Head of Information Security

Company: CyberNorth
Apply for the Head of Information Security
Location:
Job Description:

As Head of Information Security , you will be accountable for building,maintaining, and continuously improving a proportionate, risk-based cybersecurity framework aligned to NIST CSF 2.0. This is a hybrid leadership and technical delivery role: while governance, assurance, and influencing across the business are critical, you will also roll up your sleeves to implement and oversee technical security controls where necessary.

You will lead the security strategy, risk management, and compliance initiatives, working closely with IT, Engineering, Product, and third-party partners, while reporting regularly to the CTO, CEOand executive team on risk posture and security priorities.

What You’ll Do:

  • Lead the development and operation of our information security program in line with NIST CSF 2.0.
  • Own and managean active risk management framework, ensuring risks areidentified, assessed, treated, andmonitored.Report security posture and key risks clearly to CTO,CEOand executive leadership.
  • Define and oversee technical security controls across identity, endpoint, cloud, and network environments.
  • Govern outsourced security services (e.g., MDR/SOC) to ensure effective detection, response, and remediation.
  • Define and implement a vulnerability management programme.
  • Lead incident response planning, testing, and lessons-learned processes.
  • Embed security into the delivery lifecycle and ensure secure practices across teams.
  • Develop andmaintainsecurity awareness programs and training for staff.
  • Manage and mentor a high-performing security teamincluding an ISMS coordinator and security engineer, fostering a culture of continuous improvement.
  • Achieve Cyber Essentials Pluswithinfirst 12 months.
  • Maintain, and oversee information security and data governance policies, standards, and procedures.
  • Provide oversight and assurance for third-party and supplier security risk management.

What We’re Looking For:

  • Proven experience leading information security programs in a scaling or high-change environment.
  • Deep understanding of regulatory standards (ISO 27001, NIS2,NIST CSF 2.0,PCI DSS, GDPR) and security frameworks.
  • Strong understanding of modern cyber controls: IAM, endpoint security, vulnerability management, cloud security, logging, monitoring, and secure delivery practices.
  • Experience managing outsourced security services (MDR/SOC) and vendors.
  • Strong leadership, influence, and stakeholder management skills within a matrix delivery model.
  • Ability tooperateat both strategic and hands‑on levels.

Desirable: CISSP, CISM, CISA, or relevant cloud/security technical certifications.

#J-18808-Ljbffr…

Posted: April 15th, 2026