Head of Information Security
Job Summary
MOO is seeking an experienced Head of Information Security to review and re-build our security privacy and resilience capabilities from the ground up and in the first 12 months to act as build lead for the digital and security aspects of a company-wide Business Continuity Disaster Recovery and Incident Response programme.
This is a standalone role reporting to the Head of Legal It is not a caretaker or compliance-only position. You will operate as a hands-on builder defining strategy establishing governance writing playbooks and directly influencing Engineerings roadmap and delivery practices to embed security privacy and resilience by design.
Were looking for a hands-on builder with a proven track record of building security privacy and resilience programmes from the ground up.
Youll be comfortable working with executive and board level while also getting into the details of security incident response business continuity disaster recovery cloud security and data privacy.
Youll be pragmatic and business-focused balancing security with delivery velocity and availability and have a collaborative mindset as a partner not an auditor or advisor.
- Define and own information security strategy aligned with business objectives.
- Establish security governance framework including policies standards risk management and risk appetite.
- Chair the Security Governance Forum and run a board-level reporting cadence.
- Build a security roadmap prioritising compliance privacy AppSec and resilience.
- Hold explicit authority to gate Engineering roadmap and release decisions on security and resilience grounds.
- Drive adoption of UK Cyber Essentials across the business and CIS AWS Foundations for the Platform.
- Stand up centralised monitoring and alerting across Security Hub and Wiz.
- Own and continuously improve the security incident response plan and playbooks; act as incident commander when needed.
- Create and maintain the Business Impact Analysis (BIA) and risk assessments to inform continuity strategies covering cyber scenarios.
- Define and maintain DR strategy architectures and playbooks to meet RTO/RPO targets for in-scope services.
- Design and own the data recovery strategy and identity recovery strategy.
- Establish backup restore and failover testing cadence with evidence of success criteria.
- Lead security incident crisis management including cross-functional command structure executive communications customer and regulator notifications liaison with the cyber insurer/broker and after-action reviews.
- Plan facilitate and participate directly in tabletop cyber exercises and live cyber simulations at least quarterly.
- For any incident classified Severity 1 or 2 act as deputy incident decision-maker holding delegated authority from the CFO to make time-critical operational decisions.
- Partner with Legal to own the GDPR programme end-to-end from an information security perspective including DPIAs ROPA DSR handling consent and lawful basis.
- Partner with Legal to maintain DPAs SCCs and appropriate transfer mechanisms for third countries.
- Implement data classification and protection standards across structured and unstructured data.
- Embed Privacy by Design and data minimisation into discovery design and delivery processes.
- Own the roadmap towards enterprise assurance frameworks including UK Cyber Essentials and SOC 2 readiness.
- Prepare for external audits and assessments and ensure customer security questionnaire responses reflect actual control status.
- Establish and run the vendor risk management programme with pre-procurement security gates continuous monitoring SLAs and breach flow-down obligations.
- Maintain a current inventory of third-party access and dependencies including each vendors own DR/BC posture.
- Drive cloud security posture management and foundational controls including IAM network segmentation encryption and secrets.
- Partner with Technology to eliminate shadow technology and tighten ownership/authorisation.
- 6 years in information security with 3 years of direct exposure to executive and board-level security reporting.
- Proven track record building security privacy and resilience programmes from the ground up including authoring a companys first Business Continuity Plan for information security.
- Demonstrated experience running a Business Impact Analysis and translating it into a defensible Minimum Viable Company / recovery-tier model.
- Expertise in GDPR and PCI-DSS with hands-on ownership of DPIAs DSRs and retention programmes.
- Experience leading security incident response business continuity disaster recovery and crisis exercises.
- Solid grasp of cloud security.
- Strong understanding of e-commerce security (payments customer data).
- Excellent executive communication able to brief the CFO and the Board directly and to hold the security incident-decision-maker role with credibility under pressure.
- Strong stakeholder management across Engineering Product Legal Finance and Operations with the standing to influence Engineering roadmap decisions.
- Pragmatic and business-focused balancing security with delivery velocity and availability.
- Collaborative mindset: a partner not an auditor or advisor.
- Experience with physical/production continuity planning.
- AWS experience.
- Working knowledge of UK Cyber Essentials and CIS AWS Foundations.
- Experience driving DR maturity and recurring cross-functional simulations.
- Experience with SOC 2 readiness.
Required Experience:
Director
About Company
Online printing services to create high-quality business cards, stickers, postcards, and more. Professional custom printing by MOO, the best online print shop.