About you
Do you thrive on shaping information security goals and setting the direction and vision of information security?
Does identifying potential security vulnerabilities across multiple platforms and planning remediation activity come as second nature to you?
Do you have the technical security expertise to increase the maturity level of information security operations?
Do you have a good track record of success in managing information and cyber security incidents and data breaches?
If so, then you could be just what we are looking for. Read on to find out more…
The role
As Head of Information Security, your role will be to develop, shape and update the Company’s information security capability, ensuring it remain secure against an ever-changing threat landscape.
Key responsibilities include:
Information security strategy
- Create and maintain the Company’s strategy, ensuring alignment to the Company’s strategy and business goals
- Communicate the information security strategy to relevant parties, providing assurance of policies, procedures, and systems
- Develop, maintain, and expand the information security management system (‘ISMS’)
- Responsible for the Company’s information security capability, ensuring it remains secure against an ever-changing threat landscape
Operational input
- Contribute to design and architectural decisions and improve approach to the Company’s threat modelling
- Lead on information security incidents and work directly with internal teams and external parties on containment and mitigation activities
- Execute threat simulations
- Assess emerging and potential security threats and acting proactively to mitigate relevant threats
- End to end vulnerability management
- Manage security toolset.
Experience/qualifications
- Industry certifications such as CISSP, CISM, CISA, or equivalent
- Expert in information security
- Excellent knowledge of security frameworks, standards, and regulations, including ISO 27001, SOC 2, HIPAA, GDPR, etc
- Strong understanding of cloud security principles and best practices, particularly in AWS/Azure
- Experience in managing security incidents and leading incident response
- Good communication and interpersonal skills, with the ability to effectively communicate security-related questions to technical and non-technical stakeholders (employees, customers, or partners)
- Project management skills, with the ability to manage projects such as processes implementation and improvement, security systems implementation
- Ability to collaborate cross-functionally and influence stakeholders at all levels of the organisation
About us
Heywood combines a passion for software with Agile methodologies to create modern software and data solutions and services for businesses, pension providers and third parties that help transform how their members and customers manage their lifelong financial journeys.
Working for an expanding established market leader, you will have a real voice to influence our evolution. Continued learning and progression is ingrained in our daily life, encouraged through a variety of forums from e-learning subscriptions and a monthly community day (“Hive Day”) and communities of practice for learning and experimentation. Our open culture encourages wide participation and innovation.
We also reward our hard work through regular socials, organised by our people. Socials events include fiercely competitive bake-offs, Pride month office parties, sporting events, games nights and much more!
We are committed to a hybrid working model, combining the best of remote and office-based working.
Discover more at https://www.heywood.co.uk/careers
Legal stuff
https://www.heywood.co.uk/privacy-notices#jobapplicantprivacynotice
EDI statement
As an equal opportunities’ employer, Heywood is committed to the equal treatment of all current and prospective employees and does not condone discrimination on the basis of age, disability, sex, sexual orientation, pregnancy and maternity, race or ethnicity, religion or belief, gender identity, or marriage and civil partnership.
We aspire to have a diverse and inclusive workplace and strongly encourage suitably qualified applicants from a wide range of backgrounds to apply and join Heywood.
…