
Information Security Lead
- Sunbury, Surrey
- Permanent
- Full-time
- Relationship and Customer management: Act as the main point of contact for all Digital Security enquiries within the relevant business portfolio. Build strong partnerships and influence positive change that serves the commercial ambitions.
- Security Expertise: Provide technical expertise, implementing digital security operating processes aligned to security standards across all value stream activities.
- Safety: Prioritize cyber and operational safety, improve digital security controls through architecture designs and process to maintain our cyber posture and react to new threats.
- Monitor and Assess: Keep a vigilant eye on our digital domains, using innovative tools to detect and assess threats. This includes collaborating on the identification, assessment and management of risk
- Strategize and Protect: Develop and implement robust security measures, crafting a secure environment for our data and systems.
- Respond and Recover: Partner Customers during security incidents with a calm, calculated approach, minimising impact and guiding recovery efforts.
- Educate and Advocate: Champion security awareness across the organisation, encouraging vigilance and responsibility.
- Innovate and Guide: Provide strategic insights to teams, ensuring security is a cornerstone of product development and business operations.
- Protect & Defend: Proactively mitigate cyber risks and coordinate the remediation of findings from vulnerability scans, supplier assurance, compliance reviews, and support the digital Delivery teams in maintaining high levels of cyber hygiene.
- Degree Educated, preferably BSc in Information Security or equivelent.
- Certified Information Security Manager (CISM) or Certified Information Systems Security Professional (CISSP) or working towards certification.
- Knowledge of security frameworks such as ISO 27001/2, NIST, and CIS framework is highly advantageous.
- Previous track record in similar roles in Finance, HR, Trading, Retail, Supply or Oil and Gas companies.
- Strong influencing skills that enable you to communicate technical information to both technical and non-technical audiences, clearly and concisely.
- Deep technical knowledge, and experience delivering security solutions and providing technical advice.
- A track record of delivering business benefits by balancing the need to protect the organizations commercial ambitions and maintain operations of the core value streams.
- Experience working within developing digital ecosystems, with multiple partners and environments, ensuring suitable digital security standards and practices delivered and maintained.
- Good understanding of enterprise and operational risk management, risk governance and compliance requirements.
- Excellent project management skills, with the ability to lead multiple projects simultaneously.
- Able to adapt to shifting priorities, demands, and timelines and keep customers abreast of impact (potential or actual) to defined delivery timescales and/or business impact.
- Ability to use technology, data, and insights to enable decision making.