At a Glance
- Tasks: Lead cyber security and privacy initiatives to protect Nando's customers and staff.
- Company: Join Nando's, a vibrant and innovative brand in the hospitality sector.
- Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
- Other info: Dynamic role with a focus on collaboration and continuous learning.
- Why this job: Make a real impact on cyber security while working with a passionate team.
- Qualifications: 5+ years in information security, with leadership experience and strong communication skills.
The predicted salary is between 80000 - 100000 £ per year.
The Head of Cyber Security & Privacy is accountable for implementing and maintaining information security across Nando's UKI's operations, protecting customers and Nandocas whilst enabling the business to operate securely. This role ensures security policies, standards and practices agreed with and set by the Group CISO are effectively embedded across restaurants, digital platforms, supply chain and support functions within the Nando's UKI. The role is a mixture of working with peers and the CISO to set standards and policies and assuring those in market. This individual is also the Data Protection Officer for Nando's UKI.
Reports to: UKI Technology Director
Works closely with: Group CISO (for guidance, standards, and frameworks).
Accountable for: UKI cyber security posture, compliance and assurance.
Works closely with: the UKI Chief Risk Officer, the Head of Product & Delivery- Technology Platforms.
Security Implementation & Operations
- Understand Group security Architecture and Implement Group information security policies and standards across Nando's UKI.
- Manage day-to-day security operations including monitoring, threat detection and incident response.
- Coordinate with the Security Operations Centre on Nando's UKI-specific threats and incidents.
- Maintain the Nando's UKI cyber security risk register and elevate significant risks.
- Conduct security assessments of Nando's UKI systems, suppliers and processes.
- Act as approver for the Data Protection Impact Assessment process.
Incident Response
- Act as Nando's UKI incident commander for cyber security incidents.
- Coordinate response with Group CISO for major incidents.
- Document and report incidents following Group standards.
- Implement lessons learned and track remediation actions.
Nando's UKI Stakeholder Engagement
- Build relationships with Nando's UKI leadership (Tech, People, Ops, Risk, Legal, Supply Chain).
- Ensure security is embedded in Nando's UKI initiatives, projects and training.
- Support the Nando's UKI CEO to understand and prioritise cyber security.
- Translate technical security risks into business impact for Nando's UKI stakeholders.
Security Culture & Awareness
- Deliver security awareness training to Nando's UKI teams using Group materials.
- Make security engaging and relevant to restaurant teams and support office staff.
- Act as the face of security in the Nando's UKI – visible, approachable and credible.
- Communicate security in line with Nando's values and tone of voice.
- Maintain knowledge of the evolving threat landscape, relevant regulatory requirements, and industry standards applicable to Nando's (e.g. ISO 27001 and NIST).
- Keep abreast of emerging risks related to technology, data privacy, and cyber security.
- Actively engage with reputable industry bodies, publications, and peer networks, and apply relevant insights to continuously assess whether the organisation's security posture, policies and controls remain fit for purpose.
Third‑Party & Vendor Management
- Assess security risks of Nando's UKI‑specific suppliers and vendors.
- Work with Procurement to ensure security requirements in supplier contracts.
- Monitor ongoing compliance of third parties with security standards.
- Escalate significant third‑party risks to Group CISO.
Compliance & Audit
- Ensure and demonstrate Nando's UKI compliance with Group security policies and relevant legislation (e.g. GDPR, local data protection laws).
- Coordinate Nando's UKI participation in security audits and assessments.
- Maintain evidence and documentation for compliance reporting.
- Support Group CISO with regulatory reviews affecting the Nando's UKI.
Architecture & Projects
- Review and approve security requirements for Nando's UKI technology initiatives.
- Ensure secure configuration of Nando's UKI systems and infrastructure.
- Work with Group CISO to implement identity and access management standards.
- Support secure deployment of the Global Nando's Platform in the Nando's UKI.
Data Security
- Implement data classification and data lifecycle management practices.
- Ensure sensitive data is appropriately protected across the Nando's UKI.
- Monitor and report on data security metrics.
- Investigate and remediate data security incidents; Nando's UKI leadership understands and actively supports security priorities.
- Clean audit outcomes against Group security standards.
- Security embedded in all major Nando's UKI projects and initiatives.
- Effective incident response demonstrated through exercises and/or real incidents.
- High engagement rates with security awareness programmes.
Ongoing
- Nando's UKI consistently meets Group security metrics and KPIs.
- Strong working relationship with Group CISO and other Nando's UKI Heads of Security.
- Proactive identification and mitigation of Nando's UKI‑specific risks.
- Security seen as an enabler rather than a blocker.
- Positive feedback from Nando's UKI stakeholders on security support and guidance.
Essential
- 5+ years experience in information security, with at least 2 years in a leadership role.
- Strong practical knowledge of security operations, incident response and risk management.
- Experience implementing security frameworks (NIST CSF, ISO 27001 or similar).
- Ability to influence stakeholders without direct authority.
- Excellent communication skills – can explain technical risks to non‑technical audiences.
- Understanding of GDPR and data protection principles.
- Experience working in multi‑site or retail/hospitality environments.
Desirable
- Relevant certifications (CISSP, CISM, Security+, CEH or similar).
- Experience with cloud security (AWS, Azure, GCP).
- Up‑to‑date knowledge of security tools (SIEM, EDR, vulnerability management).
- Understanding of secure development practices.
- Experience in a franchised or multi‑site organisation.
Head of Cyber Security & Privacy in London employer: Nando's Chickenland Limited
Contact Detail:
Nando's Chickenland Limited Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Head of Cyber Security & Privacy in London
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the cyber security field. Attend industry events, webinars, or even local meetups. The more people you know, the better your chances of landing that dream job!
✨Tip Number 2
Show off your skills! Create a portfolio or a personal website showcasing your projects, achievements, and any relevant certifications. This is your chance to shine and demonstrate what you can bring to the table.
✨Tip Number 3
Prepare for interviews like it’s game day! Research Nando's UKI, understand their security needs, and be ready to discuss how your experience aligns with their goals. Practice common interview questions and have your own questions ready to show your interest.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who take the initiative to engage directly with us.
We think you need these skills to ace Head of Cyber Security & Privacy in London
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Head of Cyber Security & Privacy role. Highlight your experience in information security, especially in leadership roles, and showcase your knowledge of security frameworks like NIST CSF or ISO 27001.
Craft a Compelling Cover Letter: Your cover letter should tell us why you're the perfect fit for this role. Use specific examples from your past experiences that demonstrate your ability to manage security operations and engage with stakeholders effectively.
Showcase Your Communication Skills: Since you'll need to explain technical risks to non-technical audiences, make sure your application reflects your excellent communication skills. Use clear and concise language to convey your points.
Apply Through Our Website: We encourage you to apply through our website for a smoother application process. It’s the best way for us to receive your application and ensure it gets the attention it deserves!
How to prepare for a job interview at Nando's Chickenland Limited
✨Know Your Stuff
Make sure you brush up on the latest security frameworks like NIST CSF and ISO 27001. Be ready to discuss how you've implemented these in past roles, especially in a leadership capacity. This shows you're not just familiar with the theory but have practical experience too.
✨Speak Their Language
Prepare to explain complex security concepts in simple terms. You'll need to communicate effectively with non-technical stakeholders, so practice translating technical risks into business impacts. This will demonstrate your ability to bridge the gap between tech and business.
✨Show Your Leadership Skills
Highlight your experience in leading security operations and incident response teams. Share specific examples of how you've influenced stakeholders and driven security initiatives in multi-site environments. This will showcase your capability to lead and inspire others in a security context.
✨Engage with the Culture
Understand Nando's values and how they relate to security culture. Be prepared to discuss how you would make security engaging for restaurant teams and support staff. Showing that you can align security practices with the company’s ethos will set you apart.