Head of IT Security

Incite InsightLondon, EnglandOn-siteFull-timeListed 1 hour ago

Apply now

About this role

JOB PROFILE

Job title: Head of IT Security

Hybrid Role (2 Days per Week from HQ Offices SE5 London)

Purpose:
Responsible for defining the vision and setting and implementing the strategy for IT risk management, information security and cyber security, within the UK & Ireland (UKI) Territory.

Leading on the understanding of emerging security trends, risks, guidelines , technologies and applicable laws, regulations, and contractual requirements.

Responsible for all IT security risk and vulnerability identification and assessment,
and the resulting mitigating actions

Leading on organisational and behavioural change in relation to IT security, at all
levels, by education and collaboration.

The organisation has approximately 7000 IT users across approximately 900 locations, comprising of a comprehensive IT infrastructure delivering several line- of-business systems which reach out to all staff. Primarily based at Territorial Headquarters in London the IT Department is responsible for the entire IT infrastructure, service desk support, corporate systems, IT provisioning, information security, telephony (landline and mobile), IT project management, and management information.

Organisation Chart
Chief Information Officer
Head of IT Security
Assistant Head of Information Security

Report to:

Chief Information Officer

Accountable to:

Chief Information Officer, Secretary for Business
Administration, IT Strategy

You will

- Define the vision, and set and implement the strategy for IT risk management, information security and cyber security within the UK & Ireland (UKI) Territory, to ensure the organisations information assets are adequately protected

- Develop an organisation wide risk-based approach to threats, so reducing threat exposure through vulnerability identification, assessment, and remediation actions.
- Take responsibility for all IT risk management, information security and cyber security matters in relation to product/vendor selection and Missional contract negotiation, to mitigate security threats and ensure ongoing contract compliance
- Take organisational responsibility for IT security incident response planning at security breach investigation, and assist with any associated disciplinary, public relations and legal matters, to enable recovery and legal compliance in the event of a disaster
- Lead and manage the Security team of employee’s, vendors & contractors and associated budgets, to ensure uninterrupted service and value for money
- Establish and lead the Information Security Forum, to support effective decision making and improve organisation understanding
- Develop an enterprise information security programme, so establishing a cyber savvy workforce that can make the right decisions for safe and efficient operations, so minimising the risk of the organisation being exposed to security threats
- Communicate objectives and key results to the Executive Committee , Board of Directors, and other stakeholders, including a clear and measurable view of Information and Cyber Security, to ensure that security activities meet strategic objectives.
You have
Extensive demonstratable IT risk management, information security and cyber security experience at a strategic level, in a geographically diverse and multi-disciplinary organisation

Key working relationships

Senior leaders, regularly with Audit Director, Territorial Risk and Compliance Manager, Mission contract holders, Procurement, HR, Legal, Data Protection Officer and IT Steering Board.

External suppliers and out-tasked service providers

Government bodies e.g., Home Office

Sub Contracted service providers

People management:

Assistant Head of Information Security and other specialist
consultants/contractors and out tasked service providers(3-6
people).

Operating budget:

c£1.5- 2m covering specialist security tools, audits, services,
awareness courses, certifications

- Expert level subject matter in IT risk management, information security and cyber security, with the proven ability to apply that knowledge effectively within the workplace, with the drive to keep updated with all relevant statutory and best practice developments, and influence organisational thinking
- Demonstrable proven ability of planning at a strategic level with a 3-5 year time horizon
- Demonstrable excellent communication skills (written, verbal, and presentational) with the proven ability to convey complex ideas/processes/procedures to technical & non technical audiences, up to Board level, with the intention of influencing decision making and/or changing behaviours
- Excellent interpersonal skills with the ability to influence at a senior level, and develop strong, successful, collaborative, and influential working relationships at all levels of seniority within an organisation
- Proven ability to think critically, you are a solution focussed individual with demonstrable ability to analyse and improve existing processes and procedures to positively influence performance and outcomes
- Proven strong financial management skills with previous experience of managing budgets developing spending plans, and delivering financial reporting as required
- Excellent leadership and management skills with the ability to motivate employees and teams, identify and nurture talent, manage performance effectively, and provide practical emotional and pastoral support to deliver organisational objectives
- Educated to MSc Information Security degree level and/or with equivalent relevant practical experience and certified Information Systems Security Professional, Certified Information Security Manager and ISO27001 Practitioner
- The ability to work flexibly to deliver the requirements of your role such as evening work, weekend work, unsociable hours and occasional overnight stays for meetings and visits throughout the Territory. Often at short notice as critical changes must be made outside core hours.
You may have
- Experience of successfully implementing complex projects with responsibility for delivering the full project management cycle including initiation, planning, execution monitor and control
- Experience of working in the not-for-profit sector
- Understanding of ITIL service processes and management relevant to information security
How criteria will be assessed - (A) application form; (I) interview; (T) test;
(P) presentation and (R) references.
We expect you to exhibit behaviours that model our values of integrity;
accountability; compassion; passion; respect and boldness