Head of Information Security
Job in
London, Greater London, W1B, England, UK
Listed on 2026-10-09
Listing for:
Endeavour Recruitment
Full Time, Part Time
position Listed on 2026-10-09
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Network Security
Job Description & How to Apply Below
Location:
Central London - Hybrid (2 days per week onsite)
Salary:
Up to £125,000 per annum, depending on experience
Working hours:
Monday to Friday, 9:00am-5:00pm
Start date:
As soon as possible
About the Opportunity
Endeavour Recruitment is looking for an experienced Head of Information Security on behalf of our client, an established international organisation with a complex technology environment and a strong focus on protecting its systems, data and intellectual property.
This is an excellent opportunity for a technically strong security professional to take ownership of the organisation's information and cyber security agenda. Reporting to the senior technology leadership team, you will define security priorities, shape the organisation's security strategy and ensure that practical, proportionate improvements are implemented across the business.
This is a senior individual-contributor position rather than a traditional departmental management role. You will not be responsible for managing a dedicated security team. Instead, you will work closely with infrastructure, technology and external service provider teams, providing technical expertise, setting standards and ensuring security risks are appropriately managed.
The successful candidate will combine strong hands-on technical experience with the ability to influence senior stakeholders, challenge existing practices constructively and translate complex security issues into clear business priorities.
Key Responsibilities
Develop and maintain the organisation's information and cyber security strategy, including a prioritised roadmap and investment plan.
Establish and maintain security policies, standards and technical baselines aligned with recognised industry practices.
Review the security of enterprise networks, infrastructure, cloud services, endpoints, applications and identity platforms.
Work with technical teams to identify security gaps, agree remediation plans and monitor progress.
Provide security architecture guidance for new systems, technology projects, cloud services and infrastructure changes.
Drive improvements in identity and access management, including authentication, multi-factor authentication and privileged access.
Lead vulnerability management activities, prioritising remediation based on risk and potential business impact.
Establish effective security monitoring, threat detection and incident response arrangements.
Coordinate responses to significant security incidents, ensuring a calm, structured and effective approach.
Assess third-party and supplier security risks and ensure security requirements are considered during procurement.
Provide senior management with clear reporting on security risks, priorities and recommended actions.
Support audit, insurance, customer and regulatory requirements.
Promote security awareness and encourage practical, effective security practices throughout the organisation.
Essential Skills and Experience
Significant professional experience in information security or cyber security, with a strong foundation in hands-on technical roles.
Proven experience securing enterprise network and infrastructure environments.
Good knowledge of cloud security, particularly Microsoft Azure and Microsoft 365.
Experience with Google Enterprise environments would be advantageous.
Strong understanding of identity and access management, authentication, privileged access and access-control principles.
Experience in vulnerability management, security monitoring and incident response, including coordinating significant security incidents.
A track record of developing or improving security policies, technical standards and operational controls.
Experience assessing technical security risks and translating findings into practical business decisions.
The ability to communicate security risks and recommendations effectively to senior stakeholders and non-technical audiences.
Working knowledge of recognised security frameworks, such as the NIST Cybersecurity Framework, CIS Controls and ISO/IEC 27001.
Technical Knowledge
The successful candidate should have working knowledge across several of the following areas:
Network security:
Secure network design, segmentation, firewalls, remote access and secure connectivity.
Infrastructure and endpoint security:
Server hardening, endpoint protection, endpoint detection and response, and patch management.
Cloud and SaaS security:
Secure cloud configurations, configuration management and cloud service…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×