Enable job alerts via email!

Head of Information Security

True North Group

North East

Hybrid

GBP 70,000 - 90,000

Full time

Today
Be an early applicant

Job summary

A fast growing tech company is seeking a dedicated Head of Information Security to ensure the implementation and maintenance of various security standards including ISO 27001 and GDPR. The ideal candidate will have strong leadership skills and experience in tech-focused organizations, managing security audits and incident responses. This position offers a hybrid working model from Newcastle HQ, requiring 2-3 days in the office.

Qualifications

  • Proven experience with information security standards.
  • Background in tech companies or heavy reliance on SaaS products.
  • Experience working with a similar-sized organization.

Responsibilities

  • Lead implementation and maintenance of security standards.
  • Respond to audit and information requests.
  • Manage incident investigations and reviews.

Skills

Leadership and stakeholder engagement
Information security frameworks (ISO 27001, GDPR, Cyber Essentials Plus)
Incident investigation and reporting
ISMS and security controls design
Security audits and risk assessments
Data protection best practices
Supplier risk management
Responding to 3rd party security requirements
Job description
Overview

TrueNorth are working with a fast growing tech company who are looking to recruit a dedicated Head of Information Security to join the team.

The right candidate for this role will have extensive experience of the implementation and maintenance of various information security standards including: ISO27001, CyberEssentials (Plus), GDPR, NIST etc - you would also naturally be the person leading responses to audit and information requests too.

You will ideally have worked with a company of a similar size or larger, circa 500 employees - it would also be beneficial to have experience in organisations that are tech companies or heavily tech focussed as well as using a lot of SAAS products.

Key skills and experience
  • Excellent leadership and stakeholder engagement.
  • Detailed understanding of information security frameworks (ISO 27001, GDPR, Cyber Essentials Plus), and how to implement, apply and maintain them
  • Incident investigation, reporting, and post-incident review capabilities.
  • Design, implementation, and maintenance of ISMS and security controls.
  • In-depth understanding of security audits, risk assessments, and mitigation strategies.
  • Working knowledge of data protection best practices (including DSARs and DPIAs).
  • Supplier risk management
  • Ability to respond to 3rd party security requirements, questionnaires, and ISQs.

The role will be based from their Newcastle HQ on a hybrid working 2-3 days per week in office (with flexibility).

We are unable to sponsor visa's for this requirement.

Get in touch for more information!

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.