Job Details

Group Head of Information Security & Cyber Operations

Group Head of Information Security & Cyber Operations

📍 Commutable from: Oxford, Beaconsfield, London, Uxbridge,
£115,000 per annum
£115000 - £125000/annum £115,000 - c.£125,000 p.a. + benefits
Industry: IT
Applications: <10
Posted: 28-09-2026
Company: William Scott Consulting Ltd
Type: Permanent
Reference: 225659336

Job Description:

Group Head of Information Security & Cyber Operations
 
Commutable from: Oxford, Beaconsfield, London, Uxbridge, Wycombe, Watford, Aylesbury, Windsor, Maidenhead, Reading, Hemel Hempstead.
 
Package: £115,000 - c.£125,000 p.a. + benefits
 
There are cyber security roles where you're brought in to maintain what already exists.
 
There are others where everything is on fire and you're expected to put it out.
 
This is neither.
 
The foundations are there.
 
There's an established function, existing capability and a business that takes information security seriously.
 
But there's also a recognition that it can be better.
 
Much better.
 
And that's where you come in.
 
We're looking for a Group Head of Information Security & Cyber Operations to take ownership of the function, understand exactly where it is today and then lead its next stage of maturity.
 
This isn't about arriving with a pre-written playbook.
 
Your first job will be to get curious.
 
Understand the tools. The processes. The procedures. The people.
 
What's working. What isn't. Where the vulnerabilities are. Where capability needs strengthening. And, importantly, what good needs to look like for this organisation.
 
Then you'll build the roadmap to get there.
 
And deliver it.
 
You've probably got a few scars.
 
Because we're not looking for somebody whose experience of transformation has predominantly been advising other people how to do it.
 
We want somebody who's actually lived it.
 
Someone who has built or matured security operations and understands the reality of taking a function from where it is to where it needs to be.
 
You'll be comfortable navigating the competing demands of security, compliance, operations and the wider business.
 
Your background will be from within a complex and regulated environment.
 
The sector matters.
 
But the experience behind it matters more.
 
You'll know what it's like to create a strategy at 30,000 feet and then find yourself considerably closer to the ground when something needs sorting.
 
Because this is a leadership position.
 
But it isn't a position from which you'll simply lead at a distance.
 
You'll need to be able to strategise and execute. To challenge and support. To think long term and act today.
 
And, when required, roll your sleeves up and get involved.
 
So, what are you actually taking ownership of?
 
You'll lead the Group Information Security and Cyber Operations function, owning the development and delivery of the cyber security strategy and roadmap.
 
That spans cyber operations and incident management; security risk, governance and compliance; cyber resilience and business continuity; security assurance; tooling and operational capability; and the continued development of the team.
 
You'll oversee areas including MDR/XDR, security monitoring, threat detection and vulnerability management, whilst operating across regulatory and contractual security requirements, including Cyber Essentials Plus.
 
And when significant cyber incidents occur, you'll be expected to lead.
 
Calmly.
Credibly.
 
And with the judgement to know what matters most.
 
This isn't happening in isolation.
 
You'll sit on the IT Senior Leadership Team, alongside the Group Heads responsible for Architecture, Service Delivery, Software and End User.
 
Your influence will extend beyond your own function.
 
You'll contribute to the direction of the wider IT organisation, working with Compliance, Risk and other stakeholders whilst translating complex security matters into language that business and technology leaders can actually use to make decisions.
 
Because great cyber security can't exist in its own little kingdom.
 
It has to work for the business it's protecting.
 
And here's perhaps the most interesting part.
 
You're not inheriting a finished product.
 
Think of the current function as somewhere around 6 out of 10.
Not broken. Not dysfunctional. Not requiring somebody to ride in and rescue it.
 
But equally, not yet where the organisation wants it to be.
 
And that creates quite an unusual opportunity.
 
The broad expectation looks something like this:
 
First 3 months: Discover. Get underneath the function. Understand the people, processes, technology, risks, capability and current maturity.
 
3-6 months: Define. Establish the appropriate team structure and create the roadmap for the function.
 
6-12 months: Build. Progress the function towards Maturity Level 2.
 
12-24 months: Transform.
Drive towards Maturity Level 4 and a genuinely high-performing Information Security and Cyber Operations capability.
 
How you get there is part of why we're hiring someone like you.
 
Who will this suit?
 
Probably somebody who looks at a function that's already a 10/10 and thinks:
 
"What am I actually here to do now?"
 
Someone who enjoys understanding why things are the way they are.
 
Who asks questions before prescribing answers.
 
Who can see the destination but isn't naïve about what it takes to get there.
 
You'll bring significant leadership experience.
 
You'll have influenced senior stakeholders.
 
Managed difficult incidents.
 
Made decisions when the information available wasn't perfect.
 
And you'll have experienced enough transformation to know that a PowerPoint roadmap is the easy bit.
 
Making it happen is what counts.
 
Relevant professional certifications such as CISSP, CISM or CRISC would be advantageous, alongside experience of areas such as outsourced SOC/MDR/XDR environments, cloud security, Zero Trust, security architecture or international/multi-site operations.
 
But this appointment won't be made by counting acronyms.
 
It'll be made by understanding what you've actually done with them.
 
The opportunity.
 
You'll have ownership. You'll have influence. You'll have a seat at the table.
 
And you'll have enough work ahead of you to make the role genuinely interesting.
 
So, if you've already lived through security transformation...
 
If you know what good looks like because you've actually had to build it...
 
And if the idea of being handed a blank canvas rather than somebody else's finished picture
appeals to you...
 
We should probably talk.
 
Send a copy of your profile and we'll get it arranged.
Apply Now