Head of Information Security

Bravura Solutions LimitedLondon, EnglandOn-siteFull-timePrincipal, 12–15+ yearsListed 1 hour ago

Apply now

About this role

### Description & Requirements:
Bravura’s Commitment and Mission
At Bravura Solutions, collaboration, diversity and excellence matter. We value your ideas, giving you room to be curious and innovate in an exciting, fast-paced, and flexible environment. We look for many different skills and abilities, as well as how you can add value to Bravura and our culture.
As a Global FinTech market leader and ASX listed company, Bravura is a trusted partner to over 350 leading financial services clients, delivering wealth management technology and products. We invest significantly in our technology hubs and innovation labs, which inspire and drive our creative, future-focused mindset. We take pride in developing cutting-edge, digital first technology solutions that support our clients to achieve financial security and prosperity for their customers.

Role Description

Bravura is seeking an experienced and commercially minded Head of Information Security to lead the execution and continual improvement of our global information security capability.

Reporting directly to the Global Head of IT (Acting CISO), this role will be the most senior dedicated security role in the business. It will be responsible for leading Information Security Operations and Security Architecture across the organisation, ensuring that security services, controls, processes and governance frameworks effectively protect Bravura, its customers, employees and partners.

The Head of Information Security will play a key leadership role in shaping and delivering Bravura's information security strategy, translating strategic objectives into practical roadmaps, measurable outcomes and operational excellence.

This role combines strategic leadership with operational accountability and requires an individual who can confidently engage with executive stakeholders, regulators, auditors, customers and technology teams whilst leading a high-performing security function.

The successful candidate will lead the team responsible for security operations, incident management and response, vulnerability management, cyber risk management and security architecture, while working closely with outsourced security service providers.

Key Accountabilities

Information Security Leadership

- Lead and develop Bravura's global Information Security function, fostering a culture of accountability, collaboration and continuous improvement
- Partner with the Global Head of IT (Acting CISO) to develop and evolve the information security strategy, operating model and security roadmap
- Translate strategic objectives into actionable plans, measurable outcomes and operational improvements
- Provide leadership, coaching and development for a team of security professionals across security operations and security architecture
- Build strong relationships across technology and business functions to ensure security is embedded into decision-making and delivery processes

Security Operations & Incident Response

- Own the operational effectiveness of Bravura's information security controls and services
- Lead incident management and cyber incident response activities, ensuring effective preparedness, response, recovery and post-incident review processes
- Oversee relationships with outsourced security service providers, including SIEM and Managed Detection and Response partners
- Ensure security monitoring, threat detection and response capabilities remain effective and aligned to business risk
- Drive continual improvements in security operations processes, tooling and performance

Cyber Risk Management

- Lead the identification, assessment, management and reporting of information security risks across the organisation
- Maintain and mature cyber risk management frameworks, methodologies and governance processes
- Ensure security risks are appropriately assessed, documented, prioritised and communicated to senior stakeholders
- Drive effective risk treatment plans and track progress against agreed remediation activities
- Provide regular reporting and insights to senior leadership and governance forums
- Lead threat identification and modelling activities including formal workshops

Vulnerability Management & Security Assurance

- Own Bravura's vulnerability management programme and drive continuous improvement in security posture
- Establish effective governance, prioritisation and remediation processes for security vulnerabilities
- Monitor and report on security trends, vulnerabilities and areas of emerging risk
- Drive security assurance activities including penetration testing, technical assessments and control validation exercises
- Ensure security weaknesses are identified, understood and remediated appropriately

Security Architecture & Engineering Governance

- Lead the Security Architecture function and establish security standards, patterns and security-by-design principles
- Ensure security requirements are embedded within technology projects, cloud services and operational environments
- Provide governance and oversight of security architecture decisions across the organisation
- Act as a trusted advisor to technology leaders on security risks and control design
- Support secure adoption of new technologies and digital transformation initiatives

Governance, Audit & Compliance

- Lead security governance activities and ensure effective reporting across the organisation
- Support regulatory, client and audit requirements through effective control design, evidence management and remediation activities
- Support the successful delivery of internal and external audits
- Maintain and mature controls aligned to recognised frameworks and standards including ISO 27001, NIST Cyber Security Framework, CIS Controls, APRA CPS 234 and relevant regulatory obligations, in partnership with our Governance, Risk & Compliance team
- Partner with Risk, Compliance and Infosec Assurance teams to strengthen organisational assurance

Executive Stakeholder Engagement

- Present security risks, trends, incidents, control effectiveness and strategic recommendations to senior leaders and governance forums
- Support the Global Head of IT (Acting CISO) in executive communications and board-level reporting
- Build strong relationships with senior business stakeholders and act as a trusted advisor on information security matters
- Support customer and prospect discussions where security assurance and trust are critical to business outcomes

Skills & Experience

Essential

- Significant experience in Information Security leadership roles, including responsibility for security operations, risk management and security governance
- Experience leading high-performing cyber security or information security teams
- Proven experience supporting the development and implementation of information security strategies, roadmaps and operating models
- Experience managing major security incidents and incident response activities
- Strong experience in vulnerability management, security assurance and risk management
- Experience leading the infosec aspects of external audits and supporting regulatory compliance activities
- Proven ability to influence senior stakeholders and communicate effectively with technical and non-technical audiences
- Experience managing third-party security service providers and strategic technology partners

Technical Knowledge

Strong understanding of:

- Security Operations
- Incident Response
- Vulnerability Management
- Security Architecture
- Cloud Security
- Security Engineering
- Threat Detection and Monitoring
- Identity and Access Management
- Network Security
- Application Security
- Security Governance and Risk Management
- Regulatory and Compliance Requirements
- Rapid7 or either managed SIEM solutions

Experience with industry frameworks and standards such as:

- ISO 27001
- NIST Cyber Security Framework
- CIS Controls
- APRA CPS 234
- GDPR and privacy-related security obligations
- SOC and assurance frameworks

Key Attributes

- Calm, credible and delivery-focused
- Pragmatic in balancing change with stability
- Comfortable operating at both strategic and operational levels
- Clear decision-maker with strong ownership mindset
- Commercial awareness and pragmatic decision-making
- Builds trust and bridges across technology and business functions
- Confident working across multiple teams across the globe
- Highly driven with strong problem-solving skills
- Comfortable operating in a lean environment and shaping new processes

Corporate Responsibilities Environmental & Health & Safety

- Ensure Annual Training is competed as required.
- Review Annually & Comply with all Company policies related to H&S and Environmental Management Systems
- Report all/any breaches or accidents/near misses immediately when discovered.

Working at Bravura
Our people are the heart of our business. We work hard to provide a rich employee experience and a robust framework for ongoing career development.
So, what’s next?
We make hiring decisions based on your experience, skills and passion so even if you don’t match every listed skill or tick all the boxes, we’d still love to hear from you.
Please note that interviews are primarily conducted virtually and if you require any reasonable adjustments or would like to note which pronouns you use, please let us know.
All final applicants for this position will be asked to consent to a criminal record and background check. Please note that people with criminal records are not automatically barred from applying for this position. Each application will be considered on its merits.