Account Security Director (vCISO) Role Purpose The Account Security Director (vCISO) is the senior security leader responsible for security governance, assurance and strategic security oversight across a major client account. Acting as the primary security interface between the client security organisation, account leadership and service delivery teams, the role ensures security requirements are understood, embedded and effectively managed throughout the service lifecycle. The role provides trusted security leadership, independent challenge and executive-level advice to ensure services remain aligned with business objectives, contractual obligations, organisational policies, regulatory expectations and risk appetite. Through effective stakeholder engagement and influence, the Account Security Director drives security outcomes, operational resilience and continual improvement in security maturity and assurance effectiveness.Strategic Security Leadership & Client Partnership Act as the senior security representative for the account. Build trusted relationships with client security, technology, risk, compliance, audit and business stakeholders. Serve as the primary point of contact for strategic security matters across the account. Provide strategic security advice and guidance to client executives, account leadership and delivery teams. Represent security interests within governance, operational, service review and transformation forums. Influence senior stakeholders to support effective risk-based decision making. Act as a trusted advisor on security, resilience, compliance and risk matters. Act as an escalation point for significant security issues affecting the account. Promote a positive security culture across the account and wider delivery organisation. Governance, Risk, Assurance & Security Oversight Own, maintain and continually improve the Account Security Management Plan and associated security governance arrangements. Ensure the Security Management Plan remains aligned with client requirements, contractual obligations, organisational policies and industry good practice. Establish and maintain effective security governance and reporting arrangements across the account. Ensure security risks are identified, assessed, communicated and managed in accordance with business objectives and risk appetite. Provide independent oversight and challenge of security controls, assurance activities and risk treatment plans. Provide oversight of security posture, control effectiveness, risks, issues and remediation activities. Challenge decisions, practices or activities that introduce unacceptable levels of security risk. Drive remediation of security risks, audit findings and control weaknesses through to completion. Promote transparency, ownership and continual improvement across the account. Security Architecture and Design Authority Provide strategic security architecture oversight across the account, ensuring security requirements are reflected within technology strategy, solution design and service evolution. Assess the impact of architectural decisions on security risk, operational resilience, compliance obligations and business objectives. Provide independent security challenge to proposed solutions, identifying opportunities to improve security, resilience and risk management outcomes. Support transformation initiatives by providing strategic security guidance and architecture oversight. Ensure security architecture considerations are integrated into service roadmaps and future-state planning. Regulatory, Contractual and Compliance Oversight Maintain a strong understanding of applicable regulatory requirements, industry standards and evolving security expectations relevant to the client environment. Develop and maintain effective working relationships with client Risk, Compliance, Legal, Audit and Operational Resilience stakeholders. Provide trusted advice and guidance on the interpretation and application of regulatory, contractual and security requirements. Ensure regulatory, contractual and policy obligations are understood and appropriately reflected within security governance, assurance and service delivery activities. Support organisational readiness for internal audit, external audit, assurance reviews and regulatory engagement activities. Assess the impact of changes in regulatory, legal and industry requirements on the account and advise on appropriate actions. Promote a proactive approach to compliance, ensuring security controls, processes and governance arrangements continue to support regulatory expectations. Provide oversight and challenge to ensure identified compliance risks, findings and remediation activities are effectively managed through to completion. Ensure security governance and assurance arrangements evolve in line with changes in regulation, business strategy, technology and risk. Continuous Improvement Drive continual improvement in security governance, assurance and risk management practices. Promote adoption of security best practice across account teams. Support the ongoing development of security maturity, operational resilience and assurance effectiveness across the account. Minimum 7 years' experience in a senior information security leadership, Security Director, CISO or virtual CISO role. Experience developing and leading security governance, risk management and assurance programmes. Experience reviewing and challenging technology, cloud, infrastructure and transformation initiatives from a security, resilience and risk perspective. Knowledge and Skills Security governance, risk management and assurance, including the design and operation of effective governance and reporting frameworks. Security oversight of technology strategy, cloud adoption, infrastructure modernisation and digital transformation programmes. Risk-based decision making, balancing business objectives, regulatory obligations and security requirements. Regulatory compliance and the practical application of security, resilience, outsourcing and third-party risk management requirements. Translation of complex security, technical and regulatory issues into clear business, risk and assurance outcomes. Commercial awareness and an understanding of how security supports business objectives, operational resilience and customer confidence. Strong judgement and decision-making capability in complex business, technology and risk environments. Qualifications and Professional Membership CISSP, CISM, CRISC, CCISO or equivalent recognised senior cyber security qualification. UK Cyber Security Council Professional or equivalent recognised accreditation. Member of a professional industry body Evidence of continuing professional development and industry engagement. At NTT DATA, you have endless opportunities to think big, act bold and take ownership. As a $30+ billion business and technology services, AI and digital infrastructure leader, we co-innovate solutions with clients and partners globally for business and societal impact. Proudly a Global Top Employer, NTT DATA is part of NTT Group, which invests over $3 billion annually in R&D. Make this the place where you belong, learn, and build your network. We offer a range of tailored benefits that support your physical, emotional, and financial wellbeing. Our Learning and Development team ensure that there are continuous growth and development opportunities for our people. We also offer the opportunity to have flexible work options.You can find more information about NTT DATA UK & Ireland here: We believe in the fair treatment of all our employees and commit to promoting equity and diversity in our employment practices. We actively collaborate with individuals who have disabilities and long-term health conditions which have an effect on their ability to do normal daily activities, ensuring that barriers are eliminated when it comes to employment opportunities. In line with our commitment, we guarantee an interview to applicants who declare to us, during the application process, that they have a disability and meet the minimum requirements for the role. Join us in building a truly diverse and empowered team.
Information Security Senior Risk Officer in London employer: NTT DATA
At NTT DATA, we pride ourselves on being an excellent employer that fosters a culture of innovation and collaboration. Our commitment to employee growth is evident through continuous learning opportunities and a supportive environment that encourages creativity in the rapidly evolving field of AI/ML security. Located in a vibrant tech hub, we offer competitive benefits and a dynamic workplace where your contributions directly impact the future of secure AI systems.