Chief Information Security Officer (CISO) and Head of Corporate Security and Resilience

Company: UK Regulators' Network
Apply for the Chief Information Security Officer (CISO) and Head of Corporate Security and Resilience
Location: Manchester
Job Description:

Independent Football Regulator

Requirements of the role

This role provides strategic leadership and operational ownership of cyber security across the IFR, a small but high‑profile organisation. You will be responsible for developing, embedding and maturing a robust, proportionate cyber security and broader organisational security framework that protects the organisation’s people, data, systems and services.

Responsibilities Will Include

  • Developing, embedding, maturing and leading the organisation’s cyber security strategy, governance, resilience and assurance activity.
  • Overseeing all aspects of cyber security operations, including incident response, threat monitoring, vulnerability management and security operations
  • Owning the wider organisational security framework, including physical security, information governance, data protection and resilience planning.
  • Setting clear security management expectations and embedding a strong, resilient and effective security awareness culture across a small but high‑profile organisation.
  • Ensuring compliance with relevant legislation, regulatory requirements and government security standards, including Government Functional Standard GovS 007: Security.
  • Providing authoritative advice to the CEO, COO, CDDO, ExCo and Board on emerging threats, risks and mitigations.
  • Implementing a formal cyber exercising and incident response programme; driving security and operational resilience.
  • Embedding secure‑by‑design principles across digital services, data platforms and operational processes.
  • Ensuring the cyber security framework aligns with the regulator’s digital and data roadmap.
  • Establishing ambitious and effective cyber maturity credentials; leading on assurance, penetration testing, risk assessments and audit readiness.
  • Implementing audit recommendations and ensuring timely remediation of identified risks.
  • Overseeing identity and access management, cloud security and supplier assurance.

Location: Manchester

Contract type: Full time

Profession: Data, Digital, Technology

Working pattern: Flexible working, Hybrid

Closing Date: 22/04/2026

#J-18808-Ljbffr…

Posted: April 12th, 2026