Incite-Insight.co.uk
Head of IT Security

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
JOB PROFILE
Job title: Head of IT Security
Hybrid Role (2 Days per Week from HQ Offices SE5 London)
Purpose
Responsible for defining the vision and setting and implementing the strategy for IT risk management, information security and cyber security, within the UK & Ireland (UKI) Territory.
Leading on the understanding of emerging security trends, risks, guidelines, technologies, and applicable laws, regulations, and contractual requirements.
Responsible for all IT security risk and vulnerability identification and assessment, and the resulting mitigating actions.
Leading on organisational and behavioural change in relation to IT security, at all levels, by education and collaboration.
The organisation has approximately 7000 IT users across approximately 900 locations, comprising of a comprehensive IT infrastructure delivering several line-of-business systems which reach out to all staff. Primarily based at Territorial Headquarters in London, the IT Department is responsible for the entire IT infrastructure, service desk support, corporate systems, IT provisioning, information security, telephony (landline and mobile), IT project management, and management information.
Organisation Chart
Chief Information Officer
Head of IT Security
Assistant Head of Information Security
Report To
Chief Information Officer
Accountable To
Chief Information Officer, Secretary for Business Administration, IT Strategy
You will…
- Define the vision, and set and implement the strategy for IT risk management, information security and cyber security within the UK & Ireland (UKI) Territory, to ensure the organisation’s information assets are adequately protected.
- Develop an organisation-wide risk-based approach to threats, so reducing threat exposure through vulnerability identification, assessment, and remediation actions.
- Take responsibility for all IT risk management, information security and cyber security matters in relation to product/vendor selection and Missional contract negotiation, to mitigate security threats and ensure ongoing contract compliance.
- Take organisational responsibility for IT security incident response planning at security breach investigation, and assist with any associated disciplinary, public relations and legal matters, to enable recovery and legal compliance in the event of a disaster.
- Lead and manage the Security team of employees, vendors & contractors and associated budgets, to ensure uninterrupted service and value for money.
- Establish and lead the Information Security Forum, to support effective decision making and improve organisation understanding.
- Develop an enterprise information security programme, so establishing a cyber-savvy workforce that can make the right decisions for safe and efficient operations, so minimising the risk of the organisation being exposed to security threats.
- Communicate objectives and key results to the Executive Committee, Board of Directors, and other stakeholders, including a clear and measurable view of Information and Cyber Security, to ensure that security activities meet strategic objectives.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
You have…
- Extensive demonstratable IT risk management, information security and cyber security experience at a strategic level, in a geographically diverse and multi-disciplinary organisation.
- Key working relationships
- Senior leaders, regularly with Audit Director, Territorial Risk and Compliance Manager, Mission contract holders, Procurement, HR, Legal, Data Protection Officer, and IT Steering Board.
- External suppliers and out-tasked service providers
- Government bodies e.g., Home Office.
- Sub Contracted service providers
- People Management
- Assistant Head of Information Security and other specialist consultants/contractors and out-tasked service providers (3-6 people).
- Operating Budget
- c£1.5-2m covering specialist security tools, audits, services, awareness courses, certifications.
- Expert level subject matter in IT risk management, information security, and cyber security, with the proven ability to apply that knowledge effectively within the workplace, with the drive to keep updated with all relevant statutory and best practice developments, and influence organisational thinking.
- Demonstrable proven ability of planning at a strategic level with a 3-5 year time horizon.
- Demonstrable excellent communication skills (written, verbal, and presentational) with the proven ability to convey complex ideas/processes/procedures to technical & non-technical audiences, up to Board level, with the intention of influencing decision-making and/or changing behaviours.
- Excellent interpersonal skills with the ability to influence at a senior level, and develop strong, successful, collaborative, and influential working relationships at all levels of seniority within an organisation.
- Proven ability to think critically, you are a solution-focused individual with demonstrable ability to analyse and improve existing processes and procedures to positively influence performance and outcomes.
- Proven strong financial management skills with previous experience of managing budgets, developing spending plans, and delivering financial reporting as required.
- Excellent leadership and management skills with the ability to motivate employees and teams, identify and nurture talent, manage performance effectively, and provide practical emotional and pastoral support to deliver organisational objectives.
- Educated to MSc Information Security degree level and/or with equivalent relevant practical experience and certified Information Systems Security Professional, Certified Information Security Manager, and ISO27001 Practitioner.
- The ability to work flexibly to deliver the requirements of your role such as evening work, weekend work, unsociable hours, and occasional overnight stays for meetings and visits throughout the Territory. Often at short notice as critical changes must be made outside core hours.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
You may have…
- Experience of successfully implementing complex projects with responsibility for delivering the full project management cycle including initiation, planning, execution, monitor and control.
- Experience of working in the not-for-profit sector.
- Understanding of ITIL service processes and management relevant to information security.
How criteria will be assessed
- (A) application form
- (I) interview
- (T) test
- (P) presentation
- (R) references.
We expect you to exhibit behaviours that model our values of integrity, accountability, compassion, passion, respect, and boldness.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location