NTT DATA
Chief Information Security Officer

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Account Security Director (vCISO)
Role Purpose
The Account Security Director (vCISO) is the senior security leader responsible for security governance, assurance and strategic security oversight across a major client account.
Acting as the primary security interface between the client security organisation, account leadership and service delivery teams, the role ensures security requirements are understood, embedded and effectively managed throughout the service lifecycle.
The role provides trusted security leadership, independent challenge and executive-level advice to ensure services remain aligned with business objectives, contractual obligations, organisational policies, regulatory expectations and risk appetite. Through effective stakeholder engagement and influence, the Account Security Director drives security outcomes, operational resilience and continual improvement in security maturity and assurance effectiveness.
What you'll bring;
Strategic Security Leadership & Client Partnership
- Act as the senior security representative for the account.
- Build trusted relationships with client security, technology, risk, compliance, audit and business stakeholders.
- Serve as the primary point of contact for strategic security matters across the account.
- Provide strategic security advice and guidance to client executives, account leadership and delivery teams.
- Represent security interests within governance, operational, service review and transformation forums.
- Influence senior stakeholders to support effective risk-based decision making.
- Act as a trusted advisor on security, resilience, compliance and risk matters.
- Act as an escalation point for significant security issues affecting the account.
- Facilitate effective communication between business, operational and technical stakeholders.
- Promote a positive security culture across the account and wider delivery organisation.
Governance, Risk, Assurance & Security Oversight
- Own, maintain and continually improve the Account Security Management Plan and associated security governance arrangements.
- Ensure the Security Management Plan remains aligned with client requirements, contractual obligations, organisational policies and industry good practice.
- Establish and maintain effective security governance and reporting arrangements across the account.
- Ensure security risks are identified, assessed, communicated and managed in accordance with business objectives and risk appetite.
- Provide independent oversight and challenge of security controls, assurance activities and risk treatment plans.
- Ensure security requirements are understood, embedded and effectively managed throughout service delivery activities.
- Drive accountability for security outcomes across delivery, operational and support teams.
- Provide oversight of security posture, control effectiveness, risks, issues and remediation activities.
- Ensure security obligations, commitments and compliance requirements are met and evidenced.
- Support internal audit, external audit and client assurance activities.
- Challenge decisions, practices or activities that introduce unacceptable levels of security risk.
- Ensure security considerations are embedded within service delivery, operational processes, change activities and service improvement initiatives.
- Drive remediation of security risks, audit findings and control weaknesses through to completion.
- Provide meaningful security reporting, assurance and management information to stakeholders.
- Promote transparency, ownership and continual improvement across the account.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Security Architecture and Design Authority
- Provide strategic security architecture oversight across the account, ensuring security requirements are reflected within technology strategy, solution design and service evolution.
- Act as the security authority for the review and challenge of significant architectural, technology and service changes.
- Ensure security-by-design principles are embedded throughout the service lifecycle and considered within all material design decisions.
- Assess the impact of architectural decisions on security risk, operational resilience, compliance obligations and business objectives.
- Provide independent security challenge to proposed solutions, identifying opportunities to improve security, resilience and risk management outcomes.
- Work collaboratively with client architects, service architects and delivery teams to ensure security architecture principles are consistently applied.
- Support transformation initiatives by providing strategic security guidance and architecture oversight.
- Ensure security architecture considerations are integrated into service roadmaps and future-state planning.
- Maintain awareness of emerging technologies, threats and industry practices to ensure security architecture remains effective, proportionate and aligned with business objectives.
Regulatory, Contractual and Compliance Oversight
- Maintain a strong understanding of applicable regulatory requirements, industry standards and evolving security expectations relevant to the client environment.
- Develop and maintain effective working relationships with client Risk, Compliance, Legal, Audit and Operational Resilience stakeholders.
- Provide trusted advice and guidance on the interpretation and application of regulatory, contractual and security requirements.
- Ensure regulatory, contractual and policy obligations are understood and appropriately reflected within security governance, assurance and service delivery activities.
- Work collaboratively with stakeholders to support the achievement and maintenance of compliance objectives.
- Support organisational readiness for internal audit, external audit, assurance reviews and regulatory engagement activities.
- Assess the impact of changes in regulatory, legal and industry requirements on the account and advise on appropriate actions.
- Promote a proactive approach to compliance, ensuring security controls, processes and governance arrangements continue to support regulatory expectations.
- Provide oversight and challenge to ensure identified compliance risks, findings and remediation activities are effectively managed through to completion.
- Support the development of a strong control environment through effective governance, assurance and continuous improvement activities.
- Ensure security governance and assurance arrangements evolve in line with changes in regulation, business strategy, technology and risk.
Continuous Improvement
- Drive continual improvement in security governance, assurance and risk management practices.
- Ensure lessons identified from incidents, audits, assessments and reviews are translated into measurable improvement activities.
- Promote adoption of security best practice across account teams.
- Encourage innovation and effective use of security capabilities to improve security outcomes.
- Support the ongoing development of security maturity, operational resilience and assurance effectiveness across the account.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
What you'll bring;
Experience
- Minimum 7 years' experience in a senior information security leadership, Security Director, CISO or virtual CISO role.
- Proven experience providing strategic security leadership within large, complex and regulated organisations.
- Experience acting as a trusted advisor to executive leadership, client security teams and senior business stakeholders.
- Experience developing and leading security governance, risk management and assurance programmes.
- Experience owning and maintaining Security Management Plans and associated governance and reporting frameworks.
- Experience leading security assurance activities, managing audit engagements and driving remediation activities through to completion.
- Significant experience in enterprise security architecture, security design assurance and security-by-design principles.
- Experience reviewing and challenging technology, cloud, infrastructure and transformation initiatives from a security, resilience and risk perspective.
- Experience operating within outsourced, managed service and multi-supplier delivery environments.
- Proven ability to influence senior stakeholders and drive security outcomes without direct management authority.
Knowledge and Skills
- Security governance, risk management and assurance, including the design and operation of effective governance and reporting frameworks.
- Enterprise security architecture and the application of security-by-design principles across technology and business change initiatives.
- Security oversight of technology strategy, cloud adoption, infrastructure modernisation and digital transformation programmes.
- Risk-based decision making, balancing business objectives, regulatory obligations and security requirements.
- Regulatory compliance and the practical application of security, resilience, outsourcing and third-party risk management requirements.
- Translation of complex security, technical and regulatory issues into clear business, risk and assurance outcomes.
- Development of meaningful security metrics, reporting and management information to support executive decision making.
- Audit, assurance and control effectiveness assessment, including evidence-based assurance practices.
- Commercial awareness and an understanding of how security supports business objectives, operational resilience and customer confidence.
- Excellent stakeholder management, negotiation, communication and influencing skills.
- Strong judgement and decision-making capability in complex business, technology and risk environments.
Qualifications and Professional Membership
- CISSP, CISM, CRISC, CCISO or equivalent recognised senior cyber security qualification.
- UK Cyber Security Council Professional or equivalent recognised accreditation.
- Member of a professional industry body.
- Evidence of continuing professional development and industry engagement.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location