- Collaborative and able to influence across Engineering, Compliance, Legal, Product, Workplace Technology and the wider business.
- Strong understanding of current and emerging threats, and how to manage them proportionately in a fast‑moving organisation.
- Interested in how AI and automation can improve security operations, assurance, monitoring, reporting and decision‑making.
- Motivated by building a high‑quality security function that fits Moneybox, rather than importing a large‑enterprise or big‑bank model.
Head of Information Security employer: Limelight Health
At Limelight Health, we pride ourselves on fostering a collaborative and innovative work culture that empowers our employees to thrive. As a remote-first company, we offer flexible working arrangements, competitive benefits, and ample opportunities for professional growth, making it an ideal environment for those passionate about driving technological advancements in healthcare. Join us to be part of a forward-thinking team that values your expertise and encourages you to lead the way in AI-driven solutions.