Managing Director, International Chief Information Security Officer Position Summary The International Chief Information Security Officer (International CISO) reporting to the SVP, Global Head of Business Information Security, serves as the senior cybersecurity executive responsible for cybersecurity strategy, governance, regulatory engagement, and cyber risk oversight across multiple international jurisdictions. The role provides leadership and accountability for regional cybersecurity programs while ensuring alignment with enterprise security strategies, local regulatory requirements, business objectives, and operational resilience expectations. The International CISO acts as the primary cybersecurity advisor to regional executives, regulators, legal entities, risk committees, and business leaders, while coordinating closely with global cybersecurity functions to drive consistent security outcomes and regulatory compliance across international markets. The International CISO balances global cybersecurity standards with regional business and regulatory requirements while driving execution across complex multinational environments. The International CISO is expected to operate as a trusted advisor to executive leadership and the regional boards, while being able to translate complex cybersecurity issues into business-oriented risk decisions. Key Responsibilities International Cybersecurity Leadership Lead cybersecurity strategies and execution across assigned international regions, including oversight of country and regional cybersecurity programs. Establish and maintain a consistent cybersecurity operating model across jurisdictions while accounting for local regulatory and business requirements. Serve as the senior cybersecurity executive for international legal entities and country governance structures. Drive regional cybersecurity transformation initiatives supporting emerging technologies, cloud adoption, AI, resilience, and digital modernization efforts. Regulatory Engagement Serve as the accountable cybersecurity representative for regulatory examinations, audits, supervisory engagements, and regulatory reporting requirements. Maintain strong relationships with regional regulators, industry associations, and cybersecurity authorities. Monitor changes in cyber, technology risk, privacy, resilience, and operational risk regulations across assigned jurisdictions. Ensure cybersecurity programs meet local regulatory expectations and support enterprise compliance objectives. Business Information Security Function as the primary cybersecurity advisor to regional business executives, country heads, legal entity boards, and management committees. Partner with business leaders to embed security into strategic initiatives, acquisitions, client solutions, and technology modernization programs. Support client cybersecurity due diligence activities and strategic customer engagements. Promote cybersecurity awareness and accountability throughout the regional businesses. Incident Management and Resilience Provide leadership during significant cybersecurity incidents affecting international operations. Coordinate with cyber defense center, cyber threat intelligence, technical and business teams during regional cyber events. Ensure regional readiness for cyber incidents and operational disruptions through resilience testing exercises. Maintain oversight of regulatory reporting and regional stakeholder communications during cybersecurity events. International Team Leadership Lead and develop regional cybersecurity staff in support of technical and business aligned teams. Establish succession planning, workforce development, and talent strategies. Build a high-performing, globally connected cybersecurity team capable of supporting regional growth and regulatory demands. Foster collaboration between international teams and enterprise security functions. Required Qualifications Education Bachelor's degree in information security, Computer Science, Technology, Risk Management, Business, or related field. Experience 15+ years of progressive cybersecurity, technology risk, or information security experience. Considerable experience leading cybersecurity programs across multiple countries and regulatory jurisdictions. Proven experience engaging directly with regulators and executive leadership. Experience within global financial services or other highly regulated industries. Demonstrated success leading large-scale cybersecurity transformation programs. Technical and Regulatory Expertise Cybersecurity frameworks and controls. Operational resilience and business continuity. Cloud security and emerging technologies. AI security and governance. Data protection and privacy requirements. Identity and access management. Cyber threat intelligence and incident response. Third-party and supply chain risk management. Success Measures Regulatory outcomes Reduction of material cybersecurity risk across the regional teams. Cyber resilience maturity improvements. Timely remediation of owned audit and regulatory findings. Business satisfaction and executive stakeholder engagement. Cybersecurity program maturity across regions. Talent development and organizational effectiveness. Successful execution of strategic cybersecurity initiatives. About State Street Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success. We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you'll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future. As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law. Discover more information on jobs at Read our CEO Statement
Aug 21, 2026
Full time
Managing Director, International Chief Information Security Officer Position Summary The International Chief Information Security Officer (International CISO) reporting to the SVP, Global Head of Business Information Security, serves as the senior cybersecurity executive responsible for cybersecurity strategy, governance, regulatory engagement, and cyber risk oversight across multiple international jurisdictions. The role provides leadership and accountability for regional cybersecurity programs while ensuring alignment with enterprise security strategies, local regulatory requirements, business objectives, and operational resilience expectations. The International CISO acts as the primary cybersecurity advisor to regional executives, regulators, legal entities, risk committees, and business leaders, while coordinating closely with global cybersecurity functions to drive consistent security outcomes and regulatory compliance across international markets. The International CISO balances global cybersecurity standards with regional business and regulatory requirements while driving execution across complex multinational environments. The International CISO is expected to operate as a trusted advisor to executive leadership and the regional boards, while being able to translate complex cybersecurity issues into business-oriented risk decisions. Key Responsibilities International Cybersecurity Leadership Lead cybersecurity strategies and execution across assigned international regions, including oversight of country and regional cybersecurity programs. Establish and maintain a consistent cybersecurity operating model across jurisdictions while accounting for local regulatory and business requirements. Serve as the senior cybersecurity executive for international legal entities and country governance structures. Drive regional cybersecurity transformation initiatives supporting emerging technologies, cloud adoption, AI, resilience, and digital modernization efforts. Regulatory Engagement Serve as the accountable cybersecurity representative for regulatory examinations, audits, supervisory engagements, and regulatory reporting requirements. Maintain strong relationships with regional regulators, industry associations, and cybersecurity authorities. Monitor changes in cyber, technology risk, privacy, resilience, and operational risk regulations across assigned jurisdictions. Ensure cybersecurity programs meet local regulatory expectations and support enterprise compliance objectives. Business Information Security Function as the primary cybersecurity advisor to regional business executives, country heads, legal entity boards, and management committees. Partner with business leaders to embed security into strategic initiatives, acquisitions, client solutions, and technology modernization programs. Support client cybersecurity due diligence activities and strategic customer engagements. Promote cybersecurity awareness and accountability throughout the regional businesses. Incident Management and Resilience Provide leadership during significant cybersecurity incidents affecting international operations. Coordinate with cyber defense center, cyber threat intelligence, technical and business teams during regional cyber events. Ensure regional readiness for cyber incidents and operational disruptions through resilience testing exercises. Maintain oversight of regulatory reporting and regional stakeholder communications during cybersecurity events. International Team Leadership Lead and develop regional cybersecurity staff in support of technical and business aligned teams. Establish succession planning, workforce development, and talent strategies. Build a high-performing, globally connected cybersecurity team capable of supporting regional growth and regulatory demands. Foster collaboration between international teams and enterprise security functions. Required Qualifications Education Bachelor's degree in information security, Computer Science, Technology, Risk Management, Business, or related field. Experience 15+ years of progressive cybersecurity, technology risk, or information security experience. Considerable experience leading cybersecurity programs across multiple countries and regulatory jurisdictions. Proven experience engaging directly with regulators and executive leadership. Experience within global financial services or other highly regulated industries. Demonstrated success leading large-scale cybersecurity transformation programs. Technical and Regulatory Expertise Cybersecurity frameworks and controls. Operational resilience and business continuity. Cloud security and emerging technologies. AI security and governance. Data protection and privacy requirements. Identity and access management. Cyber threat intelligence and incident response. Third-party and supply chain risk management. Success Measures Regulatory outcomes Reduction of material cybersecurity risk across the regional teams. Cyber resilience maturity improvements. Timely remediation of owned audit and regulatory findings. Business satisfaction and executive stakeholder engagement. Cybersecurity program maturity across regions. Talent development and organizational effectiveness. Successful execution of strategic cybersecurity initiatives. About State Street Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success. We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you'll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future. As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law. Discover more information on jobs at Read our CEO Statement
State Street Corporation in London seeks an International Chief Information Security Officer to lead regional cybersecurity programs, align with enterprise security strategies, and ensure regulatory compliance across international markets. The role reports to the SVP, Global Head of Business Information Security. The candidate will advise regional executives, regulators, and risk committees, driving resilience and security modernization in collaboration with global security functions.
Aug 21, 2026
Full time
State Street Corporation in London seeks an International Chief Information Security Officer to lead regional cybersecurity programs, align with enterprise security strategies, and ensure regulatory compliance across international markets. The role reports to the SVP, Global Head of Business Information Security. The candidate will advise regional executives, regulators, and risk committees, driving resilience and security modernization in collaboration with global security functions.
AXA XL is an Equal Opportunity Employer. Chief Enterprise Architect Location: UK / US AXA XL's Chief Enterprise Architect is a key senior executive, leadership team role in the Technology & AI function, accountable for defining and governing the enterprise-wide architecture vision, ensuring our business strategy is translated into an integrated technology, data, and capability roadmap. This role drives simplification, modernization, resilience, and value through architecture-led decision making, transforming to AI-based architecture. The role reports to AXA XL's Chief Technology & AI Officer. What you'll be doing Enterprise Architecture Strategy & Vision Define and maintain the enterprise target architecture aligned to AXA XL's business strategy. Lead creation of multi-year architecture roadmaps across business, data, application, and infrastructure domains. Ensure architectural decisions support growth, customer experience, operational efficiency, and regulatory requirements. Own the enterprise AI architecture strategy, ensuring AI capabilities, platforms, data, governance and responsible controls are designed to scale securely while delivering measurable business value Architecture Governance & Standards Establish and run enterprise architecture governance (design authorities, standards, patterns, guardrails). Approve or challenge major technology and platform decisions, ensuring architecture is consistent across portfolios, programs, and delivery teams. Technology Simplification & Modernization Drive reduction of technical duplication, and complexity across the enterprise. Lead rationalization of application estates and platform portfolios, in addition to guiding cloud migration strategy and legacy modernization priorities. Business & Capability Architecture Translate AXA XL's business strategy into capability maps and operating model requirements. Partner with senior business leaders to define capability gaps and investment priorities. Build e2e integrated AI-based architecture and ensure engineering executes using this agreed architecture. Ensure technology investment is anchored in business outcomes. Data, Integration & Platform Architecture Define enterprise integration principles (API strategy, event-driven architecture, interoperability). Align data architecture with enterprise data strategy, governance, and analytics needs. Define and keep Enterprise Architecture principles current, ensuring principles are embedded in the governance (architecture review, sourcing and procurement, AI, engineering) while promoting reuse of platforms, components, and shared services. Security, Risk & Resilience by Design Ensure security and operational resilience are embedded in architecture standards; resulting in security, AI and privacy by design. Work with CISO, risk and compliance teams to ensure architecture meets regulatory expectations. Drive architecture decisions that reduce systemic technology risk. What you'll bring We're looking for someone who has these abilities and skills: Required Skills and Abilities: Deep expertise and hands on experience in e2e business and technology capability architecture with embedded security/privacy/AI. with a track record of success in the areas of delivery high impact learning and development solutions and operations Leadership experience in managing high performing teams who are autonomous, empowered and strive for excellence to serve a global scope Extensive critical thinking, systems thinking and problem solving skills, with the ability to continually seek to improve, create efficiencies and optimize service delivery Data and insight driven, the ability to make robust decisions and drive measurable outcomes Effective oral/written communication skills to be able to engage multiple stakeholders in driving change and embedding new processes/practices. What we offer Inclusion AXA XL is committed to equal employment opportunity and will consider applicants regardless of gender, sexual orientation, age, ethnicity and origins, marital status, religion, disability, or any other protected characteristic. At AXA XL, we know that an inclusive culture enables business growth and is critical to our success. That's why we have made a strategic commitment to attract, develop, advance and retain the most inclusive workforce possible, and create a culture where everyone can bring their full selves to work and reach their highest potential. It's about helping one another - and our business - to move forward and succeed. Five Business Resource Groups focused on gender, LGBTQ+, ethnicity and origins, disability and inclusion with 20 Chapters around the globe. Robust support for Flexible Working Arrangements Enhanced family friendly leave benefits Named to the Diversity Best Practices Index Signatory to the UK Women in Finance Charter Learn more at AXA XL is an Equal Opportunity Employer. Total Rewards AXA XL's Reward program is designed to take care of what matters most to you, covering the full picture of your health, wellbeing, lifestyle and financial security. It provides competitive compensation and personalized, inclusive benefits that evolve as you do. We're committed to rewarding your contribution for the long term, so you can be your best self today and look forward to the future with confidence. Sustainability At AXA XL, Sustainability is integral to our business strategy. In an ever-changing world, AXA XL protects what matters most for our clients and communities. We know that sustainability is at the root of a more resilient future. Our 2023-26 Sustainability strategy, called "Roots of resilience", focuses on protecting natural ecosystems, addressing climate change, and embedding sustainable practices across our operations. Our Pillars: Valuing nature: How we impact nature affects how nature impacts us. Resilient ecosystems - the foundation of a sustainable planet and society - are essential to our future. We're committed to protecting and restoring nature - from mangrove forests to the bees in our backyard - by increasing biodiversity awareness and inspiring clients and colleagues to put nature at the heart of their plans. Addressing climate change: The effects of a changing climate are far-reaching and significant. Unpredictable weather, increasing temperatures, and rising sea levels cause both social inequalities and environmental disruption. We're building a net zero strategy, developing insurance products and services, and mobilizing to advance thought leadership and investment in societal led solutions. Integrating ESG: All companies have a role to play in building a more resilient future. Incorporating ESG considerations into our internal processes and practices builds resilience from the roots of our business. We are training our colleagues, engaging our external partners, and evolving our sustainability governance and reporting. AXA Hearts in Action: We have established volunteering and charitable giving programs to help colleagues support causes that matter most to them, known as AXA XL's "Hearts in Action" programs. These include our Matching Gifts program, Volunteering Leave, and our annual volunteering day - the Global Day of Giving. For more information, please see The U.S. base salary range for this position is $275,000 to $300,000 USD. AXA XL is a global Company. The salary range noted above is applicable only for US applicants. Actual pay will be determined based upon the individual's skills, experience and location. We strive for market alignment and internal equity with our colleagues' pay. At AXA XL, we know how important physical, mental, and financial health are to our employees, which is why we are proud to offer benefits such as a competitive retirement savings plan, health and wellness programs, and many other benefits. We also believe in fostering our colleagues' development and offer a wide range of learning opportunities for colleagues to hone their professional skills and to position themselves for the next step of their careers. Who we are AXA XL, the P&C and specialty risk division of AXA, is known for solving complex risks. For mid sized companies, multinationals and even some inspirational individuals we don't just provide re/insurance, we reinvent it. How? By combining a comprehensive and efficient capital platform, data driven insights, leading technology, and the best talent in an agile and inclusive workspace, empowered to deliver top client service across all our lines of business property, casualty, professional, financial lines and specialty. With an innovative and flexible approach to risk solutions, we partner with those who move the world forward. Learn more at
Aug 19, 2026
Full time
AXA XL is an Equal Opportunity Employer. Chief Enterprise Architect Location: UK / US AXA XL's Chief Enterprise Architect is a key senior executive, leadership team role in the Technology & AI function, accountable for defining and governing the enterprise-wide architecture vision, ensuring our business strategy is translated into an integrated technology, data, and capability roadmap. This role drives simplification, modernization, resilience, and value through architecture-led decision making, transforming to AI-based architecture. The role reports to AXA XL's Chief Technology & AI Officer. What you'll be doing Enterprise Architecture Strategy & Vision Define and maintain the enterprise target architecture aligned to AXA XL's business strategy. Lead creation of multi-year architecture roadmaps across business, data, application, and infrastructure domains. Ensure architectural decisions support growth, customer experience, operational efficiency, and regulatory requirements. Own the enterprise AI architecture strategy, ensuring AI capabilities, platforms, data, governance and responsible controls are designed to scale securely while delivering measurable business value Architecture Governance & Standards Establish and run enterprise architecture governance (design authorities, standards, patterns, guardrails). Approve or challenge major technology and platform decisions, ensuring architecture is consistent across portfolios, programs, and delivery teams. Technology Simplification & Modernization Drive reduction of technical duplication, and complexity across the enterprise. Lead rationalization of application estates and platform portfolios, in addition to guiding cloud migration strategy and legacy modernization priorities. Business & Capability Architecture Translate AXA XL's business strategy into capability maps and operating model requirements. Partner with senior business leaders to define capability gaps and investment priorities. Build e2e integrated AI-based architecture and ensure engineering executes using this agreed architecture. Ensure technology investment is anchored in business outcomes. Data, Integration & Platform Architecture Define enterprise integration principles (API strategy, event-driven architecture, interoperability). Align data architecture with enterprise data strategy, governance, and analytics needs. Define and keep Enterprise Architecture principles current, ensuring principles are embedded in the governance (architecture review, sourcing and procurement, AI, engineering) while promoting reuse of platforms, components, and shared services. Security, Risk & Resilience by Design Ensure security and operational resilience are embedded in architecture standards; resulting in security, AI and privacy by design. Work with CISO, risk and compliance teams to ensure architecture meets regulatory expectations. Drive architecture decisions that reduce systemic technology risk. What you'll bring We're looking for someone who has these abilities and skills: Required Skills and Abilities: Deep expertise and hands on experience in e2e business and technology capability architecture with embedded security/privacy/AI. with a track record of success in the areas of delivery high impact learning and development solutions and operations Leadership experience in managing high performing teams who are autonomous, empowered and strive for excellence to serve a global scope Extensive critical thinking, systems thinking and problem solving skills, with the ability to continually seek to improve, create efficiencies and optimize service delivery Data and insight driven, the ability to make robust decisions and drive measurable outcomes Effective oral/written communication skills to be able to engage multiple stakeholders in driving change and embedding new processes/practices. What we offer Inclusion AXA XL is committed to equal employment opportunity and will consider applicants regardless of gender, sexual orientation, age, ethnicity and origins, marital status, religion, disability, or any other protected characteristic. At AXA XL, we know that an inclusive culture enables business growth and is critical to our success. That's why we have made a strategic commitment to attract, develop, advance and retain the most inclusive workforce possible, and create a culture where everyone can bring their full selves to work and reach their highest potential. It's about helping one another - and our business - to move forward and succeed. Five Business Resource Groups focused on gender, LGBTQ+, ethnicity and origins, disability and inclusion with 20 Chapters around the globe. Robust support for Flexible Working Arrangements Enhanced family friendly leave benefits Named to the Diversity Best Practices Index Signatory to the UK Women in Finance Charter Learn more at AXA XL is an Equal Opportunity Employer. Total Rewards AXA XL's Reward program is designed to take care of what matters most to you, covering the full picture of your health, wellbeing, lifestyle and financial security. It provides competitive compensation and personalized, inclusive benefits that evolve as you do. We're committed to rewarding your contribution for the long term, so you can be your best self today and look forward to the future with confidence. Sustainability At AXA XL, Sustainability is integral to our business strategy. In an ever-changing world, AXA XL protects what matters most for our clients and communities. We know that sustainability is at the root of a more resilient future. Our 2023-26 Sustainability strategy, called "Roots of resilience", focuses on protecting natural ecosystems, addressing climate change, and embedding sustainable practices across our operations. Our Pillars: Valuing nature: How we impact nature affects how nature impacts us. Resilient ecosystems - the foundation of a sustainable planet and society - are essential to our future. We're committed to protecting and restoring nature - from mangrove forests to the bees in our backyard - by increasing biodiversity awareness and inspiring clients and colleagues to put nature at the heart of their plans. Addressing climate change: The effects of a changing climate are far-reaching and significant. Unpredictable weather, increasing temperatures, and rising sea levels cause both social inequalities and environmental disruption. We're building a net zero strategy, developing insurance products and services, and mobilizing to advance thought leadership and investment in societal led solutions. Integrating ESG: All companies have a role to play in building a more resilient future. Incorporating ESG considerations into our internal processes and practices builds resilience from the roots of our business. We are training our colleagues, engaging our external partners, and evolving our sustainability governance and reporting. AXA Hearts in Action: We have established volunteering and charitable giving programs to help colleagues support causes that matter most to them, known as AXA XL's "Hearts in Action" programs. These include our Matching Gifts program, Volunteering Leave, and our annual volunteering day - the Global Day of Giving. For more information, please see The U.S. base salary range for this position is $275,000 to $300,000 USD. AXA XL is a global Company. The salary range noted above is applicable only for US applicants. Actual pay will be determined based upon the individual's skills, experience and location. We strive for market alignment and internal equity with our colleagues' pay. At AXA XL, we know how important physical, mental, and financial health are to our employees, which is why we are proud to offer benefits such as a competitive retirement savings plan, health and wellness programs, and many other benefits. We also believe in fostering our colleagues' development and offer a wide range of learning opportunities for colleagues to hone their professional skills and to position themselves for the next step of their careers. Who we are AXA XL, the P&C and specialty risk division of AXA, is known for solving complex risks. For mid sized companies, multinationals and even some inspirational individuals we don't just provide re/insurance, we reinvent it. How? By combining a comprehensive and efficient capital platform, data driven insights, leading technology, and the best talent in an agile and inclusive workspace, empowered to deliver top client service across all our lines of business property, casualty, professional, financial lines and specialty. With an innovative and flexible approach to risk solutions, we partner with those who move the world forward. Learn more at
Salary is competitive and commensurate with experience, plus a 14.5% pension contribution and a relocation package where applicable. Shape the future of information security for one of the world's most important organisations supporting biomedical research. At UK Biobank, information security isn't simply about protecting systems, it's about safeguarding one of the world's most valuable health research resources. Our data is trusted by more than 22,000 approved researchers across over 60 countries, helping advance our understanding of cancer, dementia, cardiovascular disease, mental health and hundreds of other conditions. Protecting that trust while enabling scientific discovery is fundamental to everything we do. We're entering one of the most significant periods of technology transformation in our history. As we continue to invest in modern cloud platforms, AI-enabled services, new digital capabilities and our £127.6 million headquarters at Manchester Science Park, we're looking for a Director of Information Security to lead the next phase of our information security maturity. This isn't a role focused on maintaining an established security function. It's an opportunity to shape and define a world-class capability Can you do it? As Director of Information Security, you'll report directly to our Chief Technology Officer and provide strategic leadership for information security across UK Biobank. You'll be responsible for ensuring our governance, cyber security, identity management, business continuity, and risk management capabilities continue to evolve alongside an increasingly complex threat landscape. Working closely with colleagues across Data and Technology, Legal, and the wider organisation, you'll embed security into organisational decision-making, providing confidence that our platforms remain secure, resilient, and compliant while continuing to support innovation and world-leading research. This is a unique opportunity to build on the strong foundations already in place while leading the next phase of UK Biobank's security maturity. As we continue our wider technology transformation, you'll shape the organisation's security strategy, strengthen operational capability, and help embed security into every aspect of our cloud platforms, digital services, AI initiatives, and future technologies. You'll lead a growing Information Security function, with the opportunity to develop capability, evolve the team, and foster a positive security culture across the organisation. Working at both strategic and operational levels, you'll influence Executive Leadership and Board discussions while providing the leadership needed to respond to emerging threats, manage organisational risk, and ensure security enables innovation rather than becoming a barrier to it. This is a unique and rare opportunity to shape the future of information security within one of the world's leading biomedical research organisations, protecting data that supports thousands of researchers across the globe while helping deliver the next generation of scientific discovery. You will be responsible for Developing, implementing, and creating a comprehensive information security strategy, providing direction and support to ensure effective implementation of security controls. Conducting regular risk assessments, audits, tests, and modelling to identify and evaluate vulnerabilities and potential threats. Providing regular updates to the executive leadership team and represent information security at board, audit, and governance committees Establishing metrics and enforcing information security policies, procedures, and guidelines aligned with standards and frameworks, particularly ISO27001 and the NCSC Cyber Assessment Framework, as well as regulatory requirements and industry best practices. Ensuring that critical data and assets have been identified, classified, and subject to appropriate controls, including for handling, ownership, and destruction. Leading the organisation's response to major cyber incidents, including providing out-of-hours and crisis-level support when required. Promoting and communicating a culture of security awareness so all staff understand their role in maintaining information security. Managing the Information Security budget, setting investment priorities, and contributing to financial planning. Is this 'you'? To be successful, you will have: Significant experience in information security management, with a proven track record of leadership in the field. Relevant industry certifications, preferably CISSP, CISM, or CCISO. Strong knowledge of information security standards, frameworks, and best practices. Previous experience of ISO270001 is a key requirement. A clear understanding of the laws and regulations associated with controlling and processing personal data, directing organisation responses to cyber incidents. Strong knowledge and understanding of the cyber threat landscape. Experience securing cloud environments with a knowledge of the vulnerability detection tools and security services available in AWS and /or MS Azure. Experience of deploying controls across networking, end-user compute, identity and access management, software development, and business operations to minimise the likelihood of security incidents. Experience of recruiting specialist staff, building teams, and developing existing colleagues through training, coaching and mentoring. Working hours are 35 hours per week, Monday to Friday, with 3 days onsite and hybrid working available. The role will be based at Greenheys, Manchester Science Park's headquarters. Our passion for diversity and equality means creating a work environment for all employees that is welcoming, respectful, engaging, and enriched with opportunities for personal and professional development. We actively welcome applications from people with disabilities, long-term health conditions, neurodivergent candidates, and those with diverse thinking styles. We are committed to making reasonable adjustments throughout our recruitment process and in the workplace so that everyone can perform at their best. If you require any adjustments during the recruitment process, please contact Tommy Wilson at so we can support you. Your Wellbeing Matters to Us Colleagues at UK Biobank often highlight feeling supported, included, and connected to meaningful work, with wellbeing and work-life balance genuinely valued across teams. We're proud to offer a benefits package that supports your health, financial security, and development from day one: Currently 14.5% employer contribution to the USS Pension Scheme Healthcare Cash Plan to help cover everyday healthcare costs ️ 30 days' annual leave, plus bank holidays Buy up to 5 additional days' annual leave through our Holiday Buy Scheme A paid day off for your birthday Enhanced maternity, paternity, adoption and shared parental pay Hybrid and flexible working for many office-based roles Up to 6 months' full sick pay ️ Free on-site gym Subsidised lunch when working on site ️ Life Assurance Cycle to Work Scheme Season Ticket Loan Training and development opportunities, including a £500 annual personal development allowance Paid professional subscriptions, where applicable ️ Employee Discounts Portal Wellbeing support, including an Employee Assistance Programme Free annual flu vaccination and Hepatitis B vaccination, where applicable An active social committee with regular social events Free on-site parking Payroll Giving (Give As You Earn) The job advert closing date may change, so early applications are encouraged. About UK Biobank UK Biobank is a large-scale biomedical database and research resource containing in-depth genetic and health information from half a million UK participants. The database, the largest and most comprehensive of its kind in the world, is anonymised and made widely accessible by UK Biobank to global researchers who use it to find new scientific discoveries about common and life-threatening diseases - such as cancer, heart disease and stroke which strike in mid-later life. UK Biobank is an innovative organisation with over 350 staff across four sites in the UK that fosters an engaging environment and supports the development of our staff. Our dedicated teams work alongside the world's leading biomedical scientists in our joint mission to improve public health.
Aug 17, 2026
Full time
Salary is competitive and commensurate with experience, plus a 14.5% pension contribution and a relocation package where applicable. Shape the future of information security for one of the world's most important organisations supporting biomedical research. At UK Biobank, information security isn't simply about protecting systems, it's about safeguarding one of the world's most valuable health research resources. Our data is trusted by more than 22,000 approved researchers across over 60 countries, helping advance our understanding of cancer, dementia, cardiovascular disease, mental health and hundreds of other conditions. Protecting that trust while enabling scientific discovery is fundamental to everything we do. We're entering one of the most significant periods of technology transformation in our history. As we continue to invest in modern cloud platforms, AI-enabled services, new digital capabilities and our £127.6 million headquarters at Manchester Science Park, we're looking for a Director of Information Security to lead the next phase of our information security maturity. This isn't a role focused on maintaining an established security function. It's an opportunity to shape and define a world-class capability Can you do it? As Director of Information Security, you'll report directly to our Chief Technology Officer and provide strategic leadership for information security across UK Biobank. You'll be responsible for ensuring our governance, cyber security, identity management, business continuity, and risk management capabilities continue to evolve alongside an increasingly complex threat landscape. Working closely with colleagues across Data and Technology, Legal, and the wider organisation, you'll embed security into organisational decision-making, providing confidence that our platforms remain secure, resilient, and compliant while continuing to support innovation and world-leading research. This is a unique opportunity to build on the strong foundations already in place while leading the next phase of UK Biobank's security maturity. As we continue our wider technology transformation, you'll shape the organisation's security strategy, strengthen operational capability, and help embed security into every aspect of our cloud platforms, digital services, AI initiatives, and future technologies. You'll lead a growing Information Security function, with the opportunity to develop capability, evolve the team, and foster a positive security culture across the organisation. Working at both strategic and operational levels, you'll influence Executive Leadership and Board discussions while providing the leadership needed to respond to emerging threats, manage organisational risk, and ensure security enables innovation rather than becoming a barrier to it. This is a unique and rare opportunity to shape the future of information security within one of the world's leading biomedical research organisations, protecting data that supports thousands of researchers across the globe while helping deliver the next generation of scientific discovery. You will be responsible for Developing, implementing, and creating a comprehensive information security strategy, providing direction and support to ensure effective implementation of security controls. Conducting regular risk assessments, audits, tests, and modelling to identify and evaluate vulnerabilities and potential threats. Providing regular updates to the executive leadership team and represent information security at board, audit, and governance committees Establishing metrics and enforcing information security policies, procedures, and guidelines aligned with standards and frameworks, particularly ISO27001 and the NCSC Cyber Assessment Framework, as well as regulatory requirements and industry best practices. Ensuring that critical data and assets have been identified, classified, and subject to appropriate controls, including for handling, ownership, and destruction. Leading the organisation's response to major cyber incidents, including providing out-of-hours and crisis-level support when required. Promoting and communicating a culture of security awareness so all staff understand their role in maintaining information security. Managing the Information Security budget, setting investment priorities, and contributing to financial planning. Is this 'you'? To be successful, you will have: Significant experience in information security management, with a proven track record of leadership in the field. Relevant industry certifications, preferably CISSP, CISM, or CCISO. Strong knowledge of information security standards, frameworks, and best practices. Previous experience of ISO270001 is a key requirement. A clear understanding of the laws and regulations associated with controlling and processing personal data, directing organisation responses to cyber incidents. Strong knowledge and understanding of the cyber threat landscape. Experience securing cloud environments with a knowledge of the vulnerability detection tools and security services available in AWS and /or MS Azure. Experience of deploying controls across networking, end-user compute, identity and access management, software development, and business operations to minimise the likelihood of security incidents. Experience of recruiting specialist staff, building teams, and developing existing colleagues through training, coaching and mentoring. Working hours are 35 hours per week, Monday to Friday, with 3 days onsite and hybrid working available. The role will be based at Greenheys, Manchester Science Park's headquarters. Our passion for diversity and equality means creating a work environment for all employees that is welcoming, respectful, engaging, and enriched with opportunities for personal and professional development. We actively welcome applications from people with disabilities, long-term health conditions, neurodivergent candidates, and those with diverse thinking styles. We are committed to making reasonable adjustments throughout our recruitment process and in the workplace so that everyone can perform at their best. If you require any adjustments during the recruitment process, please contact Tommy Wilson at so we can support you. Your Wellbeing Matters to Us Colleagues at UK Biobank often highlight feeling supported, included, and connected to meaningful work, with wellbeing and work-life balance genuinely valued across teams. We're proud to offer a benefits package that supports your health, financial security, and development from day one: Currently 14.5% employer contribution to the USS Pension Scheme Healthcare Cash Plan to help cover everyday healthcare costs ️ 30 days' annual leave, plus bank holidays Buy up to 5 additional days' annual leave through our Holiday Buy Scheme A paid day off for your birthday Enhanced maternity, paternity, adoption and shared parental pay Hybrid and flexible working for many office-based roles Up to 6 months' full sick pay ️ Free on-site gym Subsidised lunch when working on site ️ Life Assurance Cycle to Work Scheme Season Ticket Loan Training and development opportunities, including a £500 annual personal development allowance Paid professional subscriptions, where applicable ️ Employee Discounts Portal Wellbeing support, including an Employee Assistance Programme Free annual flu vaccination and Hepatitis B vaccination, where applicable An active social committee with regular social events Free on-site parking Payroll Giving (Give As You Earn) The job advert closing date may change, so early applications are encouraged. About UK Biobank UK Biobank is a large-scale biomedical database and research resource containing in-depth genetic and health information from half a million UK participants. The database, the largest and most comprehensive of its kind in the world, is anonymised and made widely accessible by UK Biobank to global researchers who use it to find new scientific discoveries about common and life-threatening diseases - such as cancer, heart disease and stroke which strike in mid-later life. UK Biobank is an innovative organisation with over 350 staff across four sites in the UK that fosters an engaging environment and supports the development of our staff. Our dedicated teams work alongside the world's leading biomedical scientists in our joint mission to improve public health.
ClearCourse Partnership LLP is looking for an experienced Chief Information Security Officer (CISO) to lead our security strategy across 40+ software and payments businesses. This pivotal role reports to the Chief Technology & Transformation Officer and requires managing security governance, compliance, and risk management. The ideal candidate will have extensive CISO experience, particularly in PCI-DSS compliance, and a strong understanding of embedding security within DevSecOps practices. The position offers a hybrid work model with competitive salary and benefits.
Aug 07, 2026
Full time
ClearCourse Partnership LLP is looking for an experienced Chief Information Security Officer (CISO) to lead our security strategy across 40+ software and payments businesses. This pivotal role reports to the Chief Technology & Transformation Officer and requires managing security governance, compliance, and risk management. The ideal candidate will have extensive CISO experience, particularly in PCI-DSS compliance, and a strong understanding of embedding security within DevSecOps practices. The position offers a hybrid work model with competitive salary and benefits.
Chief Information Security Officer (CISO) Location: Hybrid Permanent ClearCourse is seeking an experienced Chief Information Security Officer (CISO) to lead and evolve our group wide security strategy across a diverse portfolio of 40+ software and payments businesses. Reporting to the Chief Technology & Transformation Officer, with a dotted line to the Board and Audit Committee, this is a pivotal executive leadership role responsible for security governance, operations, compliance, and risk management across a complex technology estate spanning payments, healthcare, and B2B SaaS. With ongoing M&A activity, active PCI-DSS obligations, and a rapidly evolving platform landscape, you'll play a critical role in protecting our customers, supporting business growth, and embedding security across the organisation. What you'll do Define and lead the Group's security strategy, policies, and governance framework Provide Board-level reporting on security posture, risks, and compliance activities Oversee security operations, including threat detection, incident response, and remediation Act as the executive lead during security incidents and manage external stakeholder communications Own PCI-DSS compliance across ClearAccept and ClearDebit payment platforms Lead the Group's Governance, Risk and Compliance (GRC) function, including ISO 27001, Cyber Essentials, PCI-DSS, and data protection obligations Manage relationships with auditors, regulators, cyber insurers, and certification bodies Lead security assessments and integration activities for acquisitions, driving alignment to Group standards Partner with Platform Engineering teams to embed security practices into development lifecycles without impacting delivery velocity Lead and develop the GRC function to support a proactive and risk aware security culture Previous experience operating at CISO level within a multi-product or multi-entity organisation Hands on experience leading PCI DSS compliance programmes and QSA assessments Proven expertise building and managing enterprise wide GRC frameworks and risk registers Experience assessing and integrating security functions following M&A activity Strong understanding of DevSecOps principles and embedding security into engineering practices Experience leading major security incidents, including external communications and stakeholder management Ability to influence at Board and executive leadership level Strong leadership skills with experience building and developing high performing security teams Competitive salary + benefits 25 days holiday + your birthday off Private medical insurance (Bupa) & health cash plan Life assurance & income protection Enhanced parental leave & family wellbeing support Perkbox discounts & perks Generous pension contributions Hybrid working model This is a rare opportunity to shape and lead the security strategy of a fast growing international software and payments group. You'll work at executive level, influence critical business decisions, and play a key role in safeguarding the future growth of the organisation. If you're passionate about security leadership and thrive in complex, evolving environments, we'd love to hear from you.
Aug 07, 2026
Full time
Chief Information Security Officer (CISO) Location: Hybrid Permanent ClearCourse is seeking an experienced Chief Information Security Officer (CISO) to lead and evolve our group wide security strategy across a diverse portfolio of 40+ software and payments businesses. Reporting to the Chief Technology & Transformation Officer, with a dotted line to the Board and Audit Committee, this is a pivotal executive leadership role responsible for security governance, operations, compliance, and risk management across a complex technology estate spanning payments, healthcare, and B2B SaaS. With ongoing M&A activity, active PCI-DSS obligations, and a rapidly evolving platform landscape, you'll play a critical role in protecting our customers, supporting business growth, and embedding security across the organisation. What you'll do Define and lead the Group's security strategy, policies, and governance framework Provide Board-level reporting on security posture, risks, and compliance activities Oversee security operations, including threat detection, incident response, and remediation Act as the executive lead during security incidents and manage external stakeholder communications Own PCI-DSS compliance across ClearAccept and ClearDebit payment platforms Lead the Group's Governance, Risk and Compliance (GRC) function, including ISO 27001, Cyber Essentials, PCI-DSS, and data protection obligations Manage relationships with auditors, regulators, cyber insurers, and certification bodies Lead security assessments and integration activities for acquisitions, driving alignment to Group standards Partner with Platform Engineering teams to embed security practices into development lifecycles without impacting delivery velocity Lead and develop the GRC function to support a proactive and risk aware security culture Previous experience operating at CISO level within a multi-product or multi-entity organisation Hands on experience leading PCI DSS compliance programmes and QSA assessments Proven expertise building and managing enterprise wide GRC frameworks and risk registers Experience assessing and integrating security functions following M&A activity Strong understanding of DevSecOps principles and embedding security into engineering practices Experience leading major security incidents, including external communications and stakeholder management Ability to influence at Board and executive leadership level Strong leadership skills with experience building and developing high performing security teams Competitive salary + benefits 25 days holiday + your birthday off Private medical insurance (Bupa) & health cash plan Life assurance & income protection Enhanced parental leave & family wellbeing support Perkbox discounts & perks Generous pension contributions Hybrid working model This is a rare opportunity to shape and lead the security strategy of a fast growing international software and payments group. You'll work at executive level, influence critical business decisions, and play a key role in safeguarding the future growth of the organisation. If you're passionate about security leadership and thrive in complex, evolving environments, we'd love to hear from you.
Senior Information Security Officer Please note: Although this role is listed as London-based, we're also happy to consider candidates based in Bournemouth or Stockport , with hybrid working from any of these office locations. Salary: Up to £80,000 + circa 16% bonus + excellent benefits The Opportunity An exciting opportunity has arisen for an experienced Senior Information Security Officer to join a growing Information Security function during a period of significant transformation. Reporting directly to the Chief Information Security Officer (CISO), you'll lead the Information Security Governance team and play a pivotal role in shaping how Information Security supports the wider business. This is not a traditional governance or compliance position. We're looking for someone who combines strong governance expertise with real operational Information Security experience. Someone who understands how to build practical, business-focused governance that enables delivery while managing risk effectively. The Role Leading a team of three Information Security professionals, you'll be responsible for: Leading the Information Security Governance function Managing and developing the Information Security Governance team Driving continual improvement of the Information Security Management System (ISMS) and ISO27001 framework Owning Information Security risk management and governance processes Leading internal and external audits and supporting regulatory compliance Developing and maintaining security policies, standards and governance frameworks Overseeing supplier and third-party security assurance Promoting a strong security culture through awareness and engagement Working closely with business and technology teams to embed security across projects, change initiatives and day-to-day operations This is a highly visible role offering genuine influence across the organisation and the opportunity to help shape the future direction of Information Security. The responsibilities include leading governance, information risk, ISMS, audits, security culture and regulatory compliance. About You You'll have a strong background in Information Security Governance, but you'll also understand security from an operational perspective. We're looking for someone with: Experience leading Information Security Governance within a complex organisation Strong knowledge of ISO27001, ISMS, Information Risk Management and recognised security frameworks Operational Information Security experience rather than a purely governance or compliance background Experience managing audits, risk and regulatory requirements Excellent stakeholder management and communication skills Experience leading or developing Information Security professionals A pragmatic approach to balancing business objectives with effective security governance Experience within a regulated environment would be advantageous. The Person You'll be someone who naturally builds credibility and confidence with colleagues at every level. You'll bring: Strong executive presence and excellent communication skills A collaborative and pragmatic approach Commercial awareness and sound judgement The ability to thrive in a fast-paced, evolving environment A proactive mindset with the confidence to challenge constructively A passion for building, improving and continuously developing Information Security capability If you're looking for a role where you can influence strategy, lead a talented team and make a lasting impact, we'd love to hear from you. Package Up to £80,000 salary 16% Annual bonus Hybrid working Excellent pension and benefits package Private healthcare Career development within a collaborative and forward-thinking Information Security function.
Aug 06, 2026
Full time
Senior Information Security Officer Please note: Although this role is listed as London-based, we're also happy to consider candidates based in Bournemouth or Stockport , with hybrid working from any of these office locations. Salary: Up to £80,000 + circa 16% bonus + excellent benefits The Opportunity An exciting opportunity has arisen for an experienced Senior Information Security Officer to join a growing Information Security function during a period of significant transformation. Reporting directly to the Chief Information Security Officer (CISO), you'll lead the Information Security Governance team and play a pivotal role in shaping how Information Security supports the wider business. This is not a traditional governance or compliance position. We're looking for someone who combines strong governance expertise with real operational Information Security experience. Someone who understands how to build practical, business-focused governance that enables delivery while managing risk effectively. The Role Leading a team of three Information Security professionals, you'll be responsible for: Leading the Information Security Governance function Managing and developing the Information Security Governance team Driving continual improvement of the Information Security Management System (ISMS) and ISO27001 framework Owning Information Security risk management and governance processes Leading internal and external audits and supporting regulatory compliance Developing and maintaining security policies, standards and governance frameworks Overseeing supplier and third-party security assurance Promoting a strong security culture through awareness and engagement Working closely with business and technology teams to embed security across projects, change initiatives and day-to-day operations This is a highly visible role offering genuine influence across the organisation and the opportunity to help shape the future direction of Information Security. The responsibilities include leading governance, information risk, ISMS, audits, security culture and regulatory compliance. About You You'll have a strong background in Information Security Governance, but you'll also understand security from an operational perspective. We're looking for someone with: Experience leading Information Security Governance within a complex organisation Strong knowledge of ISO27001, ISMS, Information Risk Management and recognised security frameworks Operational Information Security experience rather than a purely governance or compliance background Experience managing audits, risk and regulatory requirements Excellent stakeholder management and communication skills Experience leading or developing Information Security professionals A pragmatic approach to balancing business objectives with effective security governance Experience within a regulated environment would be advantageous. The Person You'll be someone who naturally builds credibility and confidence with colleagues at every level. You'll bring: Strong executive presence and excellent communication skills A collaborative and pragmatic approach Commercial awareness and sound judgement The ability to thrive in a fast-paced, evolving environment A proactive mindset with the confidence to challenge constructively A passion for building, improving and continuously developing Information Security capability If you're looking for a role where you can influence strategy, lead a talented team and make a lasting impact, we'd love to hear from you. Package Up to £80,000 salary 16% Annual bonus Hybrid working Excellent pension and benefits package Private healthcare Career development within a collaborative and forward-thinking Information Security function.
Closing Date: 25th May 2026 Role Purpose The Head of Cyber Security & Privacy is accountable for implementing and maintaining information security across Nando's UKI's operations, protecting customers and Nandocas whilst enabling the business to operate securely. This role ensures security policies, standards and practices agreed with and set by the Group CISO are effectively embedded across restaurants, digital platforms, supply chain and support functions within the Nando's UKI. The role is a mixture of working with peers and the CISO to set standards and policies and assuring those in market. This individual is also the Data Protection Officer for Nando's UKI. Reporting & Accountability Reports to: UKI Technology Director Works closely with: Group CISO (for guidance, standards, and frameworks). Accountable for: UKI cyber security posture, compliance and assurance. Works closely with the UKI Chief Risk Officer Works closely with the Head of Product & Delivery- Technology Platforms. Key Responsibilities Security Implementation & Operations Understand Group security Architecture and Implement Group information security policies and standards across Nando's UKI. Understand how Group policies add to UKIs threat vectors and plan accordingly Manage day-to-day security operations including monitoring, threat detection and incident response. Coordinate with the Security Operations Centre on Nando's UKI-specific threats and incidents. Maintain the Nando's UKI cyber security risk register and escalate significant risks. Conduct security assessments of Nando's UKI systems, suppliers and processes. Act as approver for the Data Protection Impact Assessment process. Incident Response Act as Nando's UKI incident commander for cyber security incidents Coordinate response with Group CISO for major incidents Document and report incidents following Group standards Implement lessons learned and track remediation actions Nando's UKI Stakeholder Engagement Build relationships with Nando's UKI leadership (Tech, People, Ops, Risk, Legal, Supply Chain) Ensure security is embedded in Nando's UKI initiatives, projects and training. Support the Nando's UKI CEO to understand and prioritise cyber security Translate technical security risks into business impact for Nando's UKI stakeholders Security Culture & Awareness Deliver security awareness training to Nando's UKI teams using Group materials Make security engaging and relevant to restaurant teams and support office staff Act as the face of security in the Nando's UKI - visible, approachable and credible Communicate security in line with Nando's values and tone of voice Maintain knowledge of the evolving threat landscape, relevant regulatory requirements, and industry standards applicable to Nando's (e.g. ISO 27001 and NIST) Keep abreast of emerging risks related to technology, data privacy, and cyber security Actively engage with reputable industry bodies, publications, and peer networks, and apply relevant insights to continuously assess whether the organisation's security posture, policies, and controls remain fit for purpose. Third-Party & Vendor Management Assess security risks of Nando's UKI-specific suppliers and vendors Work with Procurement to ensure security requirements in supplier contracts Monitor ongoing compliance of third parties with security standards Escalate significant third-party risks to Group CISO Compliance & Audit Ensure and demonstrate Nando's UKI compliance with Group security policies and relevant legislation (e.g. GDPR, local data protection laws) Coordinate Nando's UKI participation in security audits and assessments Maintain evidence and documentation for compliance reporting Support Group CISO with regulatory reviews affecting the Nando's UKI Architecture & Projects Review and approve security requirements for Nando's UKI technology initiatives Ensure secure configuration of Nando's UKI systems and infrastructure Work with Group CISO to implement identity and access management standards Support secure deployment of the Global Nando's Platform in the Nando's UKI Data Security Implement data classification and data lifecycle management practices Ensure sensitive data is appropriately protected across the Nando's UKI Monitor and report on data security metrics Investigate and remediate data security incidents Skills & Qualifications Essential 5+ years experience in information security, with at least 2 years in a leadership role Strong practical knowledge of security operations, incident response and risk management Experience implementing security frameworks (NIST CSF, ISO 27001 or similar) Ability to influence stakeholders without direct authority Excellent communication skills - can explain technical risks to non-technical audiences Understanding of GDPR and data protection principles Experience working in multi-site or retail/hospitality environments Desirable Relevant certifications (CISSP, CISM, Security+, CEH or similar) Experience with cloud security (AWS, Azure, GCP) Up to date knowledge of security tools (SIEM, EDR, vulnerability management) Understanding of secure development practices Experience in a franchised or multi-site organisation What Success Looks Like Year 1: Nando's UKI leadership understands and actively supports security priorities Clean audit outcomes against Group security standards Security embedded in all major Nando's UKI projects and initiatives Effective incident response demonstrated through exercises and/or real incidents High engagement rates with security awareness programmes Ongoing: Nando's UKI consistently meets Group security metrics and KPIs Strong working relationship with Group CISO and other Nando's UKI Heads of Security Proactive identification and mitigation of Nando's UKI-specific risks Security seen as an enabler rather than a blocker Positive feedback from Nando's UKI stakeholders on security support and guidance Heart and soul. Passion and personality. You may know us as the home of PERi-PERi goodness, but we're actually a people-first, chicken-second kind of place.
May 13, 2026
Full time
Closing Date: 25th May 2026 Role Purpose The Head of Cyber Security & Privacy is accountable for implementing and maintaining information security across Nando's UKI's operations, protecting customers and Nandocas whilst enabling the business to operate securely. This role ensures security policies, standards and practices agreed with and set by the Group CISO are effectively embedded across restaurants, digital platforms, supply chain and support functions within the Nando's UKI. The role is a mixture of working with peers and the CISO to set standards and policies and assuring those in market. This individual is also the Data Protection Officer for Nando's UKI. Reporting & Accountability Reports to: UKI Technology Director Works closely with: Group CISO (for guidance, standards, and frameworks). Accountable for: UKI cyber security posture, compliance and assurance. Works closely with the UKI Chief Risk Officer Works closely with the Head of Product & Delivery- Technology Platforms. Key Responsibilities Security Implementation & Operations Understand Group security Architecture and Implement Group information security policies and standards across Nando's UKI. Understand how Group policies add to UKIs threat vectors and plan accordingly Manage day-to-day security operations including monitoring, threat detection and incident response. Coordinate with the Security Operations Centre on Nando's UKI-specific threats and incidents. Maintain the Nando's UKI cyber security risk register and escalate significant risks. Conduct security assessments of Nando's UKI systems, suppliers and processes. Act as approver for the Data Protection Impact Assessment process. Incident Response Act as Nando's UKI incident commander for cyber security incidents Coordinate response with Group CISO for major incidents Document and report incidents following Group standards Implement lessons learned and track remediation actions Nando's UKI Stakeholder Engagement Build relationships with Nando's UKI leadership (Tech, People, Ops, Risk, Legal, Supply Chain) Ensure security is embedded in Nando's UKI initiatives, projects and training. Support the Nando's UKI CEO to understand and prioritise cyber security Translate technical security risks into business impact for Nando's UKI stakeholders Security Culture & Awareness Deliver security awareness training to Nando's UKI teams using Group materials Make security engaging and relevant to restaurant teams and support office staff Act as the face of security in the Nando's UKI - visible, approachable and credible Communicate security in line with Nando's values and tone of voice Maintain knowledge of the evolving threat landscape, relevant regulatory requirements, and industry standards applicable to Nando's (e.g. ISO 27001 and NIST) Keep abreast of emerging risks related to technology, data privacy, and cyber security Actively engage with reputable industry bodies, publications, and peer networks, and apply relevant insights to continuously assess whether the organisation's security posture, policies, and controls remain fit for purpose. Third-Party & Vendor Management Assess security risks of Nando's UKI-specific suppliers and vendors Work with Procurement to ensure security requirements in supplier contracts Monitor ongoing compliance of third parties with security standards Escalate significant third-party risks to Group CISO Compliance & Audit Ensure and demonstrate Nando's UKI compliance with Group security policies and relevant legislation (e.g. GDPR, local data protection laws) Coordinate Nando's UKI participation in security audits and assessments Maintain evidence and documentation for compliance reporting Support Group CISO with regulatory reviews affecting the Nando's UKI Architecture & Projects Review and approve security requirements for Nando's UKI technology initiatives Ensure secure configuration of Nando's UKI systems and infrastructure Work with Group CISO to implement identity and access management standards Support secure deployment of the Global Nando's Platform in the Nando's UKI Data Security Implement data classification and data lifecycle management practices Ensure sensitive data is appropriately protected across the Nando's UKI Monitor and report on data security metrics Investigate and remediate data security incidents Skills & Qualifications Essential 5+ years experience in information security, with at least 2 years in a leadership role Strong practical knowledge of security operations, incident response and risk management Experience implementing security frameworks (NIST CSF, ISO 27001 or similar) Ability to influence stakeholders without direct authority Excellent communication skills - can explain technical risks to non-technical audiences Understanding of GDPR and data protection principles Experience working in multi-site or retail/hospitality environments Desirable Relevant certifications (CISSP, CISM, Security+, CEH or similar) Experience with cloud security (AWS, Azure, GCP) Up to date knowledge of security tools (SIEM, EDR, vulnerability management) Understanding of secure development practices Experience in a franchised or multi-site organisation What Success Looks Like Year 1: Nando's UKI leadership understands and actively supports security priorities Clean audit outcomes against Group security standards Security embedded in all major Nando's UKI projects and initiatives Effective incident response demonstrated through exercises and/or real incidents High engagement rates with security awareness programmes Ongoing: Nando's UKI consistently meets Group security metrics and KPIs Strong working relationship with Group CISO and other Nando's UKI Heads of Security Proactive identification and mitigation of Nando's UKI-specific risks Security seen as an enabler rather than a blocker Positive feedback from Nando's UKI stakeholders on security support and guidance Heart and soul. Passion and personality. You may know us as the home of PERi-PERi goodness, but we're actually a people-first, chicken-second kind of place.