Head of Secure Access & Trust

Head of Secure Access & Trust

Full-Time 90000 - 110000 £ / year (est.) No working from home possible
M

At a Glance

  • Tasks: Lead the Secure Access & Trust strategy, ensuring secure access to M&S technology and information.
  • Company: Join M&S, a forward-thinking retailer committed to innovation and inclusivity.
  • Benefits: Enjoy a 20% discount, competitive holidays, and tailored training from day one.
  • Other info: Be part of a diverse team driving change in the retail industry.
  • Why this job: Make a real impact on security and trust in a dynamic retail environment.
  • Qualifications: Proven experience in Identity & Access Management and strong technical leadership skills.

The predicted salary is between 90000 - 110000 £ per year.

As Head of Secure Access & Trust, you are accountable for the enterprise capability that enables trusted access to M&S technology and information.

You ensure the right people, systems, devices and AI agents have secure, proportionate and seamless access to the resources they require, enabling business growth, modern engineering, operational resilience and effective management of cyber risk.

You define the strategic direction and evolution of the Secure Access & Trust capability, establishing the governance, platform strategy, trust architecture and operating model that underpin how trust is established, managed and assured across M&S.

Through this capability, you provide secure, resilient and reusable platform services that enable engineering teams to build secure solutions by default.

This is a retained leadership role accountable for capability outcomes.

You set direction, govern standards, manage enterprise risk and assure delivery through strategic partners, ensuring Secure Access & Trust continually evolves to meet changing business, technology and regulatory needs.

Working closely with the CTO, CISO, Enterprise Architecture, Engineering and business leaders, you strengthen M&S's security posture while reducing complexity, improving developer and colleague experience, and enabling technology to be consumed securely at enterprise scale.

Due to high interest, this role may close earlier than advertised.

What you'll do

  • Define and lead the Secure Access & Trust strategy, owning the roadmap, operating model and governance framework to align with business objectives, security policies and regulatory requirements.
  • Own enterprise identity and trust governance, including identity lifecycle management, access governance, privileged access, segregation of duties and trust standards across people, devices, applications, services and AI agents.
  • Lead the Secure Access & Trust platform, ensuring authentication, authorisation, directory, remote access and privileged access services are secure, resilient, scalable and support cloud-native and AI-enabled environments.
  • Enable secure engineering and business delivery through reusable platform capabilities, APIs, architectural standards and self-service services that improve developer experience and embed security by design.
  • Drive cyber risk reduction, operational resilience and supplier performance, overseeing business continuity, major incident response, managed service governance and the development of a high-performing capability focused on measurable outcomes.

Proven experience defining and leading enterprise Identity & Access Management (IAM) and Zero Trust strategies within complex, large-scale organisations.

  • Deep expertise in identity governance, privileged access management, authentication, authorisation and access controls across cloud, on-premise and emerging AI-enabled environments.
  • Strong technical leadership experience managing secure access and identity platforms, ensuring services are resilient, scalable and aligned to modern engineering practices.
  • Demonstrated ability to balance cyber risk, regulatory compliance and operational resilience while enabling business growth, innovation and secure delivery.
  • Excellent stakeholder management and influencing skills, with experience leading multidisciplinary teams, suppliers and senior business leaders to deliver measurable outcomes.

Working at M&S means being part of something bigger - helping to deliver quality, value and service to millions of customers every day.

We're inclusive, fast-moving and always evolving, with a strong sense of purpose and a focus on doing the right thing.

  • Here are just a few of the benefits that make working here even more rewarding:
  • 20% colleague discount on all M&S products and many third-party brands for you and someone in your household, available once you've completed your probation
  • Competitive holiday allowance with the option to buy more
  • Discretionary bonus schemes linked to your performance and ours
  • Strong pension and life assurance to help plan for the future
  • Tailored induction and training to support your development from day one
  • Exclusive perks and savings through our M&S Choices portal
  • Market-leading family policies, including parental, adoption and neonatal leave
  • 24/7 wellbeing support, including virtual GP access and mental health services
  • One paid volunteer day a year to support a cause that matters to you
  • Everyone's welcome

We are ambitious about the future of retail.

We're disrupting, innovating and leading the industry into a more conscientious, inspiring digital era.

We're transforming how we work together and offering our most exciting opportunities yet.

Marks & Spencer strives to be an inclusive organisation, trusted and admired by our colleagues, customers and suppliers.

Join us and make change happen.

We are committed to building diverse and representative teams, where everyone can bring their whole selves to work and be at their best.

We support each other and work together to win together.

If you feel you'd benefit from any support or reasonable adjustments during any stage of the recruitment process, please don't hesitate to let us know when completing your application.

This information will be picked up by our team, so we can try and put steps in place to help you be at your best through this process.

#J-18808-Ljbffr

Head of Secure Access & Trust employer: Marks and Spencer plc (UK)

Marks and Spencer plc is an exceptional employer, offering a vibrant work culture that thrives on teamwork and collaboration. Located in Kingston upon Thames, employees benefit from a dynamic retail environment where they can grow their skills in fashion and customer service while enjoying opportunities for personal development and career advancement. With a commitment to providing a remarkable shopping experience, Marks and Spencer fosters a supportive atmosphere that values passion and adaptability.

M

Contact Details:

Marks and Spencer plc (UK) Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Head of Secure Access & Trust

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Marks and Spencer plc (UK), love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Marks and Spencer plc (UK)

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Marks and Spencer plc (UK). Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Head of Secure Access & Trust

Secure Access & Trust Strategy
Identity & Access Management (IAM)
Zero Trust Strategies
Identity Governance
Privileged Access Management
Authentication and Authorisation
Access Controls

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Marks and Spencer plc (UK) insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Marks and Spencer plc (UK) that you’re committed to staying ahead in the game.

How to prepare for a job interview at Marks and Spencer plc (UK)

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Marks and Spencer plc (UK) to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Marks and Spencer plc (UK).

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.