- Company Name
- Jewson
- Job Title
- Director of Information (Cyber) Security - UK
- Job Description
-
Job title: Director of Information (Cyber) Security
Role Summary: Lead the strategic direction, operational excellence, and continuous improvement of information and cyber security for the UK business unit. Drive governance, risk management, compliance, incident response, and a security‑aware culture that aligns with business objectives and digital transformation goals.
Expactations:
- Define and publish a UK business unit Information & Cyber Security (ICS) strategy and vision aligned to group strategy.
- Develop and implement a roadmap of security improvements and architectural plans.
- Govern UK security policies, standards, and technical controls while overseeing risk management and audit activities.
- Lead incident‑response planning and support the Global Security Operations Center.
- Deliver executive‑level management information, cyber‑security intelligence, and insights to support decision‑making.
- Ensure compliance with applicable laws, regulations, and standards (ISO 27001, NIST, GDPR, etc.).
Key Responsibilities:
- Establish and sustain UK‑specific security strategy, vision, and improvement program.
- Develop, enforce, and monitor security policies, standards, and technical controls.
- Direct risk identification, assessment, and mitigation across IT and business functions.
- Plan, coordinate, and exercise incident response and business continuity events.
- Build and lead a multidisciplinary UK IPC team; mentor and develop staff.
- Provide regular security metrics, reports, and intelligence to senior management.
- Engage with business units to integrate security into technology and business planning.
Required Skills:
- Proven leadership of large, complex cyber‑security teams.
- Deep expertise in security strategy, governance, risk management, and compliance frameworks (ISO 27001, NIST, GDPR, Cyber Essentials).
- Strong experience in policy development, technical controls, security audits, third‑party risk, and vendor assessments.
- Ability to influence and communicate across technical and non‑technical stakeholders.
- Proficiency with ITIL, Agile, and change‑management practices.
- Demonstrated success in driving cultural change and building security‑centric communities.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Engineering, or related field (Master’s preferred).
- Minimum 10–12 years of experience in risk, security, or IT roles.
- Professional security certifications highly desirable (CISSP, CISM, CISA, CRISC).
Huddersfield, United kingdom
On site
Senior
29-10-2025