Head of IT Security

Head of IT Security

Full-Time 80000 - 100000 ÂŁ / year (est.) No home office possible
Go Premium
M

At a Glance

  • Tasks: Lead cybersecurity initiatives and protect information assets in a dynamic environment.
  • Company: Join Mecsia, a leading UK provider transforming the technical inspection and engineering services industry.
  • Benefits: Competitive salary, bonus incentives, hybrid working, and comprehensive benefits package.
  • Why this job: Make a real impact on cybersecurity while working with cutting-edge Microsoft security technologies.
  • Qualifications: Proven experience in cybersecurity management and strong knowledge of Microsoft 365 security tools.
  • Other info: Be part of an ambitious growth strategy with excellent career development opportunities.

The predicted salary is between 80000 - 100000 ÂŁ per year.

Company Overview

Mecsia is a leading UK provider of technical inspection, maintenance, and engineering services, aiming to transform the industry with a ‘Local Service, National Reach’ approach. The company has grown significantly through organic expansion and strategic acquisitions, serving large clients across commercial offices, healthcare, and educational facilities. Under private equity ownership since 2020, Mecsia has expanded to approximately 1,200 employees, including 700 engineers. In 2024, Mecsia was acquired by Synova, recognised as the PE house of the year for four of the last seven years, and supports an ambitious growth strategy through service excellence and further acquisitions.

Remote role with some travel

This role is based remotely with occasional travel.

About The Role

The Head of IT Security is responsible for establishing and maintaining the enterprise vision, strategy, and program to ensure information assets and technologies are adequately protected. This role leads the organisation’s cybersecurity initiatives, risk management, and compliance efforts, ensuring alignment with business objectives. It combines strategic security leadership with hands‑on oversight of tooling, suppliers, controls, and assurance activities. The position will act as the organisation’s day‑to‑day security authority, working closely with IT, engineering, operations, and third‑party security partners.

One of the main ambitions of the Group is to bring all Group companies to Cyber Essentials Plus level and to obtain ISO 27001 accreditation. The Head of Information Security will lead and drive this initiative, focusing on Microsoft‑centric security architectures, outsourced SOC management, and security governance and compliance (GDPR, Cyber Essentials Plus, ISO 27001).

Key Responsibilities

  • Define, maintain, and execute Mecsia’s information security strategy, aligned with business growth and risk appetite.
  • Own security policies, standards, and control frameworks across the group.
  • Provide regular security risk reporting to the CIO and senior leadership team.
  • Act as the organisation’s primary security design authority.
  • Own and optimise the Microsoft security stack, including Microsoft Defender (Endpoint, Identity, Office 365, Cloud Apps), Microsoft Sentinel (SIEM / SOAR), Entra ID (Conditional Access, Identity Protection), and Intune / MDM for mobile and endpoint security.
  • Ensure security controls are proportionate for a mixed workforce (mobile‑only users and desktop/laptop users).
  • Act as service owner for the outsourced 24/7 SOC (Microsoft Sentinel‑based).
  • Define use‑cases, alerting thresholds, escalation paths, and response playbooks.
  • Oversee supplier performance, SLAs, and continuous improvement.
  • Coordinate incident response across internal teams and external partners.
  • Own security architecture and policy oversight for Cato SASE.
  • Ensure effective integration between network security, identity, endpoint, and SIEM tooling.
  • Work closely with infrastructure and cloud teams to ensure secure‑by‑design solutions.
  • Own and maintain compliance with GDPR (in collaboration with Legal / DPO where applicable).
  • Obtain and maintain Cyber Essentials Plus accreditation.
  • Obtain and maintain ISO 27001 accreditation (ISMS operation, audits, continuous improvement).
  • Manage risk registers, DPIAs, supplier security assessments, and audit findings.
  • Lead internal and external audits and remediation activities.
  • Own and test incident response plans, playbooks, and escalation models.
  • Coordinate response to security incidents, including regulatory and customer communications where required.
  • Support business continuity and disaster recovery planning from a security perspective.
  • Act as a trusted advisor to IT, operations, and senior management.
  • Provide pragmatic security guidance to non‑technical stakeholders.
  • Lead security awareness and training initiatives across the organisation.

Skills And Experience

Essential:

  • Proven experience in an Information Security Manager / Cyber Security Manager role.
  • Strong hands‑on experience with Microsoft 365 security tooling, especially Defender and Sentinel.
  • Experience working with outsourced SOC services and MSSPs.
  • Solid understanding of GDPR, including DPIAs and incident reporting.
  • Practical experience delivering and maintaining Cyber Essentials Plus.
  • Experience operating or contributing to an ISO 27001 ISMS.
  • Strong knowledge of identity, endpoint, network, and cloud security principles.
  • Experience supporting environments with mobile‑first and frontline workers.

Preferred:

  • Experience in multi‑entity or acquisitive organisations.
  • Familiarity with SASE platforms (especially Cato Networks).
  • Knowledge of NCSC / NIST / CIS security frameworks.
  • Experience working in regulated or safety‑critical environments.

Qualifications & Certifications (desirable)

  • CISSP, CISM, or equivalent.
  • ISO 27001 Lead Implementer / Auditor.
  • Microsoft Security certifications (SC‑200, SC‑300, SC‑400, etc.).

Personal attributes

  • Pragmatic and risk‑based (not “checkbox security”).
  • Comfortable balancing strategic leadership with operational oversight.
  • Able to influence without authority and work cross‑functionally.
  • Calm and structured under pressure during incidents.
  • Strong written and verbal communication skills.

Salary & package

£80,000 – £100,000 (depending on experience). Bonus / performance incentives. Pension and benefits. Hybrid working.

Equal Opportunity Employer

We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, colour, sex, age, national origin, religion, sexual orientation, gender identity, status as a veteran, and basis of disability.

Need more info? Yasmin will answer your questions.

Head of IT Security employer: Mecsia

Mecsia is an exceptional employer, offering a dynamic work culture that prioritises employee growth and development within the rapidly evolving field of IT security. With a commitment to service excellence and a focus on innovative cybersecurity initiatives, employees benefit from a supportive environment that encourages collaboration and professional advancement, all while enjoying the flexibility of remote work with occasional travel. The company's ambitious growth strategy, backed by private equity, ensures that team members are part of a forward-thinking organisation dedicated to achieving industry-leading standards in security compliance and governance.
M

Contact Detail:

Mecsia Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Head of IT Security

✨Tip Number 1

Network like a pro! Reach out to people in the industry, attend relevant events, and connect with potential colleagues on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

✨Tip Number 2

Prepare for interviews by researching Mecsia and its recent developments. Understand their approach to IT security and be ready to discuss how your experience aligns with their goals, especially around Cyber Essentials Plus and ISO 27001.

✨Tip Number 3

Showcase your hands-on experience with Microsoft security tools during interviews. Be specific about your achievements and how you've optimised security measures in previous roles. This will demonstrate your capability to lead Mecsia's security initiatives.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, it shows you’re genuinely interested in being part of the Mecsia team.

We think you need these skills to ace Head of IT Security

Information Security Management
Cybersecurity Initiatives
Risk Management
Compliance (GDPR, Cyber Essentials Plus, ISO 27001)
Microsoft 365 Security Tooling
Microsoft Defender
Microsoft Sentinel
SOC Management
Network Security
Cloud Security
Incident Response
Stakeholder Engagement
Security Awareness Training
ISO 27001 ISMS Operation
Pragmatic Security Guidance

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the Head of IT Security role. Highlight your experience with Microsoft security tools and any relevant certifications. We want to see how your skills align with our needs!

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about cybersecurity and how you can contribute to Mecsia's goals. Keep it engaging and relevant to the job description.

Showcase Your Achievements: Don’t just list your responsibilities; showcase your achievements in previous roles. Did you lead a successful security initiative or improve compliance? We love to see quantifiable results that demonstrate your impact!

Apply Through Our Website: We encourage you to apply through our website for a smoother application process. It helps us keep track of your application and ensures you don’t miss out on any important updates from us!

How to prepare for a job interview at Mecsia

✨Know Your Stuff

Make sure you brush up on your knowledge of Microsoft security tools, especially Defender and Sentinel. Be ready to discuss how you've used these in past roles and how they can be leveraged at Mecsia.

✨Understand the Compliance Landscape

Familiarise yourself with GDPR, Cyber Essentials Plus, and ISO 27001. Prepare to explain how you've navigated compliance challenges in previous positions and how you plan to lead Mecsia towards these accreditations.

✨Showcase Your Leadership Skills

As the Head of IT Security, you'll need to demonstrate your ability to lead cross-functional teams. Think of examples where you've influenced stakeholders without direct authority and be ready to share those stories.

✨Prepare for Scenario Questions

Expect questions about incident response and risk management. Prepare to discuss specific incidents you've managed, your approach to developing incident response plans, and how you ensure business continuity during crises.

Head of IT Security
Mecsia
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

M
  • Head of IT Security

    Full-Time
    80000 - 100000 ÂŁ / year (est.)
  • M

    Mecsia

    50-100
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>