Mentmore
Director of Cyber Security

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Director of Cyber Security/ Head of Security Engineering /Deputy CISO (Interim)
Department: Group Information Security
Location: Remote / Hybrid
Reports to: Chief Information Security Officer (CISO)
Contract: Interim, initial 6-month term (likely extension to 12 months)
About Our Client
Our client is a global, multi-division technology and services organisation supporting leading brands across an international client base. Having grown significantly through acquisition, the group is now investing heavily in maturing its information security function across a large, federated, multi-region organisation.
Role Summary
The Head of Services and Engineering is accountable for the day-to-day operation of mission-critical information security platforms, architectural best practice, and business-facing security services across the group.
Working alongside the Head of Security Governance, Risk and Compliance and the Head of Security Operations in the Office of the CISO, this person directs the design, development and delivery of services and architectural standards that ensure the business can meet the dynamic demands of its clients and markets, while maintaining the confidentiality, integrity and availability of information systems and data at all times.
The role carries additional accountability to maintain operational business continuity, and will deputise for the CISO in their absence — for example during a major incident or crisis, or to cover extended leave or extraordinary business assignments.
This is also a transformation-focused leadership role: the incumbent will take ownership of an existing, distributed engineering and architecture team that currently lacks consistent structure, documentation and process maturity, and will lead them through a stabilisation-to-transformation journey — defining services, building trust, and establishing operational rigour.
Key Responsibilities
- Lead a team of domain security specialists responsible for architectural outputs supporting the information security management system, ensuring security by design across the technology estate and optimal operation of security platforms.
- Manage the security service catalogue — service definitions and design, quality standards, KPIs and reporting — across Project and Programme support, Engineering and Architecture, Empowered Workforce (culture, training, communications and development), and Security Service Management (IT Service Management). Drive continuous improvement of repeatable processes to ensure quality of delivery, first-time fix, and customer satisfaction.
- Lead and direct a group of solutions analysts assigned to projects and programmes across the business, ensuring every division has the support needed to specify, design, build, implement and run secure and resilient solutions.
- Direct enterprise security architecture through the publication, implementation and maintenance of reference architectures, design principles and standards aligned to the organisation's ISMS, legal and privacy policies, and AI security governance strategy. Represent the security domain at the Design Authority Committee.
- Act as a key decision-maker in the selection of security technologies supporting the CISO's security strategy and the wider technical strategy.
- Manage strategic vendor relationships pertaining to the organisation's security posture and capabilities, working alongside peers and senior leadership.
- Jointly with the Head of Governance, Risk and Compliance, establish minimum security baselines and overarching principles of information security to drive operational consistency and manage risk within defined tolerances.
- Hold day-to-day responsibility for budget consolidation and business reporting, including regular reporting to executive leadership, board and investor stakeholders.
- Direct the "Empowered Workforce" programme — driving an effective security culture through awareness, training and development (including mandatory literacy, context and role-based training), phishing and deepfake awareness, personnel and physical security awareness, and ongoing communications.
- Champion AI and automation strategy across the security function, identifying and implementing opportunities to drive efficiency and control cost.
- Deputise for the CISO when required, as a delegate of authority.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Qualifications and Core Competencies
- 10+ years in information security with progressive technical and strategic leadership responsibility
- Demonstrated experience designing and governing enterprise security architecture across multiple domains (network, identity, cloud, endpoint, data)
- Experience building and leading security engineering teams and cross-functional security programmes
- Deep knowledge of at least three security domains, with working breadth across all (architecture, cloud, identity, data/application security, endpoint, network, cryptography, AI)
- Proven ability to operate at both strategic and execution levels — comfortable in board-level discussions and hands-on architectural review
- Experience with ISMS frameworks (ISO 27001, NIST CSF) at governance, implementation and audit-readiness levels
- Track record of translating governance requirements into implementable technical standards, patterns and awareness programmes
- Experience managing security architecture review boards or equivalent technical governance bodies
- Experience leading security awareness and culture change programmes at scale
- Strong vendor management skills for enterprise security and awareness platforms
- Excellent stakeholder communication skills, able to represent the security function to executive leadership, board committees, technology partners and business stakeholders


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Desirable
- Experience with security transformation programmes in multi-division, multi-region organisations
- Familiarity with AI/ML security, LLM governance, and automation platforms (e.g. SOAR)
- Experience operating in a matrix organisation with distributed teams across multiple time zones
- CISSP, CISM, SABSA, or equivalent senior security certification
- Experience with agile delivery in a security context (Scrum/Kanban for security engineering)
- Experience deputising for, or directly supporting, a CISO in a global enterprise
Our client is committed to equal opportunities and welcomes applications from all qualified candidates.
Seniority Level: Director
Industry: Broadcast Media Production and Distribution
Computer Games
Employment Type: Contract
Job Functions: Information Technology
Skills: Information Security
Certified Information Security Manager (CISM)
SABSA
Information Security Management System (I
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location