At a Glance
- Tasks: Lead and enhance Information Security across the UK and Europe, ensuring compliance and risk management.
- Company: Join a forward-thinking company prioritising cybersecurity and information security excellence.
- Benefits: Competitive salary, career development opportunities, and a dynamic work environment.
- Why this job: Make a significant impact on global security strategies while collaborating with top industry leaders.
- Qualifications: 12+ years in Information Security leadership, strong communication, and project management skills required.
- Other info: Opportunity to shape the future of cybersecurity in a supportive and innovative team.
The predicted salary is between 80000 - 100000 £ per year.
We have an exciting permanent opportunity for a Head of Information Security based in the UK. Your role is leading the Information Security business partner in the UK and Europe for all Cabot security organizational activities. You will prioritize activities to ensure the ongoing effectiveness of Information Security and Cybersecurity controls, working with risk and control owners to evaluate control design, effectiveness, and standards. The primary areas of focus include ongoing compliance and regulatory activities, operational performance, and enterprise information and cyber risk.
This position requires an individual that can effectively balance the elements of each of these activities, while keeping the overall program on track and in alignment with the Global InfoSec strategy and objectives. The Head of Information Security will not only be forward-looking to ensure new requirements are planned but will work with leaders across the business to ensure the goals of Encore and Cabot are met securely, and with compliance to all rules and regulations that may apply.
Key Accountabilities & Responsibilities
- Member of Encore InfoSec leadership team, acting in support of Cabot Group.
- Accountable for the overall security service received by the Business Unit(s) from internal resources, shared services and external partners.
- Responsible for executive committee reporting and strategic decision-making/communications.
- Support Cabot BU leaders who have specific InfoSec responsibilities (including under UK FCA Senior Manager & Certification Regime (SMCR) and Ireland CBI Senior Executive Accountability Regime (SEAR)) with delivery of their accountabilities by undertaking effective risk management, as defined by the company policy, and escalating issues to enable sound and prudent management of the firm, including timely resolution of Risk Events, Internal Audit, Risk and Compliance Monitoring actions.
- Demonstrable delivery of regulatory responsibilities, including the completion of assigned learning and timely and accurate completion of documentation associated with ongoing Fitness and Propriety (F&P) activity.
- Manage team members that are direct reports as well as those that are matrixed, helping develop people in their careers and inspiring them to deliver excellence, supporting day-to-day InfoSec responsibilities.
- Maintain awareness of emerging cybersecurity insurance requirements and prioritize related capability maturity activities within the business.
- Support to ongoing program capability that aligns and supports ISO 27001, SOC2, PCI, SOX404, GDPR, CCPA, and other UK, EU, US, India, and Costa Rica requirements.
- Manage and track progress against enterprise Information Security strategy and program goals.
- Working closely with the CISO, IT Risk and Compliance team and InfoSec Program Office to develop and implement strategies for governance and compliance related to corporate-wide security initiatives, operations, and engineering.
- Advise, educate key stakeholders, executives, and business partners on InfoSec trends and technologies.
- Collaborate with the Enterprise Risk team and other specialists including Privacy and Compliance to help optimize the Information Risk management related standards, tools and processes.
- Coordinate security risk measurements, key indicators, and established metrics across BUs.
- Provide oversight and guidance for periodic internal and customer security assessments to ensure compliance with information security policies and established security controls.
- Ensure continual collaboration between InfoSec and cross-functional IT and wider business teams to ensure security controls have been designed effectively and are working as intended.
- Support the CISO with consolidation and harmonisation of security policies, standards, processes and tools.
Person specification
- 12+ years experience with Information Security preferably in a leadership role with executive and board reporting responsibilities.
- Must have 10+ years experience across common industry security policy areas, including, but not limited to ISO, NIST, COSO, COBIT, PCI, FFIEC, SOX, SSAE16, and others.
- Minimum 7+ years of experience in Information Security with an emphasis on IT audit, IT risk management, and/or IT compliance.
- Ability to translate technical risk and vulnerability data into business risk, and effectively communicate potential impacts to the business.
- Excellent analytical, technical and internal assessment skills.
- Excellent organizational and documentation skills.
- Strong project management skills are highly desired.
- Proven ability to manage priorities & deadlines and to work independently in a highly dynamic and diverse environment with multiple concurrent work streams.
- Strong business sense with an ability to balance "business value" vs "security risk".
- Good communication skills with an ability to build strong narratives to highlight the importance of security to employees internally and customers/shareholders externally, including both technical and non-technical audiences.
- Ability to engage and effectively communicate with Executive Management, Legal, Risk, 3rd-party, and IT teams.
- Ability to develop and document policies, standards, and guidelines.
- Excellent oral and written communication skills.
- Professional certification in information security or compliance (for example, CISSP, CISM, or CISA) required or achievable.
Head of Information Security employer: Midland Credit Management
Contact Detail:
Midland Credit Management Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Head of Information Security
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the industry. Attend events, webinars, or even local meetups. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your expertise! Create a personal brand online by sharing insights on platforms like LinkedIn. Post articles or comment on relevant topics to get noticed by recruiters and hiring managers looking for someone with your skills.
✨Tip Number 3
Prepare for interviews like it’s game day! Research the company, understand their InfoSec challenges, and come armed with questions that show you’re genuinely interested in how you can contribute to their goals.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive about their job search!
We think you need these skills to ace Head of Information Security
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Head of Information Security role. Highlight your experience in leading security initiatives and managing compliance, as these are key for us at StudySmarter.
Craft a Compelling Cover Letter: Your cover letter should tell us why you're the perfect fit for this position. Share specific examples of how you've balanced security and business needs in previous roles, and don’t forget to show your passion for information security!
Showcase Your Achievements: When detailing your experience, focus on your achievements rather than just responsibilities. Use metrics where possible to demonstrate how you’ve improved security measures or compliance in past roles.
Apply Through Our Website: We encourage you to apply through our website for a smoother application process. It helps us keep track of your application and ensures you don’t miss any important updates from us!
How to prepare for a job interview at Midland Credit Management
✨Know Your Stuff
Make sure you brush up on the key areas of information security relevant to the role. Familiarise yourself with ISO 27001, NIST, and other compliance standards mentioned in the job description. Being able to discuss these frameworks confidently will show that you're not just a candidate, but a knowledgeable leader.
✨Showcase Your Leadership Skills
As a Head of Information Security, you'll need to demonstrate your ability to lead teams and manage projects effectively. Prepare examples from your past experiences where you've successfully led initiatives or resolved complex issues. This will help illustrate your capability to balance business value with security risk.
✨Communicate Clearly
You’ll be engaging with various stakeholders, including executives and technical teams. Practice explaining complex security concepts in simple terms. This will not only highlight your communication skills but also your ability to bridge the gap between technical and non-technical audiences.
✨Prepare for Scenario Questions
Expect questions that assess your problem-solving abilities in real-world scenarios. Think about potential risks and how you would handle them, especially in relation to compliance and regulatory activities. Having a few well-thought-out responses ready can set you apart from other candidates.