Head of Information Security (Deputy CISO) in London

Head of Information Security (Deputy CISO) in London

London Full-Time 63000 - 77000 £ / year (est.) No working from home possible
N

At a Glance

  • Tasks: Lead and shape NewDay's Information Security strategy and operations.
  • Company: Join a dynamic team at NewDay, a leader in financial services.
  • Benefits: Competitive salary, inclusive culture, and opportunities for professional growth.
  • Other info: Be part of a diverse team that values authenticity and inclusivity.
  • Why this job: Make a real impact on security while driving innovation and growth.
  • Qualifications: Proven experience in Information Security leadership within regulated environments.

The predicted salary is between 63000 - 77000 £ per year.

NewDay is recruiting a brand-new Deputy Chief Information Security Officer role to help shape, lead and strengthen our enterprise-wide security capability. Reporting directly to the CISO, you will be the senior operational leader for Information Security and the CISO’s principal deputy. You will translate our security strategy into clear priorities, measurable outcomes and consistent execution across security operations, governance, risk, architecture, engineering, identity, third-party security, resilience and assurance. This is a high-impact leadership opportunity with significant enterprise visibility. You will represent Information Security at senior forums, provide clear insight on cyber and technology risk, and ensure our security organisation remains aligned with NewDay’s risk appetite, regulatory responsibilities, customer commitments and commercial ambitions.

What you’ll be responsible for:

  • Lead the Information Security function
  • Lead, develop and bring together NewDay’s Information Security teams, creating clear priorities, strong delivery and an accountable, high-performing culture.
  • Act as the CISO’s delegate across executive, risk, governance, customer, supplier and regulatory forums.
  • Ensure the function has the right operating model, capabilities, technology and management information to protect NewDay and support future growth.
  • Be responsible for the operational delivery of NewDay’s security strategy, ensuring investment and activity are focused on reducing material cyber and technology risk.
  • Own the Information Security Management System and support continued alignment with ISO/IEC 27001:2022, the NIST Cybersecurity Framework and other recognised standards.
  • Maintain effective security policies, standards and controls, ensuring they are understood, embraced, evidenced and continuously improved.
  • Support compliance with PCI DSS, UK GDPR, the Data Protection Act 2018 and relevant FCA expectations.
  • Lead security monitoring, threat management, vulnerability management, incident response and cyber preparedness across NewDay’s technology environment.
  • Maintain effective incident playbooks, escalation routes, exercises and lessons-learned processes.
  • Oversee the technology and security contribution to operational resilience, business continuity, disaster recovery and cyber recovery.
  • Drive improvements in security tooling, telemetry, automation and operational efficiency.
  • Own the technology and information risk framework, including risk appetite, assessment, quantification, treatment and reporting.
  • Ensure security risks and control effectiveness are clearly understood, challenged and transparent to the right decision-makers.
  • Embed security into major technology change, cloud adoption, platform engineering, digital delivery and supplier-led transformation.
  • Partner with technology and engineering leaders to make secure-by-design delivery practical, proportionate and commercially aligned.
  • Oversee third-party and supply-chain security risk across key suppliers, affiliates and strategic partners.
  • Coordinate internal and external assurance activity, including audits, independent assessments and regulatory engagement.
  • Ensure findings, control gaps and regulatory commitments have clear ownership and are delivered to the required standard.
  • Lead NewDay’s approach to AI security and governance, establishing practical controls that enable safe and responsible adoption.

What we’re looking for:

  • You will be an established security leader who can combine strategic judgement with operational delivery.
  • You will be comfortable leading broad, multidisciplinary teams while providing credible, concise advice to executives and Board-level stakeholders.
  • You will bring significant experience leading a broad Information Security function within a regulated organisation, ideally financial services, consumer credit, cards, payments or FinTech.
  • Experience operating as a senior deputy to a CISO, or in an equivalent enterprise security leadership position.
  • Experience across security operations, governance, risk and compliance, architecture, engineering, third-party risk, assurance and operational resilience.
  • Strong practical knowledge of ISO/IEC 27001, PCI DSS, UK GDPR, the Data Protection Act 2018 and recognised control frameworks such as NIST.
  • A solid understanding of technology risk, risk appetite, control effectiveness and operational resilience.
  • Experience leading security incidents, audits, assurance programmes, regulatory engagement and senior-level reporting.
  • Excellent judgement, communication and influencing skills, with the confidence to make clear decisions and build alignment across complex stakeholder groups.
  • Professional certifications such as CISSP, CISM, CRISC, CISA or ISO 27001 Lead Implementer or Auditor would be valuable.
  • Experience of Microsoft Azure security, AI governance, cyber insurance, supplier assurance or major technology transformation would also be beneficial.

Why join NewDay?

This is an opportunity to take on a newly created, enterprise-wide leadership role with the directive to influence how security enables NewDay’s customers, technology strategy and commercial growth. You will work closely with the CISO and senior leaders across technology, product, operations, risk, compliance, data protection, legal and procurement. Most importantly, you will help build a pragmatic, risk-led security culture that protects NewDay while enabling the organisation to move forward with confidence.

At NewDay, we value all types of diversity. We’re an equal opportunity employer and believe that our differences create a vibrant, authentic working culture. We want all our colleagues to feel able to bring their whole selves to work. We don’t discriminate on the basis of protected characteristics or identities. We make sure that every job is crafted to be inclusive and that people with disabilities or caring responsibilities can take part in the application and interview process. Tell us if you need accommodations: We’ll put reasonable adjustments in place to support you. We work with Textio to make our job design and hiring inclusive.

Permanent

Head of Information Security (Deputy CISO) in London employer: NewDay

At NewDay, we pride ourselves on being an exceptional employer, offering a dynamic work culture that fosters collaboration and innovation in the heart of London. Our commitment to employee growth is evident through our focus on diversity and inclusion, ensuring that every team member can thrive while contributing to impactful marketing strategies. With competitive benefits and a supportive environment, we empower our employees to drive meaningful change and achieve their career aspirations.

N

Contact Details:

NewDay Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Head of Information Security (Deputy CISO) in London

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including NewDay, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through NewDay

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at NewDay. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Head of Information Security (Deputy CISO) in London

Information Security Leadership
Cyber Risk Management
ISO/IEC 27001
NIST Cybersecurity Framework
PCI DSS Compliance
UK GDPR Compliance
Data Protection Act 2018

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at NewDay insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to NewDay that you’re committed to staying ahead in the game.

How to prepare for a job interview at NewDay

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at NewDay to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at NewDay.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.