Head of Information Security in London

Head of Information Security in London

London Full-Time 80000 - 100000 £ / year (est.) No working from home possible
Z

At a Glance

  • Tasks: Lead and develop Zinc's information security function as we scale rapidly.
  • Company: Join a fast-growing tech company focused on AI and innovation.
  • Benefits: Enjoy 24 days holiday, early finish Fridays, and a £1200 annual benefits allowance.
  • Other info: Dynamic environment with opportunities for personal and professional growth.
  • Why this job: Be at the forefront of AI security governance and make a real impact.
  • Qualifications: 5+ years in info security with leadership experience; AI literacy is a must.

The predicted salary is between 80000 - 100000 £ per year.

Zinc has grown to 150+ people, we're scaling fast, and our information security function needs to grow with us. We need to continue maturing our InfoSec function in line with our rate of growth. That changes now. We're hiring a Head of Information Security - the person who will own this function, define what good looks like at Zinc's scale, and build the credibility internally and externally that our customers, partners, and regulators expect. You’ll report into our General Counsel and work closely with our AI & Automation lead, operating in an environment where security is understood as a business enabler, not a blocker. This is a step-up role. We're not looking for someone who has already done this job at a mature enterprise - we're looking for someone who is ready to own it now: hands-on, curious, and comfortable with the AI-native ways of working that define how Zinc operates. If you want to build something, not just inherit it, this is the role for you.

WHAT YOU WILL FOCUS ON FIRST

  • Establishing security maturity - Zinc is scaling fast, and we need our InfoSec function to keep pace. Your first 90 days are about understanding what good looks like at our stage and mapping the path to get there.
  • AI security governance - Zinc is AI-native, which is an opportunity and a responsibility. You'll be in the room with our COO and AI lead regarding adoption decisions from day one.
  • Incident management ownership - you're the lead on any material incident. Not managing every P3/P4, but the name at the top of the escalation when it matters. Set up the playbooks, own the response.
  • Building the function - you'll have one direct report, our InfoSec Manager. Your job is to define what this function needs to look like in 2-3 years, and start executing.

Key Responsibilities

  • Information security strategy - defining and owning the multi-year roadmap
  • Security architecture - reviewing and advising on technical design decisions, embedding security by design across products and platforms
  • Risk management - maintaining the risk register, identifying, prioritising, and tracking the things that actually matter
  • Compliance programmes - ISO 27001, SOC 2, and relevant sector standards; in close partnership with our Compliance team
  • Incident management - owning major incident response; first port of call in a crisis
  • AI security governance - partnering with our AI & Automation lead on safe AI adoption at Zinc
  • Customer and supplier security - security questionnaires, diligence requests, contractual requirements
  • Third-party risk - vendor security assessment and ongoing monitoring
  • Security awareness - training, culture, getting the business to care
  • Budget - managing the InfoSec budget and investment cases, aligned to Zinc's risk profile

Skills, Knowledge and Expertise

  • 5+ years in information security, with at least 2 years in a leadership or senior practitioner role - SOC management, security architecture, penetration testing, or engineering. You've built things and broken things, not just written about them.
  • Ready to step up - you've been a senior practitioner and you're ready to own the function.
  • AI literate - you understand the security implications of LLMs, AI tooling, agentic workflows, shadow AI, and third-party SaaS risk. This is not optional at Zinc.
  • High EQ - you'll inherit an existing team member who is professional, capable, and ambitious. How you lead that relationship matters more than your CV.
  • Strong communicator - you'll be speaking to auditors, customers, and a non-technical leadership team. You need to translate risk into language that drives decisions.
  • Compliance-aware, not compliance-driven - you understand the standards but you lead with risk, not box-ticking.
  • Comfortable with ambiguity - the playbook is incomplete. You'll write it.

Desirable:

  • Experience in a fast-growing global SaaS business
  • Familiarity with DevSecOps and secure development lifecycle practices
  • Relevant certifications (CISSP, CISM, or similar)
  • Experience with cloud security (AWS, Azure, or GCP)

What we offer

  • Zinc offers a chance to work on a product that brings a fresh perspective on data ownership in hiring
  • 24 days holiday + Bank Holidays + your birthday off
  • £1200 annual benefits allowance (ThanksBen, from month 2)
  • Early finish Fridays (16:00)
  • Yearly company retreat abroad
  • 30 days to Work from anywhere
  • Enhanced Maternity, Paternity, and Adoption Leave (2 months full pay, then statutory)
  • Statutory pension with NEST (3% employer, 5% employee)
  • Zinc shares, issued through the EMI Scheme
  • Unlimited access to MoreHappi coaching
  • Company socials, quarterly team socials
  • Free Monday lunches
  • Nursery workplace benefit scheme (Yellownest)
  • Option to lease an electric car through Electric Car Scheme
  • Celebrated Zinc anniversaries

Head of Information Security in London employer: Zinc

Zinc is an exceptional employer that fosters a dynamic and innovative work culture, perfect for those looking to make a significant impact in the field of information security. With a focus on employee growth, we offer extensive benefits including flexible working arrangements, generous holiday allowances, and unique perks like early finish Fridays and annual retreats abroad. Join us in a fast-paced environment where your contributions will shape the future of our InfoSec function and be part of a team that values collaboration and creativity.

Z

Contact Details:

Zinc Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Head of Information Security in London

Tip Number 1

Network like a pro! Get out there and connect with folks in the InfoSec community. Attend meetups, webinars, or even just grab a coffee with someone in the field. Building relationships can open doors that job applications alone can't.

Tip Number 2

Show off your skills! Create a portfolio or a personal project that highlights your expertise in information security. Whether it's a blog, a GitHub repo, or a case study, having something tangible to share can really set you apart from the crowd.

Tip Number 3

Prepare for interviews by diving deep into Zinc's culture and values. Understand how they view security as a business enabler. Tailor your responses to show how your hands-on experience aligns with their vision and how you can contribute to their growth.

Tip Number 4

Don't forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you're genuinely interested in being part of the Zinc team. Let's make this happen together!

We think you need these skills to ace Head of Information Security in London

Information Security Strategy
Security Architecture
Risk Management
Compliance Programmes (ISO 27001, SOC 2)
Incident Management
AI Security Governance
Customer and Supplier Security

Some tips for your application 🫡

Show Your Passion for InfoSec:When you're writing your application, let your enthusiasm for information security shine through. We want to see that you're not just ticking boxes but genuinely excited about building and maturing our InfoSec function at Zinc.

Tailor Your Experience:Make sure to highlight your relevant experience in information security, especially any hands-on roles you've had. We’re looking for someone who’s ready to step up, so connect your past achievements to what you can bring to Zinc.

Communicate Clearly:Remember, you'll be talking to a mix of technical and non-technical folks. Use clear, straightforward language in your application to show us you can translate complex security concepts into something everyone can understand.

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to keep track of your application and ensures you don’t miss out on any important updates from our team!

How to prepare for a job interview at Zinc

Understand Zinc's Unique Culture

Before the interview, take some time to research Zinc's culture and values. They emphasise security as a business enabler, so be ready to discuss how you can contribute to that mindset. Show them you're not just about compliance but also about fostering a security-first culture.

Prepare for Hands-On Scenarios

Since this role is all about building and owning the InfoSec function, think of specific examples from your past where you've successfully established security frameworks or led incident responses. Be prepared to discuss these scenarios in detail, highlighting your hands-on experience and problem-solving skills.

Show Your AI Literacy

Zinc is AI-native, so it's crucial to demonstrate your understanding of AI security implications. Brush up on topics like LLMs and third-party SaaS risks. Be ready to discuss how you would approach AI security governance and what strategies you would implement to ensure safe adoption.

Communicate Clearly and Effectively

You'll need to translate complex security concepts into language that resonates with non-technical stakeholders. Practice explaining your ideas clearly and concisely. Think about how you would communicate risk to auditors and leadership, ensuring they understand the importance of security without getting bogged down in technical jargon.