Head of Information Security (Deputy CISO)

NewDay Technology Limited

Greater London

On-site

GBP 140,000 - 200,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

NewDay Technology Limited is recruiting a Deputy Chief Information Security Officer to shape and lead an enterprise-wide security capability. Reporting to the CISO, you will be the principal deputy and translate strategy into clear priorities with measurable outcomes across governance, risk, operations, and resilience.

You will direct security strategy execution, oversee risk management, assurance, and regulatory engagement, and drive secure-by-design delivery while aligning with NewDay’s risk

Qualifications

  • Significant experience leading a broad Information Security function within a regulated organisation.
  • Experience as a senior deputy to a CISO or equivalent enterprise security leader.
  • Experience across security operations, governance, risk & compliance, architecture, engineering, third-party risk, assurance and operational resilience.
  • Strong knowledge of ISO/IEC 27001, PCI DSS, UK GDPR, Data Protection Act 2018 and recognised frameworks such as NIST.
  • Solid understanding of technology risk, risk appetite, control effectiveness and operational resilience.
  • Experience leading security incidents, audits, assurance programmes, regulatory engagement and reporting.
  • Professional certifications such as CISSP, CISM, CRISC, CISA, ISO 27001 Lead Implementer or Auditor would be valuable.

Responsibilities

  • Lead the Information Security function with clear priorities, delivery and accountable culture.
  • Translate security strategy into actionable priorities and measurable outcomes.
  • Own the Security Management System and ensure alignment with standards and regulatory expectations.
  • Oversee security operations, resilience, threat management, and incident response.
  • Manage risk framework, cloud adoption, secure-by-design delivery, and supplier-led transformations.
  • Coordinate assurance activities including audits and regulatory engagements; report to executives & Board.

Skills

security leadership
regulated sector
senior deputy to CISO
ISO 27001
PCI DSS
UK GDPR
NIST
risk management
audits & assurance
regulatory engagement
communication & influence
CISSP
CISM
CRISC
CISA
ISO 27001 Lead Implementer
ISO 27001 Lead Auditor
Azure security

Job description

NewDay is recruiting a brand-new Deputy Chief Information Security Officer role to help shape, lead and strengthen our enterprise-wide security capability. Reporting directly to the CISO, you will be the senior operational leader for Information Security and the CISO’s principal deputy. You will translate our security strategy into clear priorities, measurable outcomes and consistent execution across security operations, governance, risk, architecture, engineering, identity, third-party security, resilience and assurance. This is a high-impact leadership opportunity with significant enterprise visibility. You will represent Information Security at senior forums, provide clear insight on cyber and technology risk, and ensure our security organisation remains aligned with NewDay’s risk appetite, regulatory responsibilities, customer commitments and commercial ambitions.

Lead the Information Security function

Lead, develop and bring together NewDay’s Information Security teams, creating clear priorities, strong delivery and an accountable, high-performing culture. Act as the CISO’s delegate across executive, risk, governance, customer, supplier and regulatory forums. Ensure the function has the right operating model, capabilities, technology and management information to protect NewDay and support future growth.

Turn security strategy into action

Be responsible for the operational delivery of NewDay’s security strategy, ensuring investment and activity are focused on reducing material cyber and technology risk. Own the Information Security Management System and support continued alignment with ISO/IEC 27001:2022, the NIST Cybersecurity Framework and other recognised standards. Maintain effective security policies, standards and controls, ensuring they are understood, embraced, evidenced and continuously improved. Support compliance with PCI DSS, UK GDPR, the Data Protection Act 2018 and relevant FCA expectations.

Strengthen cyber operations and resilience

Lead security monitoring, threat management, vulnerability management, incident response and cyber preparedness across NewDay’s technology environment. Maintain effective incident playbooks, escalation routes, exercises and lessons-learned processes. Oversee the technology and security contribution to operational resilience, business continuity, disaster recovery and cyber recovery. Drive improvements in security tooling, telemetry, automation and operational efficiency.

Manage technology and information risk

Own the technology and information risk framework, including risk appetite, assessment, quantification, treatment and reporting. Ensure security risks and control effectiveness are clearly understood, challenged and transparent to the right decision-makers. Embed security into major technology change, cloud adoption, platform engineering, digital delivery and supplier-led transformation. Partner with technology and engineering leaders to make secure-by-design delivery practical, proportionate and commercially aligned.

Lead assurance and emerging risk

Oversee third-party and supply-chain security risk across key suppliers, affiliates and strategic partners. Coordinate internal and external assurance activity, including audits, independent assessments and regulatory engagement. Ensure findings, control gaps and regulatory commitments have clear ownership and are delivered to the required standard. Lead NewDay’s approach to AI security and governance, establishing practical controls that enable safe and responsible adoption.

What we’re looking for

You will be an established security leader who can combine strategic judgement with operational delivery. You will be comfortable leading broad, multidisciplinary teams while providing credible, concise advice to executives and Board-level stakeholders.

  • Significant experience leading a broad Information Security function within a regulated organisation, ideally financial services, consumer credit, cards, payments or FinTech.
  • Experience operating as a senior deputy to a CISO, or in an equivalent enterprise security leadership position.
  • Experience across security operations, governance, risk and compliance, architecture, engineering, third-party risk, assurance and operational resilience.
  • Strong practical knowledge of ISO/IEC 27001, PCI DSS, UK GDPR, the Data Protection Act 2018 and recognised control frameworks such as NIST.
  • A solid understanding of technology risk, risk appetite, control effectiveness and operational resilience.
  • Experience leading security incidents, audits, assurance programmes, regulatory engagement and senior-level reporting.
  • Excellent judgement, communication and influencing skills, with the confidence to make clear decisions and build alignment across complex stakeholder groups.
  • Professional certifications such as CISSP, CISM, CRISC, CISA or ISO 27001 Lead Implementer or Auditor would be valuable.
  • Experience of Microsoft Azure security, AI governance, cyber insurance, supplier assurance or major technology transformation would also be beneficial.
Why join NewDay?

This is an opportunity to take on a newly created, enterprise-wide leadership role with the directive to influence how security enables NewDay’s customers, technology strategy and commercial growth. You will work closely with the CISO and senior leaders across technology, product, operations, risk, compliance, data protection, legal and procurement. Most importantly, you will help build a pragmatic, risk-led security culture that protects NewDay while enabling the organisation to move forward with confidence. Externally this job title might also be known as Deputy CISO or Head of Information Security or Information Security Lead.

At NewDay, we value all types of diversity.

We’re an equal opportunity employer and believe that our differences create a vibrant, authentic working culture.

We want all our colleagues to feel able to bring their whole selves to work.

We don’t discriminate on the basis of protected characteristics or identities.

We make sure that every job is crafted to be inclusive and that people with disabilities or caring responsibilities can take part in the application and interview process.

Tell us if you need accommodations: We’ll put reasonable adjustments in place to support you.

We work with Textio to make our job design and hiring inclusive.

Permanent We help people move forward with credit and help our colleagues to move their careers forward too. Through innovative consumer credit and embedded finance products powered by groundbreaking technology, we deliver over 300 million transactions every year. Our brands include Aqua, Marbles, Fluid, Bip and NewPay. We partner with leading brands such as AO, Argos, Boohoo, John Lewis and Lloyds Bank. Over 5 million UK customers are supported by our award-winning customer service.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Head of Information Security (Deputy CISO)
Head of Information Security (Deputy CISO)

NewDay • Greater London

On-site
GBP 120,000 - 180,000
Head of Information Security (Deputy CISO)
Head of Information Security (Deputy CISO)

New Day • City Of London

On-site
GBP 120,000 - 170,000
Head of Technology Operations
Head of Technology Operations

NewDay Technology Limited • Greater London

On-site
GBP 120,000 - 170,000
Deputy CISO: Enterprise Information Security Leader
Deputy CISO: Enterprise Information Security Leader

NewDay Technology Limited • Greater London

On-site
GBP 140,000 - 200,000
Information Security Officer
Information Security Officer

Recognise Bank • Greater London

Hybrid
GBP 90,000 - 130,000
Competitive Time Off
Work From Anywhere
Learning & Development
+5
Deputy CISO & Information Security Leader
Deputy CISO & Information Security Leader

New Day • City Of London

On-site
GBP 120,000 - 170,000
Chief Information Security Officer (CISO)
Chief Information Security Officer (CISO)

DAC Beachcroft LLP • England

On-site
GBP 180,000 - 240,000
Private medical insurance
Income protection insurance
Discounted gym membership
+2
Head of Technology Relationships & Cost Management
Head of Technology Relationships & Cost Management

NewDay Technology Limited • Greater London

Hybrid
GBP 120,000 - 180,000
Head of Security (CISO)
Head of Security (CISO)

ClearCourse Partnership LLP • Greater London

On-site
GBP 100,000 - 150,000
Competitive salary + benefits
25 days holiday + your birthday off
Private medical insurance (Bupa)
+4
Head of Security
Head of Security

ClearCourse Partnership LLP • Greater London

On-site
GBP 100,000 - 150,000
Competitive salary + benefits
25 days holiday + your birthday off
Private medical insurance (Bupa) & health cash plan
+4