Chief InformationSecurityOfficer page is loaded Chief InformationSecurity Officerlocations: London, UKtime type: Full timeposted on: Posted Todayjob requisition id: JR100302 Who we are We're the people behind global loyalty currency, Avios, and home to two ambitious, growing businesses across Loyalty and Holidays. Each business has its own goals, strategy and team, but … story to tell our people and the rest of the world. This is where you come in. The opportunity We have a brand new opportunity for an experienced Chief InformationSecurityOfficer (CISO) to lead the information and cyber security strategy across IAG Loyalty companies, which include Loyalty (the Avios currency) and British Airways Holidays.Reporting … to the Chief Technology, Data & AI Officer you'll establish a unified security vision and governance framework, while tailoring risk-based solutions to the unique needs of each company.You'll be the principal advisor to the executive team and board on cybersecurity matters affecting our businesses, but you'll also play a key role across the wider IAG More ❯
InformationSecurityOfficer – International Law Firm (London-Based) Permanent | Hybrid Working | Competitive Salary I am working with a leading international law firm to support their search for an experienced and proactive InformationSecurityOfficer (ISO) to lead their global information and data security programme. This senior-level role offers the opportunity to … shape the firm’s long-term security strategy, drive ISO 27001 certification, and ensure the resilience of systems and data across offices in the UK, US, and Europe. The position reports to the Director of IT and works closely with regional IT teams and external partners. Key Responsibilities: Lead the firm’s informationsecurity governance framework across … all offices and platforms Maintain and enhance the ISO 27001-aligned InformationSecurity Management System (ISMS) Ensure compliance with frameworks including CIS Controls, NIST, ISO 27701, and GDPR Oversee incident response, threat detection, and access governance across systems such as iManage, Intapp, Aderant, Microsoft 365, and Azure Drive firm-wide security awareness and training initiatives Monitor regulatory More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Ryder Reid Legal
InformationSecurityOfficer – International Law Firm (London-Based) Permanent | Hybrid Working | Competitive Salary I am working with a leading international law firm to support their search for an experienced and proactive InformationSecurityOfficer (ISO) to lead their global information and data security programme. This senior-level role offers the opportunity to … shape the firm’s long-term security strategy, drive ISO 27001 certification, and ensure the resilience of systems and data across offices in the UK, US, and Europe. The position reports to the Director of IT and works closely with regional IT teams and external partners. Key Responsibilities: Lead the firm’s informationsecurity governance framework across … all offices and platforms Maintain and enhance the ISO 27001-aligned InformationSecurity Management System (ISMS) Ensure compliance with frameworks including CIS Controls, NIST, ISO 27701, and GDPR Oversee incident response, threat detection, and access governance across systems such as iManage, Intapp, Aderant, Microsoft 365, and Azure Drive firm-wide security awareness and training initiatives Monitor regulatory More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Ryder Reid Legal Ltd
InformationSecurityOfficer - International Law Firm (London-Based) Permanent | Hybrid Working | Competitive Salary I am working with a leading international law firm to support their search for an experienced and proactive InformationSecurityOfficer (ISO) to lead their global information and data security programme. This senior-level role offers the opportunity to … shape the firm's long-term security strategy, drive ISO 27001 certification, and ensure the resilience of systems and data across offices in the UK, US, and Europe. The position reports to the Director of IT and works closely with regional IT teams and external partners. Key Responsibilities: Lead the firm's informationsecurity governance framework across … all offices and platforms Maintain and enhance the ISO 27001-aligned InformationSecurity Management System (ISMS) Ensure compliance with frameworks including CIS Controls, NIST, ISO 27701, and GDPR Oversee incident response, threat detection, and access governance across systems such as iManage, Intapp, Aderant, Microsoft 365, and Azure Drive firm-wide security awareness and training initiatives Monitor regulatory More ❯
london (city of london), south east england, united kingdom Hybrid / WFH Options
Ryder Reid Legal
InformationSecurityOfficer – International Law Firm (London-Based) Permanent | Hybrid Working | Competitive Salary I am working with a leading international law firm to support their search for an experienced and proactive InformationSecurityOfficer (ISO) to lead their global information and data security programme. This senior-level role offers the opportunity to … shape the firm’s long-term security strategy, drive ISO 27001 certification, and ensure the resilience of systems and data across offices in the UK, US, and Europe. The position reports to the Director of IT and works closely with regional IT teams and external partners. Key Responsibilities: Lead the firm’s informationsecurity governance framework across … all offices and platforms Maintain and enhance the ISO 27001-aligned InformationSecurity Management System (ISMS) Ensure compliance with frameworks including CIS Controls, NIST, ISO 27701, and GDPR Oversee incident response, threat detection, and access governance across systems such as iManage, Intapp, Aderant, Microsoft 365, and Azure Drive firm-wide security awareness and training initiatives Monitor regulatory More ❯
slough, south east england, united kingdom Hybrid / WFH Options
Ryder Reid Legal
InformationSecurityOfficer – International Law Firm (London-Based) Permanent | Hybrid Working | Competitive Salary I am working with a leading international law firm to support their search for an experienced and proactive InformationSecurityOfficer (ISO) to lead their global information and data security programme. This senior-level role offers the opportunity to … shape the firm’s long-term security strategy, drive ISO 27001 certification, and ensure the resilience of systems and data across offices in the UK, US, and Europe. The position reports to the Director of IT and works closely with regional IT teams and external partners. Key Responsibilities: Lead the firm’s informationsecurity governance framework across … all offices and platforms Maintain and enhance the ISO 27001-aligned InformationSecurity Management System (ISMS) Ensure compliance with frameworks including CIS Controls, NIST, ISO 27701, and GDPR Oversee incident response, threat detection, and access governance across systems such as iManage, Intapp, Aderant, Microsoft 365, and Azure Drive firm-wide security awareness and training initiatives Monitor regulatory More ❯
InformationSecurity Consultant - Virtual CISO (vCISO) 💷 Up to £60,000 | 🌍 Hybrid My client is seeking an experienced cyber security professional to step into an InformationSecurityOfficer role, acting as a trusted advisor to a diverse portfolio of organisations. This is an opportunity to directly influence and shape cyber security strategies at board … level while embedding yourself as a valued extension of your clients’ security teams. Key Responsibilities Serve as a strategic security partner, helping clients to define, develop, and mature their cyber security roadmap. Take ownership of internal Security Improvement Plans, ensuring risks are reduced and resilience is increased. Lead governance and oversight activities, including risk reviews, board … level reporting, and mentoring client teams. Carry out security reviews across cloud, hybrid, and on-premises environments, identifying vulnerabilities and improvement areas. Provide guidance on compliance and frameworks such as ISO 27001, Cyber Assessment Framework (CAF), and Cyber Essentials. Contribute to incident readiness and response as part of the Cyber Security Incident Response Team (CSIRT). Actively contribute More ❯
InformationSecurity Consultant - Virtual CISO (vCISO) 💷 Up to £60,000 | 🌍 Hybrid My client is seeking an experienced cyber security professional to step into an InformationSecurityOfficer role, acting as a trusted advisor to a diverse portfolio of organisations. This is an opportunity to directly influence and shape cyber security strategies at board … level while embedding yourself as a valued extension of your clients’ security teams. Key Responsibilities Serve as a strategic security partner, helping clients to define, develop, and mature their cyber security roadmap. Take ownership of internal Security Improvement Plans, ensuring risks are reduced and resilience is increased. Lead governance and oversight activities, including risk reviews, board … level reporting, and mentoring client teams. Carry out security reviews across cloud, hybrid, and on-premises environments, identifying vulnerabilities and improvement areas. Provide guidance on compliance and frameworks such as ISO 27001, Cyber Assessment Framework (CAF), and Cyber Essentials. Contribute to incident readiness and response as part of the Cyber Security Incident Response Team (CSIRT). Actively contribute More ❯
InformationSecurity Consultant - Virtual CISO (vCISO) 💷 Up to £60,000 | 🌍 Hybrid My client is seeking an experienced cyber security professional to step into an InformationSecurityOfficer role, acting as a trusted advisor to a diverse portfolio of organisations. This is an opportunity to directly influence and shape cyber security strategies at board … level while embedding yourself as a valued extension of your clients’ security teams. Key Responsibilities Serve as a strategic security partner, helping clients to define, develop, and mature their cyber security roadmap. Take ownership of internal Security Improvement Plans, ensuring risks are reduced and resilience is increased. Lead governance and oversight activities, including risk reviews, board … level reporting, and mentoring client teams. Carry out security reviews across cloud, hybrid, and on-premises environments, identifying vulnerabilities and improvement areas. Provide guidance on compliance and frameworks such as ISO 27001, Cyber Assessment Framework (CAF), and Cyber Essentials. Contribute to incident readiness and response as part of the Cyber Security Incident Response Team (CSIRT). Actively contribute More ❯
InformationSecurity Manager - Contract (Inside IR35)6 Months Initially Milton Keynes/Hybrid Were looking for an experienced InformationSecurity Manager to take ownership of a key security improvement programme and help mature an existing InfoSec function. This role needs a trusted pair of hands someone who can quickly assess whats in place, bring clarity … and structure, and deliver real change. Youll lead the delivery of a 1m+ security improvement plan, working closely with technical teams and senior stakeholders to strengthen processes, governance, and controls. What were looking for: 10 - 15 years experience in InformationSecurity or Programme Delivery Proven track record leading or improving a security function Experience delivering securityMore ❯
Loughborough, Leicestershire, England, United Kingdom
Clear IT Recruitment Limited
Our client is seeking a Data Protection & InformationSecurityOfficer, to be based in their Loughborough office on a permanent full-time basis. Key Responsibilities: • Serve as the statutory Data Protection Officer (DPO). • Stay current with informationsecurity legislation and update related policies, procedures, and the company website accordingly. • Manage and coordinate responses … to Freedom of Information (FOI) and Data Protection requests, ensuring timely and accurate replies. • Investigate data breaches within required timeframes, recommending risk mitigation actions to protect data subjects and the company. • Ensure secure information handling and report security breaches per company policies. Desired Experience • Recent office administration experience. • Accurate record-keeping (electronic and paper). • Handling FOI … and Data Protection requests. • Interpreting and applying policy and legislation. • Presenting information in various settings. • Delivering training to diverse audiences. • Proficient in MS Office, databases, and spreadsheets. • Strong understanding of FOI, Data Protection Acts, and related legislation. Should you have any questions or wish to apply please do not hesitate to contact Clear Legal and Financial Recruitment. Please Note More ❯
Chief InformationSecurityOfficer (CISO) - Critical Infrastructure We are partnered with a world-leading IT company that underpins critical UK infrastructure (including the NHS). They are a mission-driven entity that protects the nation’s digital foundation from state-level cyberattacks. Up to £130k + 20% Bonus | Oxford (1-2 days a week) | Permanent You'll … networking, and threat analytics. The ability to influence and present at the Board/Executive level. Lead the transformation to a "world-class software organisation" by embedding DevSecOps and "security as code." Ensure compliance with ISO 27001, Cyber Essentials, and PSN CoC. Why join? . This organisation is a Public Benefit company committed to investing millions into social good. More ❯
strategic lead for safeguarding the integrity, confidentiality, and availability of data, systems, and operations across its global digital taxation platform. As a senior executive, the CISO will ensure that security is embedded in the architecture, products, operations, and deployment of services and solutions delivered to governments and digital service providers worldwide. This is a high-visibility role: you will … interact with national tax authorities, regulators, international stakeholders, and internal leadership to drive trust and resilience across all operations. Key Responsibilities Strategy & Vision Define and lead a global informationsecurity vision aligned with the mission to support fair and secure digital taxation across jurisdictions. Translate business objectives, regulatory frameworks, and threat landscapes into actionable security and risk … strategies. Shape the security culture: champion awareness, training, and security-first thinking from engineering to client-facing teams. Governance, Risk & Compliance Develop and maintain security policies, standards, and controls, tailored for cross jurisdictional compliance (e.g. GDPR, DORA, local tax/financial regulations). Lead periodic risk and security assessments (e.g. penetration testing, threat modeling, audit readiness More ❯
Overview The Interim CISO will provide immediate, strategic and operational security leadership on a fixed-term basis. The primary mandate is to conduct a rapid, high-impact review and uplift of critical security governance functions, focusing specifically on asset management, third-party assurance, and incident preparedness. Key Responsibilities and Deliverables: The successful candidate will be a hands-on … leader responsible for the following key reviews: 1. Group Information Asset Register (IAR) Review Audit and Validate the current IAR structure, completeness, and accuracy of Confidentiality, Integrity, and Availability (CIA) classifications. Establish a repeatable, documented process for the continuous identification, registration, and risk-linkage of all high-value information assets. 2. 3rd Party Assurance Process Uplift Assess and … Refine the entire Third-Party Risk Management (TPRM) lifecycle, identifying gaps in vendor security due diligence and ongoing monitoring. Define a tiered, risk-based methodology for assurance reviews, ensuring the rigor of the review matches the vendor's inherent risk to the organization. 3. Incident Response and Recovery Plan (IRRP) Validation Critically Review the current IRRP for clarity, compliance More ❯
Overview The Interim CISO will provide immediate, strategic and operational security leadership on a fixed-term basis. The primary mandate is to conduct a rapid, high-impact review and uplift of critical security governance functions, focusing specifically on asset management, third-party assurance, and incident preparedness. Key Responsibilities and Deliverables: The successful candidate will be a hands-on … leader responsible for the following key reviews: 1. Group Information Asset Register (IAR) Review Audit and Validate the current IAR structure, completeness, and accuracy of Confidentiality, Integrity, and Availability (CIA) classifications. Establish a repeatable, documented process for the continuous identification, registration, and risk-linkage of all high-value information assets. 2. 3rd Party Assurance Process Uplift Assess and … Refine the entire Third-Party Risk Management (TPRM) lifecycle, identifying gaps in vendor security due diligence and ongoing monitoring. Define a tiered, risk-based methodology for assurance reviews, ensuring the rigor of the review matches the vendor's inherent risk to the organization. 3. Incident Response and Recovery Plan (IRRP) Validation Critically Review the current IRRP for clarity, compliance More ❯
Overview The Interim CISO will provide immediate, strategic and operational security leadership on a fixed-term basis. The primary mandate is to conduct a rapid, high-impact review and uplift of critical security governance functions, focusing specifically on asset management, third-party assurance, and incident preparedness. Is this your next job Read the full description below to find … and do not hesitate to make an application. Key Responsibilities and Deliverables: The successful candidate will be a hands-on leader responsible for the following key reviews: 1. Group Information Asset Register (IAR) Review Audit and Validate the current IAR structure, completeness, and accuracy of Confidentiality, Integrity, and Availability (CIA) classifications. Establish a repeatable, documented process for the continuous … identification, registration, and risk-linkage of all high-value information assets. 2. 3rd Party Assurance Process Uplift Assess and Refine the entire Third-Party Risk Management (TPRM) lifecycle, identifying gaps in vendor security due diligence and ongoing monitoring. Define a tiered, risk-based methodology for assurance reviews, ensuring the rigor of the review matches the vendor's inherent More ❯
Overview The Interim CISO will provide immediate, strategic and operational security leadership on a fixed-term basis. The primary mandate is to conduct a rapid, high-impact review and uplift of critical security governance functions, focusing specifically on asset management, third-party assurance, and incident preparedness. Is this your next job Read the full description below to find … and do not hesitate to make an application. Key Responsibilities and Deliverables: The successful candidate will be a hands-on leader responsible for the following key reviews: 1. Group Information Asset Register (IAR) Review Audit and Validate the current IAR structure, completeness, and accuracy of Confidentiality, Integrity, and Availability (CIA) classifications. Establish a repeatable, documented process for the continuous … identification, registration, and risk-linkage of all high-value information assets. 2. 3rd Party Assurance Process Uplift Assess and Refine the entire Third-Party Risk Management (TPRM) lifecycle, identifying gaps in vendor security due diligence and ongoing monitoring. Define a tiered, risk-based methodology for assurance reviews, ensuring the rigor of the review matches the vendor's inherent More ❯
CISO | Global SaaS | PE-Backed | Build & Lead Security Function A high-growth global SaaS business with 600 people worldwide (130 in Engineering) is entering a critical phase: consolidating multiple products and scaling from ~$100m ARR to ~$200m over the next three years. Backed by a leading private equity firm, this is a rare opportunity to own and build the … security function from scratch , shaping strategy, operations, and security culture across the company. We’re looking for a hands-on, technically credible CISO who thrives at the intersection of strategy and execution. You’ll define the security agenda, build the team, implement robust practices across engineering and product teams, and create a culture where security is … embedded into every aspect of the business. You’ll need experience scaling security in SaaS, ideally in PE-backed environments, and a track record of delivering measurable improvements across people, processes, and technology. Reporting to the CTO, you’ll take full ownership of the security function, partnering closely with Engineering, Product, and leadership to protect growth, enable innovation More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Futurist
CISO | Global SaaS | PE-Backed | Build & Lead Security Function A high-growth global SaaS business with 600 people worldwide (130 in Engineering) is entering a critical phase: consolidating multiple products and scaling from ~$100m ARR to ~$200m over the next three years. Backed by a leading private equity firm, this is a rare opportunity to own and build the … security function from scratch , shaping strategy, operations, and security culture across the company. We’re looking for a hands-on, technically credible CISO who thrives at the intersection of strategy and execution. You’ll define the security agenda, build the team, implement robust practices across engineering and product teams, and create a culture where security is … embedded into every aspect of the business. You’ll need experience scaling security in SaaS, ideally in PE-backed environments, and a track record of delivering measurable improvements across people, processes, and technology. Reporting to the CTO, you’ll take full ownership of the security function, partnering closely with Engineering, Product, and leadership to protect growth, enable innovation More ❯
CISO Global SaaS PE-Backed Build & Lead Security Function A high-growth global SaaS business with 600 people worldwide (130 in Engineering) is entering a critical phase: consolidating multiple products and scaling from $100m ARR to $200m over the next three years. Backed by a leading private equity firm, this is a rare opportunity to own and build the … security function from scratch , shaping strategy, operations, and security culture across the company. We're looking for a hands-on, technically credible CISO who thrives at the intersection of strategy and execution. You'll define the security agenda, build the team, implement robust practices across engineering and product teams, and create a culture where security is … embedded into every aspect of the business. You'll need experience scaling security in SaaS, ideally in PE-backed environments, and a track record of delivering measurable improvements across people, processes, and technology. Reporting to the CTO, you'll take full ownership of the security function, partnering closely with Engineering, Product, and leadership to protect growth, enable innovation More ❯
london, south east england, united kingdom Hybrid / WFH Options
Futurist
CISO | Global SaaS | PE-Backed | Build & Lead Security Function A high-growth global SaaS business with 600 people worldwide (130 in Engineering) is entering a critical phase: consolidating multiple products and scaling from ~$100m ARR to ~$200m over the next three years. Backed by a leading private equity firm, this is a rare opportunity to own and build the … security function from scratch , shaping strategy, operations, and security culture across the company. We’re looking for a hands-on, technically credible CISO who thrives at the intersection of strategy and execution. You’ll define the security agenda, build the team, implement robust practices across engineering and product teams, and create a culture where security is … embedded into every aspect of the business. You’ll need experience scaling security in SaaS, ideally in PE-backed environments, and a track record of delivering measurable improvements across people, processes, and technology. Reporting to the CTO, you’ll take full ownership of the security function, partnering closely with Engineering, Product, and leadership to protect growth, enable innovation More ❯
london (city of london), south east england, united kingdom Hybrid / WFH Options
Futurist
CISO | Global SaaS | PE-Backed | Build & Lead Security Function A high-growth global SaaS business with 600 people worldwide (130 in Engineering) is entering a critical phase: consolidating multiple products and scaling from ~$100m ARR to ~$200m over the next three years. Backed by a leading private equity firm, this is a rare opportunity to own and build the … security function from scratch , shaping strategy, operations, and security culture across the company. We’re looking for a hands-on, technically credible CISO who thrives at the intersection of strategy and execution. You’ll define the security agenda, build the team, implement robust practices across engineering and product teams, and create a culture where security is … embedded into every aspect of the business. You’ll need experience scaling security in SaaS, ideally in PE-backed environments, and a track record of delivering measurable improvements across people, processes, and technology. Reporting to the CTO, you’ll take full ownership of the security function, partnering closely with Engineering, Product, and leadership to protect growth, enable innovation More ❯
slough, south east england, united kingdom Hybrid / WFH Options
Futurist
CISO | Global SaaS | PE-Backed | Build & Lead Security Function A high-growth global SaaS business with 600 people worldwide (130 in Engineering) is entering a critical phase: consolidating multiple products and scaling from ~$100m ARR to ~$200m over the next three years. Backed by a leading private equity firm, this is a rare opportunity to own and build the … security function from scratch , shaping strategy, operations, and security culture across the company. We’re looking for a hands-on, technically credible CISO who thrives at the intersection of strategy and execution. You’ll define the security agenda, build the team, implement robust practices across engineering and product teams, and create a culture where security is … embedded into every aspect of the business. You’ll need experience scaling security in SaaS, ideally in PE-backed environments, and a track record of delivering measurable improvements across people, processes, and technology. Reporting to the CTO, you’ll take full ownership of the security function, partnering closely with Engineering, Product, and leadership to protect growth, enable innovation More ❯
Birmingham, England, United Kingdom Hybrid / WFH Options
Morson Edge (Technology)
InterQuest are exclusively representing a leading bank in identifying a CISO to join the firm on a permanent basis. The role would play an integral part of the enterprise security function leading on design and implementation of security strategy for the bank. This role be a hybrid working model based in Birmingham with occasional travel to other sites … across the bank with key stakeholders such as the board and c-suite and provide strategic review and potentially redesign of 1st line responsibilities. Responsibilities would include: Leading the security risk function for the bank Monitor, report and flag key risk and controls Policy development alongside a good knowledge of PRA/FCA To be considered you would need More ❯