Director of Cyber Security
Director of Cyber Security/ Head of Security Engineering /Deputy CISO (Interim)
Department: Group Information Security
Location: Remote / Hybrid
Reports to: Chief Information Security Officer (CISO)
Contract: Interim, initial 6-month term (likely extension to 12 months)
About Our Client
Our client is a global, multi-division technology and services organisation supporting leading brands across an international client base. Having grown significantly through acquisition, the group is now investing heavily in maturing its information security function across a large, federated, multi-region organisation.
Role Summary
The Head of Services and Engineering is accountable for the day-to-day operation of mission-critical information security platforms, architectural best practice, and business-facing security services across the group.
Working alongside the Head of Security Governance, Risk and Compliance and the Head of Security Operations in the Office of the CISO, this person directs the design, development and delivery of services and architectural standards that ensure the business can meet the dynamic demands of its clients and markets, while maintaining the confidentiality, integrity and availability of information systems and data at all times.
The role carries additional accountability to maintain operational business continuity, and will deputise for the CISO in their absence — for example during a major incident or crisis, or to cover extended leave or extraordinary business assignments.
This is also a transformation-focused leadership role: the incumbent will take ownership of an existing, distributed engineering and architecture team that currently lacks consistent structure, documentation and process maturity, and will lead them through a stabilisation-to-transformation journey — defining services, building trust, and establishing operational rigour.
Key Responsibilities
- Lead a team of domain security specialists responsible for architectural outputs supporting the information security management system, ensuring security by design across the technology estate and optimal operation of security platforms.
- Manage the security service catalogue — service definitions and design, quality standards, KPIs and reporting — across Project and Programme support, Engineering and Architecture, Empowered Workforce (culture, training, communications and development), and Security Service Management (IT Service Management). Drive continuous improvement of repeatable processes to ensure quality of delivery, first-time fix, and customer satisfaction.
- Lead and direct a group of solutions analysts assigned to projects and programmes across the business, ensuring every division has the support needed to specify, design, build, implement and run secure and resilient solutions.
- Direct enterprise security architecture through the publication, implementation and maintenance of reference architectures, design principles and standards aligned to the organisation's ISMS, legal and privacy policies, and AI security governance strategy. Represent the security domain at the Design Authority Committee.
- Act as a key decision-maker in the selection of security technologies supporting the CISO's security strategy and the wider technical strategy.
- Manage strategic vendor relationships pertaining to the organisation's security posture and capabilities, working alongside peers and senior leadership.
- Jointly with the Head of Governance, Risk and Compliance, establish minimum security baselines and overarching principles of information security to drive operational consistency and manage risk within defined tolerances.
- Hold day-to-day responsibility for budget consolidation and business reporting, including regular reporting to executive leadership, board and investor stakeholders.
- Direct the "Empowered Workforce" programme — driving an effective security culture through awareness, training and development (including mandatory literacy, context and role-based training), phishing and deepfake awareness, personnel and physical security awareness, and ongoing communications.
- Champion AI and automation strategy across the security function, identifying and implementing opportunities to drive efficiency and control cost.
- Deputise for the CISO when required, as a delegate of authority.
Qualifications and Core Competencies
- 10+ years in information security with progressive technical and strategic leadership responsibility
- Demonstrated experience designing and governing enterprise security architecture across multiple domains (network, identity, cloud, endpoint, data)
- Experience building and leading security engineering teams and cross-functional security programmes
- Deep knowledge of at least three security domains, with working breadth across all (architecture, cloud, identity, data/application security, endpoint, network, cryptography, AI)
- Proven ability to operate at both strategic and execution levels — comfortable in board-level discussions and hands-on architectural review
- Experience with ISMS frameworks (ISO 27001, NIST CSF) at governance, implementation and audit-readiness levels
- Track record of translating governance requirements into implementable technical standards, patterns and awareness programmes
- Experience managing security architecture review boards or equivalent technical governance bodies
- Experience leading security awareness and culture change programmes at scale
- Strong vendor management skills for enterprise security and awareness platforms
- Excellent stakeholder communication skills, able to represent the security function to executive leadership, board committees, technology partners and business stakeholders
Desirable
- Experience with security transformation programmes in multi-division, multi-region organisations
- Familiarity with AI/ML security, LLM governance, and automation platforms (e.g. SOAR)
- Experience operating in a matrix organisation with distributed teams across multiple time zones
- CISSP, CISM, SABSA, or equivalent senior security certification
- Experience with agile delivery in a security context (Scrum/Kanban for security engineering)
- Experience deputising for, or directly supporting, a CISO in a global enterprise
Our client is committed to equal opportunities and welcomes applications from all qualified candidates.
- Seniority Level
- Director
- Industry
- Broadcast Media Production and Distribution
- Computer Games
- Employment Type
- Contract
- Job Functions
- Information Technology
- Skills
- Information Security
- Certified Information Security Manager (CISM)
- SABSA
- Information Security Management System (I