Chief Information Security Officer

GCHQ
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
£ 130K

Job location

Remote

Tech stack

API
Artificial Intelligence
Amazon Web Services (AWS)
Azure
Cloud Computing Security
Computer Security
Financial Software
Identity and Access Management
Systems Development Life Cycle
Security Information and Event Management
Software Vulnerability Management
Workspace ONE
B2b Software
Gsuite
Devsecops
Vulnerability Analysis
VMware

Job description

recertification auditLead SOC 2 Type II readiness programme (target: 2026-2027), including gap analysis and control mappingEnsure GDPR and data protection compliance across EU/UK/US/AU/NZ/CA/ZACollaborate with external DPO support provider on privacy matters and customer security questionnaires as neededCloud & Technical Security Provide security oversight across Azure, AWS, and Google WorkspaceConduct access reviews and advise on identity and access management best practicesEvaluate and guide security tooling (SIEM, vulnerability management, endpoint protection)Oversee VMware Workspace ONE MDM deployment and device security policiesAdvise engineering teams on secure SDLC, DevSecOps, and application securityOperational Security Develop and maintain incident response plans and proceduresLead incident response tabletop exercises and post-incident reviewsProvide guidance on business continuity and disaster recovery planningAdvise on vendor security assessments and third-party risk, What You'll Be Working On:️ Leading and developing the organization's information security strategy, policies, and programs️ Overseeing the implementation of risk management practices and ensuring compliance with industry regulations (e.g., GDPR, ISO 27001)️ Managing and...

Requirements

managementAwareness & Culture Design and deliver company-wide security awareness trainingMentor and upskill internal staff on security best practicesFoster a security-first culture across departmentsAct as a trusted advisor to leadership on emerging threats and security trendsStakeholder Engagement Report to the CTO on security posture, risks, and programme progressPrepare board-level security presentations as required (infrequent)Support commercial teams by contributing to customer security discussions when escalatedQualifications Experience 8+ years in information security, including at least 3 years in a CISO, Head of Security, or senior leadership roleExperience in B2B SaaS, fintech, finance software, or similarly regulated industriesProven track record of achieving and maintaining ISO 27001 certificationExperience preparing organizations for SOC 2 Type IIHands-on cloud security experience (Azure and/or AWS required; GCP a plus)Experience with Google Workspace security configuration and administrationBackground working with distributed, remote-first engineering teamsTechnical Knowledge Cloud security architecture, identity management, and zero-trust principlesSecure SDLC and DevSecOps practicesMDM solutions (VMware Workspace ONE preferred)API security and integration risk managementSecurity tooling: SIEM, vulnerability scanners, endpoint protectionAwareness of AI/ML security risks and governance frameworks (desirable)Compliance & Regulatory ISO 27001:2022 requirements and audit processesSOC 2 Trust Service Criteria (Security, Availability, Confidentiality, Privacy)GDPR, UK Data Protection Act, and international data transfersRegional requirements across EU, UK, US, Australia, New Zealand, Canada, and South AfricaAdditional information Growing international business with 10,000+ subscribersRegular performance-based compensation reviews26 days paid time off1 additional day off for your BirthdayRemote office assistanceService years recognition financial reward

Benefits & conditions

Deputy Director Chief Information Security Officer - GCHQ - SCS1 Check below to see if you have what is needed for this opportunity, and if so, make an application asap. Full-time (Permanent) £96,981 - £130,000 plus additional allowance. Published on 26 February 2026,..., Locations: Cheltenham, London, Manchester Closing Date: 23:55 on Monday 23rd March 2026 Salary: £96,981 - £130,000, plus a non-concessionary payment of £3,030 (subject to security compliance) and a London Pay Addition of £6,250 if contracted to London. Grade: SCS 1 -...

About the company

A leading fintech company is seeking a Chief Information Security Officer (CISO) to lead a global security function at the forefront of financial innovation. If you think you are the right match for the following opportunity, apply after reading the complete...

Apply for this position