Rodeo
Get started

Moneybox

Head of Information Security

London
Posted 2 months ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

About Moneybox

At Moneybox, our mission is to give everyone the means to get more out of life. We're guided by our belief that wealth isn't about the money, it's about the means to more - more freedom, opportunities, possibilities, and peace of mind. Moneybox is an award-winning wealth management platform, helping over one and a half million people build wealth throughout their lives, whether they’re saving and investing, buying their first home, or planning for retirement.

Job Brief

Moneybox is looking for a Head of Information Security to lead and mature our information security function. Reporting to the Engineering Director, this role will own Moneybox’s Information Security Programme and be accountable for reducing security risk across our people, systems, products and third-party ecosystem as the business continues to scale.

This is a hands-on leadership role. The successful candidate will need to think strategically, set direction and influence senior stakeholders whilst also being close enough to the detail to get things done.

We are looking for someone who can build a small, high-performing and nimble security function, using technology, automation and AI to increase the breadth, quality and pace of what the team can achieve.

The role will suit an experienced information security leader who is pragmatic, commercially aware and focused on reducing meaningful risk, not creating unnecessary bureaucracy or replicating a big-bank security model.

What you'll do

Working closely with Engineering, Workplace Technology, Compliance, Legal, Risk, Product and senior leadership, this role will be responsible for:

  • Owning and delivering Moneybox’s information security strategy, roadmap and operating model.
  • Leading the ongoing development of Moneybox’s Information Security Programme, using NIST CSF as the practical risk-management framework while aligning with ISO 27001 for governance, control maturity and assurance.
  • Reducing real security risk across Moneybox’s technology estate, people processes, suppliers and products.
  • Building an effective and focused security function that scales through prioritisation, tooling, automation and clear ways of working.
  • Providing clear, practical security leadership to senior stakeholders, including regular reporting on security posture, risks, incidents and priorities.
  • Making proportionate, risk-based decisions that support business growth while protecting customers and the organisation.
  • Developing, maintaining and embedding practical information security policies, standards and procedures.
  • Leading security awareness and training programmes that improve behaviours and strengthen Moneybox’s security culture.
  • Owning Moneybox’s security incident response framework, ensuring the business is prepared to identify, contain, respond to and recover from security incidents effectively.
  • Overseeing vulnerability management, including scanning, remediation, patching and risk-based prioritisation.
  • Leading third-party security risk management for key vendors, partners and technology providers.
  • Defining and tracking security metrics that support risk reduction, delivery progress and decision-making.
  • Partnering with Engineering and Product teams to ensure security is built into systems, services and ways of working.
  • Monitoring emerging threats, regulatory expectations and industry practice, then applying them pragmatically to Moneybox’s environment.
  • Continuously improving the security function in a way that is practical, proportionate and appropriate for Moneybox.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Who you are

A strategic but hands-on information security leader.

  • Comfortable owning outcomes directly and staying close to delivery.
  • Pragmatic and risk-led with strong judgement on where security effort will have the greatest impact.
  • Comfortable building security capability through focus, prioritisation, technology and automation.
  • Able to prioritise security effort based on risk, impact and business context.
  • Commercially aware, with the ability to balance security, customer experience, regulation and delivery.
  • Clear and concise with senior stakeholders, able to translate security issues into business impact.
  • Collaborative and able to influence across Engineering, Compliance, Legal, Product, Workplace Technology and the wider business.
  • Strong understanding of current and emerging threats, and how to manage them proportionately in a fast-moving organisation.
  • Interested in how AI and automation can improve security operations, assurance, monitoring, reporting and decision-making.
  • Alert to the security risks created by AI adoption, including data exposure, misuse, shadow AI, third-party tooling and changing attacker capabilities.
  • Motivated by building a high-quality security function that fits Moneybox, rather than importing a large-enterprise or big-bank model.

Experience & Skills

  • Proven experience leading or significantly contributing to an information security function.
  • Strong working knowledge of risk-based security management and the NIST Cyber Security Framework.
  • Experience developing and delivering information security strategy, roadmaps, policies and controls.
  • Practical knowledge of security technologies and business systems, including identity and access management, SIEM, endpoint security, cloud security, vulnerability management and remote working technologies.
  • Experience using technology, automation or AI to improve security outcomes or operational efficiency.
  • Experience managing security risk in cloud-based environments, ideally including Azure.
  • Strong understanding of third-party security risk management.
  • Experience with incident response planning, testing and improvement.
  • Experience reporting security risks, controls and metrics to senior management.
  • Strong communication skills, with the ability to translate technical security issues into clear business risks, recommendations and trade-offs for senior stakeholders.
  • Good understanding of financial services security, risk and regulatory expectations.
  • Demonstrated leadership skills with the ability to influence, collaborate and drive change across teams.
  • Excellent written and spoken English.

What's in it for you

  • Opportunity to join a fast-growing, award-winning and super ambitious company.
  • Work with a friendly team of highly motivated individuals.
  • Be in an environment where you are listened to and can actually have an impact.
  • Thriving collaborative and inclusive company culture.
  • Competitive remuneration package.
  • Company pension scheme.
  • Company bonus scheme.
  • Hybrid working environment.
  • Home office furniture allowance.
  • Personal Annual Learning and Development budget.
  • Private Medical Insurance.
  • Health Cash Plan (cashback on visits to the dentist & opticians etc).
  • Cycle to work scheme.
  • Wellhub subscription to a variety of gyms and wellbeing apps.
  • Enhanced parental pay & leave.
  • 25 days holiday + bank holidays with additional days added with length of service.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

This is a hybrid role. Our office is in London, by the Oxo Tower.

Our Commitment to DE&I

At Moneybox, we promote, support and celebrate inclusion, diversity and equity for all, so that everyone can bring their full selves to work. We believe that diversity drives innovation, and that if our team is representative of our community of customers, we can better support their needs. To ensure our recruitment processes provide an equal opportunity for all applicants to succeed, we encourage you to let us know if there are any adjustments that we can make. We are open-minded and always willing to go the extra mile to ensure all applicants can present their full self and potential.

Working Policy

We have a hybrid policy that includes 2 days from our London office and 3 from home. If the role states it is either hybrid or remote candidates must be based within the UK.

Visa Sponsorship

At this time we cannot offer visa sponsorship for this role and we cannot consider overseas applications.

Please read before you apply!

Please note if offered a position, the offer is conditional and subject to the receipt of satisfactory pre-employment checks which we will conduct such as criminal record and adverse credit history checks. As a regulated financial business, an adverse financial history could impact your suitability for the role. If you are aware of anything that could affect your suitability for the role, please let us know in advance.

By sending us your application you acknowledge and agree to Moneybox using your personal data as described below.

We collect applicants’ personal data to manage our recruitment related activities. Consequently, we may use your personal data to evaluate your application, to select and shortlist applicants, to set up and conduct interviews and tests, to evaluate and assess the results, and as is otherwise needed in the recruitment process generally.

We do not share your personal data with unauthorised third parties. However, we may, if necessary, share your personal data to carefully selected third parties acting on our behalf. This may include transfers to servers and databases outside the country where you provided us with your personal data. Such transfers may include for example transfers and/or disclosures outside the European Economic Area and in the United States of America.

If you are unsuccessful in your application, we may keep your details on file so that we can tell you about other suitable vacancies which may be of interest to you when they arise in the future.

If you would like to reach us then please email: talent@moneybox.com

If you would rather we did not keep your details on file, you can contact us at: DPO@moneyboxapp.com

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Information security strategy
NIST CSF
ISO 27001
Risk management
Security leadership
Incident response
Vulnerability management
Third-party risk management
Cloud security
Azure
Identity and access management
Automation
Security metrics
Stakeholder management
Compliance
Security culture

Location

London, England, United Kingdom

Sign up to applySee more jobs like this