Head of Operational Information Security, Risk and Assurance

Reference: x6kh6xvw87zr66pboz3q

We are seeking an experienced Head of Operational Information Security, Risk and Assurance to lead the development and delivery of a robust operational security, risk and assurance function. This is a senior leadership role with responsibility for protecting information assets, strengthening resilience and ensuring that security practices support organisational objectives. You will provide clear direction across information security operations, technology risk, governance, compliance and assurance, while promoting a culture of shared accountability for security.

You will oversee the identification, assessment and treatment of information and technology risks, ensuring that effective controls are designed, implemented and continuously improved. Responsibilities will include leading security assurance activities, managing audit and regulatory engagements, monitoring compliance with relevant legislation and recognised frameworks, and reporting risk and control performance to senior stakeholders. You will also guide incident preparedness and response, vulnerability and threat management, third-party assurance, business continuity considerations and the maintenance of appropriate policies, standards and procedures. Building strong relationships with technology, operational, legal, procurement and business teams will be essential, as will the ability to communicate complex risks in a clear and practical way.

Applicants should have substantial experience in information security, technology risk, governance, assurance or a closely related discipline, including experience operating at a senior management level. You will bring strong knowledge of security frameworks, control environments, risk methodologies, audit principles and relevant regulatory expectations. Professional qualifications such as CISSP, CISM, CRISC, CISA or equivalent experience are desirable. We are looking for a confident and collaborative leader who can influence at all levels, make sound judgements under pressure and balance strong security controls with effective service delivery. The successful candidate will demonstrate strategic thinking, operational credibility, excellent written and verbal communication skills, and a commitment to continuous improvement.

COMPETITIVE SALARY
Added 04/09/2026
Reference: x6kh6xvw87zr66pboz3q

Head of Operational Information Security, Risk and Assurance

London, England, United Kingdom Permanent Information Assurance

Other similar jobs

Head of Information and Data Security and Data Protection Officer

Added 22/07/2026

An exciting opportunity has arisen for an experienced professional to take on the role of Head of Information and Data Security and Data Protection Officer. This pivotal position will lead on all aspects of information security, data protection, and privacy compliance across the organisation, ensuring the safeguarding of sensitive data and alignment with relevant legislation, including GDPR and other applicable regulations. The successful candidate will be responsible for developing, implementing, and maintaining robust security strategies, policies, and procedures. You will provide expert advice and guidance to senior management and staff, conduct regular risk assessments, and oversee incident response protocols. Key...

Learn more

Technical Specialist (cyber related), Operational Risk and Resilience, R&CGI Operational Risk and Resilience Team - Insurance Directorate

Added 24/07/2026

We are seeking a highly skilled Technical Specialist with a strong focus on cyber-related issues to join our Operational Risk and Resilience Team within the Insurance Directorate. In this role, you will be responsible for identifying, assessing, and mitigating cyber risks that could impact the organization's operational resilience. You will work closely with cross-functional teams to develop and implement strategies aimed at enhancing the cybersecurity posture and ensuring compliance with relevant regulations and industry standards. Your expertise will be critical in conducting risk assessments, analyzing potential threats, and recommending appropriate risk management solutions. The ideal candidate will have a solid...

Learn more

Operational Risk Oversight Manager – Technology, Cyber and Data

Added 11/08/2026

We are seeking an experienced Operational Risk Oversight Manager specializing in Technology, Cyber, and Data to join our team. In this role, you will be responsible for developing and implementing a robust operational risk framework that addresses technology and cyber risks across the organization. You will conduct risk assessments, evaluate existing controls, and ensure compliance with regulatory requirements while providing guidance on best practices to mitigate potential risks. Your expertise will be crucial in enhancing the organization's resilience against cyber threats and safeguarding sensitive data. The ideal candidate will possess a deep understanding of operational risk management principles, particularly in...

Learn more

Head of Security Standards, Risk & Assurance

Added 02/09/2026

We are seeking an experienced Head of Security Standards, Risk & Assurance to lead the development and continuous improvement of security governance, risk management and assurance activities across a complex organisation. This is a senior role responsible for establishing clear security standards, strengthening risk-based decision-making and providing confidence that critical services, systems and information are protected effectively. You will work closely with technology, business, legal, compliance, audit and operational teams to embed proportionate, practical and measurable security controls. Your responsibilities will include owning the security standards and control framework; maintaining policies, principles and guidance aligned with recognised industry practices and...

Learn more

Senior Security Assurance Specialist , AWS Compliance and Security Assurance EMEA

Added 19/08/2026

We are seeking a Senior Security Assurance Specialist to join our team, focusing on compliance and security assurance across the EMEA region. In this role, you will be responsible for leading security assessments, audits, and compliance initiatives to ensure alignment with industry standards and regulatory requirements. You will collaborate with various stakeholders, including engineering, product management, and legal teams, to develop and implement security policies, procedures, and best practices. Your expertise will be crucial in identifying vulnerabilities and recommending effective mitigation strategies to enhance security posture. The ideal candidate will have a strong background in information security, risk management, and...

Learn more

Security Assurance Specialist , AWS Compliance and Security Assurance EMEA

Added 19/08/2026

We are seeking a detail-oriented Security Assurance Specialist to join our dynamic team focused on compliance and security assurance within the EMEA region. In this role, you will be responsible for evaluating and implementing security measures to protect sensitive information and ensure compliance with industry regulations. Your expertise will be crucial in assessing risks, conducting audits, and developing strategies to enhance the security posture of our cloud services. You will collaborate with cross-functional teams to identify vulnerabilities and recommend solutions that align with best practices and compliance requirements. The ideal candidate will possess a strong understanding of cloud security frameworks...

Learn more

Head of Governance, Risk and Compliance (Information Security)

Added 10/08/2026

We are seeking a dynamic and experienced professional to take on the role of Head of Governance, Risk and Compliance (Information Security). In this leadership position, you will be responsible for developing and implementing a robust governance framework that ensures compliance with relevant laws, regulations, and industry standards. You will lead the organization’s risk management strategy, identifying potential risks and developing mitigation plans to protect sensitive information and maintain operational integrity. Your expertise will guide the creation and enforcement of policies and procedures to enhance the organization’s information security posture. The ideal candidate will possess strong analytical skills and a...

Learn more

Certification and Assurance - Senior Security/Technology Risk Analyst

Added 20/08/2026

We are seeking a skilled and experienced Senior Security/Technology Risk Analyst to join our dynamic team. In this role, you will be responsible for identifying, assessing, and managing risks associated with technology and security across various platforms. You will conduct thorough risk assessments, ensuring compliance with regulatory requirements and internal policies. This includes evaluating the effectiveness of existing security controls and making recommendations for enhancements to safeguard our systems and data. You will also collaborate with cross-functional teams to implement security best practices and promote a culture of risk awareness within the organization. The ideal candidate will possess a deep...

Learn more

Certification and Assurance - Senior Security/Technology Risk Analyst

Added 13/08/2026

We are seeking a highly skilled Senior Security/Technology Risk Analyst to join our dynamic team. In this role, you will be responsible for assessing and mitigating security risks associated with technology and information systems. You will conduct thorough risk assessments, develop risk management strategies, and ensure compliance with industry standards and regulations. The ideal candidate will possess a deep understanding of security frameworks and have experience in implementing security controls across diverse environments. Your duties will include collaborating with cross-functional teams to identify and evaluate security vulnerabilities, conducting audits and assessments, and providing expert guidance on best practices. You will...

Learn more

Cyber Risk and Assurance Specialist

Added 04/09/2026

We are seeking a Cyber Risk and Assurance Specialist to support the identification, assessment and management of cyber security risks across a complex technology and business environment. This role will help strengthen security governance, provide assurance over key controls and promote practical, risk-based improvements that protect information, systems and services. You will work closely with technology, operational risk, compliance, audit and business stakeholders to ensure cyber risks are understood, appropriately documented and managed within agreed tolerance levels. Key responsibilities will include maintaining cyber risk and control registers; conducting risk assessments for projects, suppliers, systems and emerging technologies; reviewing security policies,...

Learn more

Junior Cyber Risk and Assurance Analyst

Added 01/09/2026

We are seeking a motivated Junior Cyber Risk and Assurance Analyst to support the development, maintenance and continuous improvement of cyber security risk and assurance activities. This is an excellent opportunity for someone at the early stage of their cyber security career who is keen to build practical experience across governance, risk management, compliance and security assurance. You will work with colleagues across technology, risk and business functions to help identify, assess and manage cyber security risks in a structured and consistent way. Key responsibilities will include supporting cyber risk assessments, maintaining risk registers and action plans, and assisting with...

Learn more

Senior Security Engineer, Operational Research and Development

Added 04/09/2026

We are seeking a Senior Security Engineer, Operational Research and Development to help shape the next generation of security capabilities. In this role, you will investigate emerging threats, assess new technologies and develop practical solutions that strengthen the resilience of complex systems. You will work across research, engineering and operational teams to translate security challenges into actionable improvements, while balancing innovation, usability, performance and risk. Your responsibilities will include designing and leading security research projects; developing prototypes, proof-of-concept tools and technical demonstrations; analysing vulnerabilities, attack techniques and defensive controls; and evaluating the security implications of new platforms, architectures and technologies....

Learn more

Senior Security Engineer, Operational Research and Development

Added 03/09/2026

We are seeking a Senior Security Engineer to lead operational research and development initiatives that strengthen the security, resilience and performance of complex technology environments. This role will combine hands-on engineering with structured investigation, enabling the organisation to assess emerging threats, validate defensive capabilities and develop practical solutions for evolving operational needs. You will work across security, infrastructure, software and operations teams to turn research findings into reliable, scalable improvements. Responsibilities will include designing and conducting security research, technical experiments, proof-of-concept implementations and controlled assessments. You will investigate vulnerabilities, attack techniques, defensive technologies and operational risks; develop tools and prototypes;...

Learn more

Operational Security Lead and Vulnerability Manager

Added 01/09/2026

We are seeking an experienced Operational Security Lead and Vulnerability Manager to strengthen the organisation’s cybersecurity posture and ensure that security risks are identified, assessed, and addressed effectively. This role will lead the operational management of security controls, vulnerability assessments, remediation activity, and risk reporting across a complex technology environment. You will work closely with infrastructure, applications, cloud, engineering, and risk teams to embed secure practices and maintain a clear view of the organisation’s exposure to cyber threats. Key responsibilities include owning the vulnerability management lifecycle, from discovery and prioritisation through to remediation, exception management, and verification. You will oversee...

Learn more
At least 8 characters, 1 uppercase, 1 lowercase and 1 special character or number
Your file must be a doc, docx or pdf. No larger than 5MB.