Head of Cyber Security & Privacy

Head of Cyber Security & Privacy

Full-Time 80000 - 100000 £ / year (est.) No working from home possible
nando's

At a Glance

  • Tasks: Lead cyber security initiatives and protect Nando's UKI operations from threats.
  • Company: Join the vibrant Nando's team, known for its inclusive culture and delicious food.
  • Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
  • Other info: Dynamic role with a focus on innovation and collaboration across various teams.
  • Why this job: Make a real impact in safeguarding customer data and enhancing security culture.
  • Qualifications: 5+ years in information security with leadership experience; strong communication skills required.

The predicted salary is between 80000 - 100000 £ per year.

The Head of Cyber Security & Privacy is accountable for implementing and maintaining information security across Nando's UKI's operations, protecting customers and Nandocas whilst enabling the business to operate securely. This role ensures security policies, standards and practices agreed with and set by the Group CISO are effectively embedded across restaurants, digital platforms, supply chain and support functions within the Nando's UKI.

This role involves working with peers and the CISO to set standards and policies and assuring those in market. This individual is also the Data Protection Officer for Nando's UKI.

Reporting & Accountability

  • Reports to: UKI Technology Director
  • Works closely with: Group CISO (for guidance, standards, and frameworks).
  • Accountable for: UKI cyber security posture, compliance and assurance.
  • Works closely with the UKI Chief Risk Officer
  • Works closely with the Head of Product & Delivery- Technology Platforms.

Key Responsibilities

Security Implementation & Operations

  • Understand Group security Architecture and Implement Group information security policies and standards across Nando's UKI.
  • Manage day-to-day security operations including monitoring, threat detection and incident response.
  • Coordinate with the Security Operations Centre on Nando's UKI-specific threats and incidents.
  • Maintain the Nando's UKI cyber security risk register and elevate significant risks.
  • Conduct security assessments of Nando's UKI systems, suppliers and processes.
  • Act as approver for the Data Protection Impact Assessment process.

Incident Response

  • Act as Nando's UKI incident commander for cyber security incidents.
  • Coordinate response with Group CISO for major incidents.
  • Document and report incidents following Group standards.
  • Implement lessons learned and track remediation actions.

Nando's UKI Stakeholder Engagement

  • Build relationships with Nando's UKI leadership (Tech, People, Ops, Risk, Legal, Supply Chain).
  • Ensure security is embedded in Nando's UKI initiatives, projects and training.
  • Support the Nando's UKI CEO to understand and prioritise cyber security.
  • Translate technical security risks into business impact for Nando's UKI stakeholders.

Security Culture & Awareness

  • Deliver security awareness training to Nando's UKI teams using Group materials.
  • Make security engaging and relevant to restaurant teams and support office staff.
  • Act as the face of security in the Nando's UKI - visible, approachable and credible.
  • Communicate security in line with Nando's values and tone of voice.
  • Maintain knowledge of the evolving threat landscape, relevant regulatory requirements, and industry standards applicable to Nando's (e.g. ISO 27001 and NIST).
  • Keep abreast of emerging risks related to technology, data privacy, and cyber security.
  • Actively engage with reputable industry bodies, publications, and peer networks, and apply relevant insights to continuously assess whether the organisation's security posture, policies, and controls remain fit for purpose.

Third-Party & Vendor Management

  • Assess security risks of Nando's UKI-specific suppliers and vendors.
  • Work with Procurement to ensure security requirements in supplier contracts.
  • Monitor ongoing compliance of third parties with security standards.
  • Escalate significant third-party risks to Group CISO.

Compliance & Audit

  • Ensure and demonstrate Nando's UKI compliance with Group security policies and relevant legislation (e.g. GDPR, local data protection laws).
  • Coordinate Nando's UKI participation in security audits and assessments.
  • Maintain evidence and documentation for compliance reporting.
  • Support Group CISO with regulatory reviews affecting the Nando's UKI.

Architecture & Projects

  • Review and approve security requirements for Nando's UKI technology initiatives.
  • Ensure secure configuration of Nando's UKI systems and infrastructure.
  • Work with Group CISO to implement identity and access management standards.
  • Support secure deployment of the Global Nando's Platform in the Nando's UKI.

Data Security

  • Implement data classification and data lifecycle management practices.
  • Ensure sensitive data is appropriately protected across the Nando's UKI.
  • Monitor and report on data security metrics.
  • Investigate and remediate data security incidents.

Skills & Qualifications

Essential

  • 5+ years experience in information security, with at least 2 years in a leadership role.
  • Strong practical knowledge of security operations, incident response and risk management.
  • Experience implementing security frameworks (NIST CSF, ISO 27001 or similar).
  • Ability to influence stakeholders without direct authority.
  • Excellent communication skills - can explain technical risks to non-technical audiences.
  • Understanding of GDPR and data protection principles.
  • Experience working in multi-site or retail/hospitality environments.

Desirable

  • Relevant certifications (CISSP, CISM, Security+, CEH or similar).
  • Experience with cloud security (AWS, Azure, GCP).
  • Up to date knowledge of security tools (SIEM, EDR, vulnerability management).
  • Understanding of secure development practices.
  • Experience in a franchised or multi-site organisation.

What Success Looks Like

Year 1

  • Nando's UKI leadership understands and actively supports security priorities.
  • Clean audit outcomes against Group security standards.
  • Security embedded in all major Nando's UKI projects and initiatives.
  • Effective incident response demonstrated through exercises and/or real incidents.
  • High engagement rates with security awareness programmes.

Ongoing

  • Nando's UKI consistently meets Group security metrics and KPIs.
  • Strong working relationship with Group CISO and other Nando's UKI Heads of Security.
  • Proactive identification and mitigation of Nando's UKI-specific risks.
  • Security seen as an enabler rather than a blocker.
  • Positive feedback from Nando's UKI stakeholders on security support and guidance.

Head of Cyber Security & Privacy employer: nando's

Nando's UKI is an exceptional employer that prioritises a culture of security and collaboration, making it an ideal place for the Head of Cyber Security & Privacy to thrive. With competitive salaries, comprehensive training programmes, and a commitment to employee growth, Nando's fosters an environment where innovation and security awareness are at the forefront. Located in a vibrant setting, employees benefit from engaging with diverse teams while ensuring the safety of customers and colleagues alike.

nando's

Contact Details:

nando's Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Head of Cyber Security & Privacy

Tip Number 1

Network like a pro! Get out there and connect with folks in the cyber security field. Attend industry events, webinars, or even local meetups. The more people you know, the better your chances of landing that dream job!

Tip Number 2

Show off your skills! Create a personal project or contribute to open-source initiatives related to cyber security. This not only boosts your portfolio but also gives you something tangible to discuss during interviews.

Tip Number 3

Prepare for those interviews! Research Nando's UKI and understand their specific security challenges. Tailor your responses to show how your experience aligns with their needs. Remember, confidence is key!

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, we love seeing candidates who are proactive about their job search!

We think you need these skills to ace Head of Cyber Security & Privacy

Information Security Management
Incident Response
Risk Management
Security Operations
Stakeholder Engagement
Data Protection Compliance
Security Framework Implementation

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Head of Cyber Security & Privacy role. Highlight your experience in information security, especially in leadership roles, and showcase your knowledge of security frameworks like NIST or ISO 27001.

Craft a Compelling Cover Letter:Your cover letter should tell us why you're the perfect fit for this role. Share specific examples of how you've implemented security policies and engaged with stakeholders in previous positions. Make it personal and engaging!

Showcase Your Communication Skills:Since you'll need to explain technical risks to non-technical audiences, demonstrate your communication skills in your application. Use clear language and avoid jargon where possible to show us you can bridge that gap.

Apply Through Our Website:We encourage you to apply through our website for the best chance of being noticed. It’s the easiest way for us to keep track of your application and ensure it gets to the right people!

How to prepare for a job interview at nando's

Know Your Stuff

Make sure you have a solid understanding of information security principles, especially those related to GDPR and data protection. Brush up on the NIST CSF and ISO 27001 frameworks, as these will likely come up in conversation.

Show Your Leadership Skills

As this role is a leadership position, be prepared to discuss your experience in managing teams and influencing stakeholders. Share specific examples of how you've led security initiatives or improved security posture in previous roles.

Understand the Business

It's crucial to translate technical security risks into business impacts. Be ready to explain how security measures can enable Nando's UKI to operate securely while still achieving its business goals. This shows you understand the bigger picture.

Engage with Security Culture

Demonstrate your ability to foster a security culture within an organisation. Talk about any past experiences where you've delivered security awareness training or engaged with teams to make security relevant and engaging.