Head of Cyber Security & Privacy in London

Head of Cyber Security & Privacy in London

London Full-Time 80000 - 100000 £ / year (est.) No working from home possible
nando's

At a Glance

  • Tasks: Lead cyber security and privacy initiatives to protect Nando's UKI operations.
  • Company: Join a vibrant team at Nando's, known for its inclusive culture.
  • Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
  • Other info: Dynamic role with significant career advancement potential.
  • Why this job: Make a real impact in safeguarding customer data and enhancing security culture.
  • Qualifications: 5+ years in information security with leadership experience required.

The predicted salary is between 80000 - 100000 £ per year.

The Head of Cyber Security & Privacy is accountable for implementing and maintaining information security across Nando's UKI's operations, protecting customers and Nandocas whilst enabling the business to operate securely. This role ensures security policies, standards and practices agreed with and set by the Group CISO are effectively embedded across restaurants, digital platforms, supply chain and support functions within the Nando's UKI.

This role involves working with peers and the CISO to set standards and policies and assuring those in market. This individual is also the Data Protection Officer for Nando's UKI.

Reporting & Accountability

  • Reports to: UKI Technology Director
  • Works closely with: Group CISO (for guidance, standards, and frameworks).
  • Accountable for: UKI cyber security posture, compliance and assurance.
  • Works closely with the UKI Chief Risk Officer
  • Works closely with the Head of Product & Delivery- Technology Platforms.

Key Responsibilities

Security Implementation & Operations

  • Understand Group security Architecture and Implement Group information security policies and standards across Nando's UKI.
  • Manage day-to-day security operations including monitoring, threat detection and incident response.
  • Coordinate with the Security Operations Centre on Nando's UKI-specific threats and incidents.
  • Maintain the Nando's UKI cyber security risk register and elevate significant risks.
  • Conduct security assessments of Nando's UKI systems, suppliers and processes.
  • Act as approver for the Data Protection Impact Assessment process.

Incident Response

  • Act as Nando's UKI incident commander for cyber security incidents.
  • Coordinate response with Group CISO for major incidents.
  • Document and report incidents following Group standards.
  • Implement lessons learned and track remediation actions.

Nando's UKI Stakeholder Engagement

  • Build relationships with Nando's UKI leadership (Tech, People, Ops, Risk, Legal, Supply Chain).
  • Ensure security is embedded in Nando's UKI initiatives, projects and training.
  • Support the Nando's UKI CEO to understand and prioritise cyber security.
  • Translate technical security risks into business impact for Nando's UKI stakeholders.

Security Culture & Awareness

  • Deliver security awareness training to Nando's UKI teams using Group materials.
  • Make security engaging and relevant to restaurant teams and support office staff.
  • Act as the face of security in the Nando's UKI - visible, approachable and credible.
  • Communicate security in line with Nando's values and tone of voice.
  • Maintain knowledge of the evolving threat landscape, relevant regulatory requirements, and industry standards applicable to Nando's (e.g. ISO 27001 and NIST).
  • Keep abreast of emerging risks related to technology, data privacy, and cyber security.
  • Actively engage with reputable industry bodies, publications, and peer networks, and apply relevant insights to continuously assess whether the organisation's security posture, policies, and controls remain fit for purpose.

Third-Party & Vendor Management

  • Assess security risks of Nando's UKI-specific suppliers and vendors.
  • Work with Procurement to ensure security requirements in supplier contracts.
  • Monitor ongoing compliance of third parties with security standards.
  • Escalate significant third-party risks to Group CISO.

Compliance & Audit

  • Ensure and demonstrate Nando's UKI compliance with Group security policies and relevant legislation (e.g. GDPR, local data protection laws).
  • Coordinate Nando's UKI participation in security audits and assessments.
  • Maintain evidence and documentation for compliance reporting.
  • Support Group CISO with regulatory reviews affecting the Nando's UKI.

Architecture & Projects

  • Review and approve security requirements for Nando's UKI technology initiatives.
  • Ensure secure configuration of Nando's UKI systems and infrastructure.
  • Work with Group CISO to implement identity and access management standards.
  • Support secure deployment of the Global Nando's Platform in the Nando's UKI.

Data Security

  • Implement data classification and data lifecycle management practices.
  • Ensure sensitive data is appropriately protected across the Nando's UKI.
  • Monitor and report on data security metrics.
  • Investigate and remediate data security incidents.

Skills & Qualifications

Essential

  • 5+ years experience in information security, with at least 2 years in a leadership role.
  • Strong practical knowledge of security operations, incident response and risk management.
  • Experience implementing security frameworks (NIST CSF, ISO 27001 or similar).
  • Ability to influence stakeholders without direct authority.
  • Excellent communication skills - can explain technical risks to non-technical audiences.
  • Understanding of GDPR and data protection principles.
  • Experience working in multi-site or retail/hospitality environments.

Desirable

  • Relevant certifications (CISSP, CISM, Security+, CEH or similar).
  • Experience with cloud security (AWS, Azure, GCP).
  • Up to date knowledge of security tools (SIEM, EDR, vulnerability management).
  • Understanding of secure development practices.
  • Experience in a franchised or multi-site organisation.

What Success Looks Like

Year 1

  • Nando's UKI leadership understands and actively supports security priorities.
  • Clean audit outcomes against Group security standards.
  • Security embedded in all major Nando's UKI projects and initiatives.
  • Effective incident response demonstrated through exercises and/or real incidents.
  • High engagement rates with security awareness programmes.

Ongoing

  • Nando's UKI consistently meets Group security metrics and KPIs.
  • Strong working relationship with Group CISO and other Nando's UKI Heads of Security.
  • Proactive identification and mitigation of Nando's UKI-specific risks.
  • Security seen as an enabler rather than a blocker.
  • Positive feedback from Nando's UKI stakeholders on security support and guidance.

Head of Cyber Security & Privacy in London employer: nando's

Nando's UKI is an exceptional employer that prioritises a culture of security and collaboration, making it an ideal place for the Head of Cyber Security & Privacy to thrive. With competitive salaries, comprehensive training programmes, and a commitment to employee growth, Nando's fosters an environment where innovation and security awareness are at the forefront. Located in a vibrant setting, employees benefit from engaging with diverse teams while ensuring the safety of customers and colleagues alike.

nando's

Contact Details:

nando's Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Head of Cyber Security & Privacy in London

Tip Number 1

Network like a pro! Get out there and connect with folks in the cyber security field. Attend industry events, webinars, or even local meetups. The more people you know, the better your chances of landing that dream job!

Tip Number 2

Show off your skills! Create a portfolio or a personal website showcasing your projects, certifications, and any relevant experience. This is your chance to shine and demonstrate what you can bring to the table.

Tip Number 3

Prepare for interviews like it’s game day! Research Nando's UKI, understand their security needs, and be ready to discuss how your experience aligns with their goals. Practice common interview questions and have your own questions ready to show your interest.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining the team at Nando's UKI.

We think you need these skills to ace Head of Cyber Security & Privacy in London

Information Security Management
Incident Response
Risk Management
Security Operations
Stakeholder Engagement
Data Protection Compliance
Security Framework Implementation

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Head of Cyber Security & Privacy role. Highlight your experience in information security, especially in leadership roles, and showcase your knowledge of security frameworks like NIST or ISO 27001.

Craft a Compelling Cover Letter:Your cover letter should tell us why you're the perfect fit for this role. Share specific examples of how you've implemented security policies and engaged with stakeholders in previous positions. Make it personal and engaging!

Showcase Your Communication Skills:Since you'll need to explain technical risks to non-technical audiences, demonstrate your communication skills in your application. Use clear language and avoid jargon where possible to show us you can bridge that gap.

Apply Through Our Website:We encourage you to apply through our website for the best chance of being noticed. It’s the easiest way for us to keep track of your application and ensure it gets to the right people!

How to prepare for a job interview at nando's

Know Your Stuff

Make sure you brush up on your knowledge of security frameworks like NIST and ISO 27001. Be ready to discuss how you've implemented these in past roles, especially in a leadership capacity. This will show that you’re not just familiar with the theory but have practical experience too.

Speak Their Language

Since you'll be translating technical risks for non-technical stakeholders, practice explaining complex concepts in simple terms. Use relatable examples from your previous work to demonstrate how security impacts business operations, making it clear that you understand both sides.

Show Your Leadership Skills

Prepare to share specific instances where you've led a team through a security incident or implemented a new policy. Highlight your ability to influence without direct authority and how you’ve built relationships across departments to embed security into the company culture.

Stay Current

Keep yourself updated on the latest trends in cyber security and data protection laws, especially GDPR. Mention any recent developments or threats you've been following, and be ready to discuss how they could impact Nando's UKI specifically.