At a Glance
- Tasks: Lead a hands-on cyber security transformation and deliver tangible improvements.
- Company: Join a nationally recognised organisation with a purpose-driven mission.
- Benefits: Hybrid working, high autonomy, and potential for contract extension.
- Other info: Fast-moving interview process with executive visibility and ownership.
- Why this job: Make a real impact in a role focused on delivery, not just strategy.
- Qualifications: Proven experience in CISO roles and strong governance framework skills.
The predicted salary is between 80000 - 100000 ÂŁ per year.
We are supporting a nationally recognized organization on a handsâon cyber security transformation mandate. This is an opportunity to step into a role with real ownership, executive visibility, and a funded roadmap already in placeâbut where delivery is the key challenge.
This is not a steadyâstate or advisory CISO role. It's about rolling up your sleeves and making transformation happen.
The Opportunity
Following a full maturity assessment aligned to NIST, the organization has a clear understanding of its current security posture and a defined 2âyear roadmap to improve it. The focus now is execution. You'll take ownership of that roadmapâshaping, driving, and delivering tangible improvements across governance, risk, and security operations.
What You'll Be Doing
- Owning and delivering a cyber security transformation roadmap
- Building and embedding a GRC framework (policies, standards, risk models)
- Increasing the maturity of security governance and operating structure
- Partnering with a team of security engineers and architects to drive delivery
- Leading the selection and management of a specialist thirdâparty partner to support implementation
- Working closely with senior stakeholders, including CIO and exec leadership
What They're Looking For
- Proven experience in a handsâon CISO / Head of Information Security role
- A track record of taking lowâmaturity security environments and improving them
- Strong experience building or maturing GRC functions and governance frameworks
- Ability to deliver, not just designâthis is key
- Comfortable working across internal teams and external suppliers
- Strong stakeholder engagement, with the ability to translate security into business impact
Title isn't the focus hereâthis could suit an experienced Head of InfoSec stepping up, or a CISO who enjoys handsâon transformation work.
6âmonth initial contract (with potential extension)
Hybrid working (Londonâbased, flexibility offered)
Fastâmoving interview process
Why This Role?
- A genuine transformation mandate with funding already secured
- High levels of autonomy and ownership
- The chance to build something meaningful in a purposeâdriven organization
- A role focused on delivery and impact, not just strategy.
CISO/ Head of Information Security in London employer: SR2 | Socially Responsible Recruitment | Certified B CorporationTM
Contact Detail:
SR2 | Socially Responsible Recruitment | Certified B CorporationTM Recruiting Team
StudySmarter Expert Advice đ¤Ť
We think this is how you could land CISO/ Head of Information Security in London
â¨Tip Number 1
Network like a pro! Reach out to your connections in the cyber security field and let them know you're on the lookout for opportunities. You never know who might have the inside scoop on a role thatâs perfect for you.
â¨Tip Number 2
Prepare for those interviews by brushing up on your hands-on experience. Be ready to share specific examples of how you've transformed low-maturity security environments and delivered tangible improvements. Show them you can roll up your sleeves!
â¨Tip Number 3
Donât just wait for job postingsâbe proactive! Check out our website regularly and apply directly to roles that catch your eye. This shows initiative and can set you apart from other candidates.
â¨Tip Number 4
Engage with potential employers on social media. Follow their pages, comment on their posts, and share relevant content. This can help you get noticed and demonstrate your passion for the industry.
We think you need these skills to ace CISO/ Head of Information Security in London
Some tips for your application đŤĄ
Show Your Hands-On Experience: Make sure to highlight your hands-on experience in cyber security transformation. We want to see how you've rolled up your sleeves and made real changes in previous roles, especially in low-maturity environments.
Tailor Your Application: Donât just send a generic CV and cover letter. Tailor your application to reflect the specific requirements of the CISO role. We love it when candidates connect their past experiences directly to the responsibilities outlined in the job description.
Demonstrate Stakeholder Engagement: Weâre looking for someone who can engage with senior stakeholders effectively. In your application, share examples of how youâve translated complex security concepts into business impact for non-technical audiences.
Apply Through Our Website: We encourage you to apply through our website for a smoother process. It helps us keep track of applications better and ensures you donât miss out on any important updates from us!
How to prepare for a job interview at SR2 | Socially Responsible Recruitment | Certified B CorporationTM
â¨Know Your Roadmap Inside Out
Before the interview, make sure you thoroughly understand the cyber security transformation roadmap mentioned in the job description. Be ready to discuss how your experience aligns with the specific goals and challenges outlined in that roadmap.
â¨Showcase Your Hands-On Experience
This role is all about execution, so prepare examples from your past where you've successfully transformed low-maturity security environments. Highlight your direct involvement and the tangible improvements you achieved.
â¨Engage with Stakeholders
Demonstrate your ability to work closely with senior stakeholders. Prepare to discuss how you've effectively communicated complex security concepts in a way that resonates with business leaders, showcasing your stakeholder engagement skills.
â¨Be Ready for Technical Discussions
Since you'll be partnering with security engineers and architects, brush up on relevant technical knowledge. Be prepared to discuss governance, risk, and compliance frameworks, and how you would implement them in this new role.