- Company Name
- PEXA UK
- Job Title
- Head of Cyber Security
- Job Description
-
**Job Title:** Head of Cyber Security
**Role Summary:**
Senior leader responsible for defining and executing the cyber security strategy for PEXA UK and its subsidiaries (Smoove, Optima Legal). Oversees Security Operations (SOC), Security Engineering, and Information Security & Governance functions, ensuring protection of digital assets, compliance with ISO 27001, FCA regulations, and lender assurance requirements. Drives security‑by‑design, incident response, threat detection, and a culture of security awareness across the organization.
**Expectations:**
- Develop and deliver a UK‑focused cyber security roadmap aligned with global objectives.
- Serve as the primary security authority for three UK brands.
- Lead, mentor, and expand a multidisciplinary security team.
- Represent security priorities in executive forums, audits, and lender assurance discussions.
- Continuously improve detection and response capabilities using leading security tools.
- Ensure compliance with ISO 27001, FCA standards, SOC audits, and partner assurance programs.
- Embed security practices into engineering, legal, risk, and operations processes.
- Communicate cyber risk, maturity, and incident status transparently to senior leadership.
**Key Responsibilities:**
- Define and maintain the cyber security strategy, policies, standards, and control frameworks.
- Oversee SOC operations: threat monitoring, incident response, and resolution.
- Manage end‑to‑end vulnerability management (scanning, prioritisation, remediation tracking).
- Direct secure configuration, endpoint management, and patch compliance across hybrid Azure/AWS environments.
- Lead ISO 27001, FCA, SOC audit preparation, evidence collection, and control testing.
- Coordinate with third‑party security providers (e.g., Blazeguard, CCX) and oversee vendor risk assessments.
- Drive security awareness programs: training, phishing simulations, and education initiatives.
- Report on cyber risk metrics, maturity assessments, and security incidents to the UK leadership team.
**Required Skills:**
- Proven senior leadership in cyber security (5+ years in a comparable role).
- Deep knowledge of ISO 27001, FCA, SOC 2, and related compliance frameworks.
- Expertise in SOC management and incident response.
- Proficiency with detection platforms (Cortex XDR, Splunk), email security (Abnormal Security), and analytics (Nucleus).
- Strong background in vulnerability management and remediation processes.
- Experience securing cloud environments (Azure, AWS) and implementing secure architecture.
- Ability to influence cross‑functional stakeholders and build security‑focused culture.
- Excellent communication, reporting, and executive presentation skills.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, Engineering, or related field (or equivalent experience).
- Professional certifications such as CISSP, CISM, CISA, ISO 27001 Lead Implementer/Auditor, and/or CCSP preferred.
- Demonstrated track record of leading security teams and delivering compliance outcomes.