At a Glance
- Tasks: Lead cyber security and privacy initiatives to protect Nando's customers and staff.
- Company: Join Nando's, a vibrant and innovative brand committed to security.
- Benefits: Competitive salary, flexible working, and opportunities for professional growth.
- Other info: Dynamic role with strong career progression and collaboration across teams.
- Why this job: Make a real impact in safeguarding data and enhancing security culture.
- Qualifications: 5+ years in information security with leadership experience required.
The predicted salary is between 80000 - 100000 £ per year.
The Head of Cyber Security & Privacy is accountable for implementing and maintaining information security across Nando's UKI's operations, protecting customers and Nandocas whilst enabling the business to operate securely. This role ensures security policies, standards and practices agreed with and set by the Group CISO are effectively embedded across restaurants, digital platforms, supply chain and support functions within the Nando's UKI. The role is a mixture of working with peers and the CISO to set standards and policies and assuring those in market. This individual is also the Data Protection Officer for Nando's UKI.
Reports to: UKI Technology Director
Works closely with: Group CISO (for guidance, standards, and frameworks).
Accountable for: UKI cyber security posture, compliance and assurance.
Works closely with: UKI Chief Risk Officer, Head of Product & Delivery- Technology Platforms.
Security Implementation & Operations
- Understand Group security Architecture and Implement Group information security policies and standards across Nando's UKI.
- Manage day-to-day security operations including monitoring, threat detection and incident response.
- Coordinate with the Security Operations Centre on Nando's UKI-specific threats and incidents.
- Maintain the Nando's UKI cyber security risk register and elevate significant risks.
- Conduct security assessments of Nando's UKI systems, suppliers and processes.
- Act as approver for the Data Protection Impact Assessment process.
Incident Response
- Act as Nando's UKI incident commander for cyber security incidents.
- Coordinate response with Group CISO for major incidents.
- Document and report incidents following Group standards.
- Implement lessons learned and track remediation actions.
Nando's UKI Stakeholder Engagement
- Build relationships with Nando's UKI leadership (Tech, People, Ops, Risk, Legal, Supply Chain).
- Ensure security is embedded in Nando's UKI initiatives, projects and training.
- Support the Nando's UKI CEO to understand and prioritise cyber security.
- Translate technical security risks into business impact for Nando's UKI stakeholders.
Security Culture & Awareness
- Deliver security awareness training to Nando's UKI teams using Group materials.
- Make security engaging and relevant to restaurant teams and support office staff.
- Act as the face of security in the Nando's UKI – visible, approachable and credible.
- Communicate security in line with Nando's values and tone of voice.
- Maintain knowledge of the evolving threat landscape, relevant regulatory requirements, and industry standards applicable to Nando's (e.g. ISO 27001 and NIST).
- Keep abreast of emerging risks related to technology, data privacy, and cyber security.
- Actively engage with reputable industry bodies, publications, and peer networks, and apply relevant insights to continuously assess whether the organisation's security posture, policies and controls remain fit for purpose.
Third‑Party & Vendor Management
- Assess security risks of Nando's UKI‑specific suppliers and vendors.
- Work with Procurement to ensure security requirements in supplier contracts.
- Monitor ongoing compliance of third parties with security standards.
- Escalate significant third‑party risks to Group CISO.
Compliance & Audit
- Ensure and demonstrate Nando's UKI compliance with Group security policies and relevant legislation (e.g. GDPR, local data protection laws).
- Coordinate Nando's UKI participation in security audits and assessments.
- Maintain evidence and documentation for compliance reporting.
- Support Group CISO with regulatory reviews affecting the Nando's UKI.
Architecture & Projects
- Review and approve security requirements for Nando's UKI technology initiatives.
- Ensure secure configuration of Nando's UKI systems and infrastructure.
- Work with Group CISO to implement identity and access management standards.
- Support secure deployment of the Global Nando's Platform in the Nando's UKI.
Data Security
- Implement data classification and data lifecycle management practices.
- Ensure sensitive data is appropriately protected across the Nando's UKI.
- Monitor and report on data security metrics.
- Investigate and remediate data security incidents; Nando's UKI leadership understands and actively supports security priorities.
- Clean audit outcomes against Group security standards.
- Security embedded in all major Nando's UKI projects and initiatives.
- Effective incident response demonstrated through exercises and/or real incidents.
- High engagement rates with security awareness programmes.
Ongoing
- Nando's UKI consistently meets Group security metrics and KPIs.
- Strong working relationship with Group CISO and other Nando's UKI Heads of Security.
- Proactive identification and mitigation of Nando's UKI‑specific risks.
- Security seen as an enabler rather than a blocker.
- Positive feedback from Nando's UKI stakeholders on security support and guidance.
Essential
- 5+ years experience in information security, with at least 2 years in a leadership role.
- Strong practical knowledge of security operations, incident response and risk management.
- Experience implementing security frameworks (NIST CSF, ISO 27001 or similar).
- Ability to influence stakeholders without direct authority.
- Excellent communication skills – can explain technical risks to non‑technical audiences.
- Understanding of GDPR and data protection principles.
- Experience working in multi‑site or retail/hospitality environments.
Desirable
- Relevant certifications (CISSP, CISM, Security+, CEH or similar).
- Experience with cloud security (AWS, Azure, GCP).
- Up‑to‑date knowledge of security tools (SIEM, EDR, vulnerability management).
- Understanding of secure development practices.
- Experience in a franchised or multi‑site organisation.
Head of Cyber Security & Privacy employer: Nando's Chickenland Limited
Contact Detail:
Nando's Chickenland Limited Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Head of Cyber Security & Privacy
✨Tip Number 1
Network like a pro! Attend industry events, webinars, and meetups to connect with folks in the cyber security space. You never know who might be looking for someone just like you!
✨Tip Number 2
Show off your skills! Create a personal project or contribute to open-source initiatives that showcase your expertise in cyber security. This not only builds your portfolio but also gets you noticed by potential employers.
✨Tip Number 3
Prepare for interviews like it’s game day! Research Nando's UKI, understand their security challenges, and come armed with ideas on how you can help. Tailor your responses to show how your experience aligns with their needs.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining the team at Nando's UKI.
We think you need these skills to ace Head of Cyber Security & Privacy
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Head of Cyber Security & Privacy role. Highlight your experience in information security, especially in leadership roles, and showcase how you've implemented security frameworks like NIST or ISO 27001.
Craft a Compelling Cover Letter: Your cover letter should tell us why you're the perfect fit for Nando's UKI. Use it to explain your understanding of cyber security challenges in the retail sector and how you can help protect our customers and Nandocas.
Showcase Your Communication Skills: Since you'll need to explain technical risks to non-technical audiences, make sure your application reflects your ability to communicate clearly. Use straightforward language and avoid jargon where possible.
Apply Through Our Website: We encourage you to apply through our website for a smoother process. It helps us keep track of your application and ensures you don’t miss any important updates from us!
How to prepare for a job interview at Nando's Chickenland Limited
✨Know Your Stuff
Make sure you brush up on the latest security frameworks like NIST CSF and ISO 27001. Be ready to discuss how you've implemented these in past roles, especially in a leadership capacity. This shows you're not just familiar with the theory but have practical experience too.
✨Speak Their Language
Prepare to explain complex security concepts in simple terms. You'll need to communicate effectively with non-technical stakeholders, so practice translating technical risks into business impacts. This will demonstrate your ability to bridge the gap between tech and business.
✨Show Your Leadership Skills
Highlight your experience in leading teams and managing security operations. Be ready to share examples of how you've influenced stakeholders without direct authority. This is crucial for a role that requires collaboration across various departments.
✨Stay Current
Keep yourself updated on the evolving threat landscape and data protection regulations like GDPR. Mention any recent trends or incidents you've followed, and be prepared to discuss how they could impact Nando's UKI. This shows you're proactive and engaged in the field.