At a Glance
- Tasks: Lead cybersecurity initiatives and protect information assets in a dynamic environment.
- Company: Join Mecsia, a leading UK provider transforming the technical inspection and engineering services industry.
- Benefits: Competitive salary, bonus incentives, hybrid working, and comprehensive benefits package.
- Why this job: Make a real impact on cybersecurity while working with cutting-edge Microsoft security technologies.
- Qualifications: Proven experience in cybersecurity management and strong knowledge of Microsoft 365 security tools.
- Other info: Be part of an ambitious growth strategy with excellent career development opportunities.
The predicted salary is between 80000 - 100000 ÂŁ per year.
Company Overview
Mecsia is a leading UK provider of technical inspection, maintenance, and engineering services, aiming to transform the industry with a âLocal Service, National Reachâ approach. The company has grown significantly through organic expansion and strategic acquisitions, serving large clients across commercial offices, healthcare, and educational facilities. Under private equity ownership since 2020, Mecsia has expanded to approximately 1,200 employees, including 700 engineers. In 2024, Mecsia was acquired by Synova, recognised as the PE house of the year for four of the last seven years, and supports an ambitious growth strategy through service excellence and further acquisitions.
Remote role with some travel
This role is based remotely with occasional travel.
About The Role
The Head of IT Security is responsible for establishing and maintaining the enterprise vision, strategy, and program to ensure information assets and technologies are adequately protected. This role leads the organisationâs cybersecurity initiatives, risk management, and compliance efforts, ensuring alignment with business objectives. It combines strategic security leadership with handsâon oversight of tooling, suppliers, controls, and assurance activities. The position will act as the organisationâs dayâtoâday security authority, working closely with IT, engineering, operations, and thirdâparty security partners.
One of the main ambitions of the Group is to bring all Group companies to Cyber Essentials Plus level and to obtain ISO 27001 accreditation. The Head of Information Security will lead and drive this initiative, focusing on Microsoftâcentric security architectures, outsourced SOC management, and security governance and compliance (GDPR, Cyber Essentials Plus, ISO 27001).
Key Responsibilities
- Define, maintain, and execute Mecsiaâs information security strategy, aligned with business growth and risk appetite.
- Own security policies, standards, and control frameworks across the group.
- Provide regular security risk reporting to the CIO and senior leadership team.
- Act as the organisationâs primary security design authority.
- Own and optimise the Microsoft security stack, including Microsoft Defender (Endpoint, Identity, Office 365, Cloud Apps), Microsoft Sentinel (SIEM / SOAR), Entra ID (Conditional Access, Identity Protection), and Intune / MDM for mobile and endpoint security.
- Ensure security controls are proportionate for a mixed workforce (mobileâonly users and desktop/laptop users).
- Act as service owner for the outsourced 24/7 SOC (Microsoft Sentinelâbased).
- Define useâcases, alerting thresholds, escalation paths, and response playbooks.
- Oversee supplier performance, SLAs, and continuous improvement.
- Coordinate incident response across internal teams and external partners.
- Own security architecture and policy oversight for Cato SASE.
- Ensure effective integration between network security, identity, endpoint, and SIEM tooling.
- Work closely with infrastructure and cloud teams to ensure secureâbyâdesign solutions.
- Own and maintain compliance with GDPR (in collaboration with Legal / DPO where applicable).
- Obtain and maintain Cyber Essentials Plus accreditation.
- Obtain and maintain ISO 27001 accreditation (ISMS operation, audits, continuous improvement).
- Manage risk registers, DPIAs, supplier security assessments, and audit findings.
- Lead internal and external audits and remediation activities.
- Own and test incident response plans, playbooks, and escalation models.
- Coordinate response to security incidents, including regulatory and customer communications where required.
- Support business continuity and disaster recovery planning from a security perspective.
- Act as a trusted advisor to IT, operations, and senior management.
- Provide pragmatic security guidance to nonâtechnical stakeholders.
- Lead security awareness and training initiatives across the organisation.
Skills And Experience
Essential:
- Proven experience in an Information Security Manager / Cyber Security Manager role.
- Strong handsâon experience with Microsoft 365 security tooling, especially Defender and Sentinel.
- Experience working with outsourced SOC services and MSSPs.
- Solid understanding of GDPR, including DPIAs and incident reporting.
- Practical experience delivering and maintaining Cyber Essentials Plus.
- Experience operating or contributing to an ISO 27001 ISMS.
- Strong knowledge of identity, endpoint, network, and cloud security principles.
- Experience supporting environments with mobileâfirst and frontline workers.
Preferred:
- Experience in multiâentity or acquisitive organisations.
- Familiarity with SASE platforms (especially Cato Networks).
- Knowledge of NCSC / NIST / CIS security frameworks.
- Experience working in regulated or safetyâcritical environments.
Qualifications & Certifications (desirable)
- CISSP, CISM, or equivalent.
- ISO 27001 Lead Implementer / Auditor.
- Microsoft Security certifications (SCâ200, SCâ300, SCâ400, etc.).
Personal attributes
- Pragmatic and riskâbased (not âcheckbox securityâ).
- Comfortable balancing strategic leadership with operational oversight.
- Able to influence without authority and work crossâfunctionally.
- Calm and structured under pressure during incidents.
- Strong written and verbal communication skills.
Salary & package
ÂŁ80,000 â ÂŁ100,000 (depending on experience). Bonus / performance incentives. Pension and benefits. Hybrid working.
Equal Opportunity Employer
We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, colour, sex, age, national origin, religion, sexual orientation, gender identity, status as a veteran, and basis of disability.
Need more info? Yasmin will answer your questions.
Head of IT Security employer: Mecsia
Contact Detail:
Mecsia Recruiting Team
StudySmarter Expert Advice đ¤Ť
We think this is how you could land Head of IT Security
â¨Tip Number 1
Network like a pro! Reach out to people in the industry, attend relevant events, and connect with potential colleagues on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
â¨Tip Number 2
Prepare for interviews by researching Mecsia and its recent developments. Understand their approach to IT security and be ready to discuss how your experience aligns with their goals, especially around Cyber Essentials Plus and ISO 27001.
â¨Tip Number 3
Showcase your hands-on experience with Microsoft security tools during interviews. Be specific about your achievements and how you've optimised security measures in previous roles. This will demonstrate your capability to lead Mecsia's security initiatives.
â¨Tip Number 4
Donât forget to apply through our website! Itâs the best way to ensure your application gets noticed. Plus, it shows youâre genuinely interested in being part of the Mecsia team.
We think you need these skills to ace Head of IT Security
Some tips for your application đŤĄ
Tailor Your CV: Make sure your CV is tailored to the Head of IT Security role. Highlight your experience with Microsoft security tools and any relevant certifications. We want to see how your skills align with our needs!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about cybersecurity and how you can contribute to Mecsia's goals. Keep it engaging and relevant to the job description.
Showcase Your Achievements: Donât just list your responsibilities; showcase your achievements in previous roles. Did you lead a successful security initiative or improve compliance? We love to see quantifiable results that demonstrate your impact!
Apply Through Our Website: We encourage you to apply through our website for a smoother application process. It helps us keep track of your application and ensures you donât miss out on any important updates from us!
How to prepare for a job interview at Mecsia
â¨Know Your Stuff
Make sure you brush up on your knowledge of Microsoft security tools, especially Defender and Sentinel. Be ready to discuss how you've used these in past roles and how they can be leveraged at Mecsia.
â¨Understand the Compliance Landscape
Familiarise yourself with GDPR, Cyber Essentials Plus, and ISO 27001. Prepare to explain how you've navigated compliance challenges in previous positions and how you plan to lead Mecsia towards these accreditations.
â¨Showcase Your Leadership Skills
As the Head of IT Security, you'll need to demonstrate your ability to lead cross-functional teams. Think of examples where you've influenced stakeholders without direct authority and be ready to share those stories.
â¨Prepare for Scenario Questions
Expect questions about incident response and risk management. Prepare to discuss specific incidents you've managed, your approach to developing incident response plans, and how you ensure business continuity during crises.