Head of Information Security

Head of Information Security

Full-Time 80000 - 100000 £ / year (est.) No working from home possible
United Fintech

At a Glance

  • Tasks: Lead the security strategy and governance for a global fintech platform.
  • Company: Join United Fintech, a leader in modern financial technology solutions.
  • Benefits: Competitive salary, flexible working, and a supportive workplace culture.
  • Other info: Dynamic environment with opportunities for professional growth and innovation.
  • Why this job: Make a real impact on security in the fast-paced fintech industry.
  • Qualifications: 10+ years in IT/security with strong leadership and technical skills.

The predicted salary is between 80000 - 100000 £ per year.

United Fintech is building a global platform that connects financial institutions with modern, scalable technology solutions. Through acquisitions and partnerships, we bring together market‑leading fintech products that serve banks, exchange groups, brokerages, and investment firms worldwide.

As Head of Information Security at United Fintech, you will play a key role in defining and executing the organisation’s security strategy, governance, and resilience. Working closely with Product, Engineering, IT, and leadership teams, you will drive security initiatives, manage risk, and support compliance across the group and its product entities.

Key responsibilities include:

  • Strategic Roadmap: Design and execute a multi‑year security roadmap that aligns with the overall corporate strategy at group level across all products to achieve the desired state for security, privacy, and compliance.
  • Executive Reporting: Define and report key security metrics and program maturity indicators to the Executive Board regularly. Educate & inform on evolving cyber risks.
  • Governance & Compliance: Facilitate group‑wide security governance across centralized services and acquired companies by supporting the definition and maintenance of security policies and controls. Provide guidance on the ISO 27001 and SOC2 programs and assist the organization in meeting applicable cybersecurity and privacy regulations.
  • M&A Due Diligence: Lead security assessments during M&A and design post‑acquisition security uplift plans as part of integration.
  • SOC 2 / ISO certification: Own the delivery and maintenance of SOC 2 and ISO 27001 certifications across the Group and its product entities, including integration of newly acquired companies.
  • Technical Risk & Operations
  • IT Collaboration: Partner with Product IT departments to establish and maintain a high level of cybersecurity maturity across the organization.
  • Vulnerability Management: Head the vulnerability management and penetration testing programs, ensuring effective oversight of treatment and remediation efforts.
  • Application Security: Partner with product and engineering teams to embed security and privacy into the design process, supporting a ‘security‑as‑a‑feature’ approach that adds value for our regulated clients.
  • AI Security: Define and oversee data governance policies, ensuring safe deployment and regulatory compliance of AI capabilities across the platform.
  • Resilience Strategy: Assist the business in ensuring the overall defense strategy is "fit for purpose," including Cyber Security Incident Response, Business Continuity Planning (BCP), and Disaster Recovery (DR).
  • Incident Response: Drive the development and implementation of a security incident response plan in accordance with applicable legislation and industry standards.
  • Culture & Enablement
  • Security Awareness: Organize and deliver targeted security training to improve the security awareness of all internal teams.
  • Risk Management: Liaise and collaborate with internal stakeholders to identify, monitor, manage, and report on security risks associated with technology, people, and processes.
  • Third‑Party Management: Ensure robust security compliance due diligence and ongoing monitoring of all third‑party vendors. Build and execute an operational & cost effective strategy on cross‑product vendor choice and management.
  • Customer Assurance: Coordinate the response to customer security assessments and questionnaires; represent the company’s security function at customer meetings, industry events, and online.

You will bring:

  • Experience: 10+ years of experience in information technology or security, with at least 5 years in a senior leadership position (e.g., Head of, VP, Director, or CISO).
  • Technical Acumen: Highly technical background with a deep understanding of modern security architectures.
  • Communication: Excellent presentation and interpersonal skills; able to communicate effectively at all levels, from technical teams to executive leadership.
  • SaaS & Agile: Demonstrated experience embedding "Agile Security" principles within a SaaS product environment.
  • Frameworks: Proven knowledge and experience with ISO 27001 and SOC2 compliance; experience within a regulated environment is required.
  • Certifications: Professional information security certifications such as CISSP, CISM, or ISO 27001 Lead Implementer.
  • Industry Knowledge: Prior experience or knowledge of commercial lending and/or capital markets is a distinct advantage.

Location & Working Arrangements

This role is based in London. The position is full‑time and will be reporting to the Chief Operations Officer (COO).

What We offer

  • Competitive salary and benefits aligned with local market standards.
  • Opportunity to work within a global organisation alongside experienced professionals, contributing to the delivery and evolution of technology solutions for financial institutions.
  • Enjoy the flexibility to balance your professional goals with personal ambitions, while contributing to a supportive, inclusive, and values‑driven workplace culture.
  • Innovative, dynamic and friendly work environment.

We encourage candidates of all backgrounds to apply and are committed to fostering a diverse, inclusive, and supportive working environment.

Head of Information Security employer: United Fintech

United Fintech is an exceptional employer, offering a dynamic and innovative work environment in the heart of London. As the Head of Information Security, you will not only lead critical security initiatives but also enjoy competitive salaries and benefits, alongside opportunities for professional growth within a global organisation. Our inclusive culture fosters collaboration and values diversity, ensuring that every team member can thrive while contributing to cutting-edge technology solutions for financial institutions.

United Fintech

Contact Details:

United Fintech Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Head of Information Security

Tip Number 1

Network like a pro! Reach out to your connections in the fintech and security sectors. Attend industry events, webinars, or even local meetups. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Show off your expertise! Create a personal brand by sharing insights on LinkedIn or writing articles about the latest trends in information security. This not only showcases your knowledge but also gets you noticed by potential employers.

Tip Number 3

Prepare for interviews like it’s game day! Research United Fintech thoroughly—know their products, culture, and recent news. Be ready to discuss how your experience aligns with their goals, especially around security strategy and compliance.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who take that extra step to connect directly with us.

We think you need these skills to ace Head of Information Security

Information Security Strategy
Governance and Compliance
ISO 27001
SOC 2
Risk Management
Vulnerability Management
Penetration Testing

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in information security, especially in leadership roles. We want to see how your skills align with our needs at United Fintech!

Showcase Your Achievements:Don’t just list your responsibilities; share specific achievements that demonstrate your impact in previous roles. Use metrics where possible to show how you’ve driven security initiatives or improved compliance.

Be Clear and Concise:Keep your application clear and to the point. We appreciate well-structured documents that are easy to read. Avoid jargon unless it’s relevant to the role, and make sure your passion for security shines through!

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows you’re keen on joining our team!

How to prepare for a job interview at United Fintech

Know Your Stuff

Make sure you brush up on the latest trends in information security, especially around ISO 27001 and SOC2 compliance. Familiarise yourself with United Fintech's products and how security integrates into their offerings. This will show that you're not just a candidate, but someone who understands their business.

Prepare for Scenario Questions

Expect to be asked about real-world scenarios, especially regarding risk management and incident response. Think of examples from your past experience where you've successfully navigated security challenges or led initiatives. This will demonstrate your hands-on expertise and strategic thinking.

Showcase Your Leadership Skills

As a Head of Information Security, you'll need to lead teams and influence stakeholders. Be ready to discuss your leadership style and how you've fostered a culture of security awareness in previous roles. Highlight any training programs you've implemented to boost security knowledge across teams.

Ask Insightful Questions

Prepare thoughtful questions about United Fintech's security strategy and future initiatives. This not only shows your interest in the role but also gives you insight into their priorities. Ask about their approach to integrating security in M&A processes or how they handle third-party vendor risks.