Recevez plus de réponses des employeurs
Envoyez un CV adapté au poste en quelques minutes.
The Chief Information Security Officer (CISO) will define and execute the organisation's cybersecurity strategy for a leading insurer undergoing digital transformation. You will balance innovation with protection of customers, operations and critical information assets while reporting to the Executive Committee and Board.
You will lead the Information Security function, ensure regulatory compliance (DORA, NIS2, GDPR), manage budgets and risk, and build a resilient security culture across the
Our client is a leading insurance company undergoing a significant digital transformation. As Chief Information Security Officer, you will define and execute the organisation's cybersecurity strategy, ensuring that security enables innovation while protecting customers, business operations and critical information assets.
You will lead the Information Security function, work closely with executive leadership, regulators and business stakeholders, and ensure the organisation remains resilient against an evolving cyber threat landscape.
This is a strategic leadership role requiring a hands-on understanding of modern security technologies, financial sector regulations and enterprise risk management.
Define and execute the enterprise cybersecurity strategy aligned with business objectives.
Lead, coach and develop the Information Security department.
Build and maintain a strong security culture throughout the organisation.
Manage security budgets, roadmaps and strategic investments.
Report cybersecurity risks, KPIs and maturity to the Executive Committee and Board.
Own the Information Security Management System (ISMS).
Ensure compliance with DORA, NIS2, GDPR and other relevant regulatory frameworks.
Maintain strong relationships with regulators, auditors and external stakeholders.
Lead cyber risk assessments and define appropriate mitigation strategies.
Drive security policies, standards and governance across the organisation.
Oversee the organisation's Security Operations capabilities.
Ensure effective incident detection, response and recovery processes.
Strengthen cyber resilience, business continuity and disaster recovery capabilities.
Lead crisis management during major cyber incidents.
Drive continuous improvement of vulnerability management and threat detection capabilities.
Provide strategic oversight and direction across key cybersecurity domains, including:
Identity & Access Management (IAM)
Active Directory & Microsoft Entra ID
Security Operations Centre (SOC)
SIEM and security monitoring
Vulnerability & Patch Management
Network Security & Zero Trust
Cloud Security (Azure and/or AWS)
Data Protection & Encryption
Email Security
Privileged Access Management (PAM)
Third-Party & Supply Chain Security
Security Awareness & Human Risk Management
You are not expected to perform engineering activities yourself, but you are able to challenge technical teams, validate strategic decisions and make informed security investments.
We're looking for a security leader who combines strategic vision with strong technical credibility.
You bring:
10+ years of experience within Information Security.
Proven experience managing a Security department, or leading multiple enterprise-wide cybersecurity initiatives.
Strong experience within the Financial Services or Insurance sector.
Deep understanding of how cybersecurity operates in highly regulated environments.
Demonstrated experience implementing and maintaining DORA compliance.
Experience engaging with executive leadership, regulators and Boards.
Strong stakeholder management and communication skills.
Experience building high-performing security teams.
Ability to balance business priorities with security risk.
You possess broad knowledge across modern enterprise security domains, including:
Microsoft Active Directory & Identity Security
Security Operations (SOC)
SIEM platforms (Microsoft Sentinel, Splunk, QRadar or similar)
Vulnerability Management
Endpoint Security (Microsoft Defender, CrowdStrike or equivalent)
Network Security
IAM & PAM
Data Protection
Security Architecture
Security Awareness programmes
Business Continuity & Disaster Recovery
CISSP, CISM or similar security certifications.
Experience with ISO 27001 or NIST Cybersecurity Framework.
Knowledge of FAIR, COBIT or other security governance frameworks.
Experience with cloud transformation programmes.
Experience managing external security service providers and MSSPs.
Within your first 12 months, you will:
Deliver a clear cybersecurity strategy aligned with business objectives.
Mature the organisation's DORA compliance programme.
Improve cyber resilience and operational readiness.
Strengthen Security Operations and incident response capabilities.
Increase executive visibility of cyber risks through meaningful reporting.
Foster a security-first culture across the organisation.