Head of Information Security and Privacy

Summary

Head of Information Security and Privacy leading a 5-person team at a UK public-sector financial body, managing ISO 27001, Cyber Essentials, NIST, and information security frameworks in a hybrid role.

Salary: £100,000 - 110,000 per year

Requirements:
  • Information Security Manager or equivalent with relevant industry experience.
  • Experience of managing and overseeing ISO 27001 audits, Cyber Essentials and Cyber Essentials Plus.
  • Ability to develop and lead information and cyber security strategies, roadmaps and maturity plans.
  • Ability to provide technical security guidance and assurance to technical and non-technical stakeholders.
  • Ability to design and deliver security awareness programmes that improve understanding and influence behaviour.
  • Ability to support business continuity and resilience planning, testing and lessons learned.
  • Ability to engage senior stakeholders and committees through clear reporting, influence and constructive challenge.
Responsibilities:
  • Manage our 5-person Information Security and Governance function within our compliance team.
  • Implement and manage our information management system, including third-party risk, and ensure its effectiveness is regularly assessed through external and internal audits.
  • Develop and manage our information and cyber security frameworks and oversee our Information and Records Management.
  • Develop and promote policies that ensure compliance with regulations, standards and good practice relating to information security management.
  • Research emerging security risks and keep our solutions, services, policies, procedures and security education programme updated in reasonable timeframes to mitigate new risks.
  • Ensure we remain compliant with Information Security Standards such as ISO 27001, Cyber Essentials, Cyber Essentials Plus, NIST and GovAssure.
  • Own the control documentation and audit process to ensure full compliance is recognised.
  • Protect our organisation in line with business needs against information and cyber risks, including third-party and supplier risk.
Technologies:
  • Support
  • Security
  • ARM

More:

Morgan Law is working with an arms-length Government body in the UK financial sector seeking a Head of Information Security and Privacy to join our compliance function. The role is hybrid, with 2-3 days a week in our South London office, and comes with a very competitive benefits package.

last updated 35 week of 2026

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available