Haystack
← Back to Jobs
Full time
Administrative
ER

Head of Information Security

Endeavour RecruitmentLondon🇬🇧United KingdomPosted 9 Oct 2026

Quick Overview

Seniority
Leader
Employment type
Full Time
Work mode
Hybrid
Location
London, United Kingdom

Job Description

Head of Information Security

Location: Central London - Hybrid (2 days per week onsite)
Salary: Up to 125,000 per annum, depending on experience
Working hours: Monday to Friday, 9:00am-5:00pm
Start date: As soon as possible

About the Opportunity

Endeavour Recruitment is looking for an experienced Head of Information Security on behalf of our client, an established international organisation with a complex technology environment and a strong focus on protecting its systems, data and intellectual property.
This is an excellent opportunity for a technically strong security professional to take ownership of the organisation's information and cyber security agenda. Reporting to the senior technology leadership team, you will define security priorities, shape the organisation's security strategy and ensure that practical, proportionate improvements are implemented across the business.
This is a senior individual-contributor position rather than a traditional departmental management role. You will not be responsible for managing a dedicated security team. Instead, you will work closely with infrastructure, technology and external service provider teams, providing technical expertise, setting standards and ensuring security risks are appropriately managed.
The successful candidate will combine strong hands-on technical experience with the ability to influence senior stakeholders, challenge existing practices constructively and translate complex security issues into clear business priorities.

Key Responsibilities

Develop and maintain the organisation's information and cyber security strategy, including a prioritised roadmap and investment plan.
Establish and maintain security policies, standards and technical baselines aligned with recognised industry practices.
Review the security of enterprise networks, infrastructure, cloud services, endpoints, applications and identity platforms.
Work with technical teams to identify security gaps, agree remediation plans and monitor progress.
Provide security architecture guidance for new systems, technology projects, cloud services and infrastructure changes.
Drive improvements in identity and access management, including authentication, multi-factor authentication and privileged access.
Lead vulnerability management activities, prioritising remediation based on risk and potential business impact.
Establish effective security monitoring, threat detection and incident response arrangements.
Coordinate responses to significant security incidents, ensuring a calm, structured and effective approach.
Assess third-party and supplier security risks and ensure security requirements are considered during procurement.
Provide senior management with clear reporting on security risks, priorities and recommended actions.
Support audit, insurance, customer and regulatory requirements.
Promote security awareness and encourage practical, effective security practices throughout the organisation.

Essential Skills and Experience

Significant professional experience in information security or cyber security, with a strong foundation in hands-on technical roles.
Proven experience securing enterprise network and infrastructure environments.
Good knowledge of cloud security, particularly Microsoft Azure and Microsoft 365. Experience with Google Enterprise environments would be advantageous.
Strong understanding of identity and access management, authentication, privileged access and access-control principles.
Experience in vulnerability management, security monitoring and incident response, including coordinating significant security incidents.
A track record of developing or improving security policies, technical standards and operational controls.
Experience assessing technical security risks and translating findings into practical business decisions.
The ability to communicate security risks and recommendations effectively to senior stakeholders and non-technical audiences.
Working knowledge of recognised security frameworks, such as the NIST Cybersecurity Framework, CIS Controls and ISO/IEC 27001.

Technical Knowledge

The successful candidate should have working knowledge across several of the following areas:
Network security: Secure network design, segmentation, firewalls, remote access and secure connectivity.
Infrastructure and endpoint security: Server hardening, endpoint protection, endpoint detection and response, and patch management.
Cloud and SaaS security: Secure cloud configurations, configuration management and cloud service protection.
Identity and access management: Directory services, multi-factor authentication, conditional access and privileged access management.
Security monitoring: Logging, SIEM tools and managed detection and response services.
Vulnerability management: Vulnerability scanning, penetration testing and remediation planning.
Security architecture: Assessing proposed designs and ensuring security is Embedded into technology changes and new projects.

Desirable Experience

Experience working within an international or multi-site organisation.
Experience in a business where intellectual property, data protection and information security are particularly important.
A recognised information security or cyber security certification.
Relevant certifications are desirable but not essential. Practical experience, technical credibility and the ability to deliver meaningful security improvements are the key priorities.

Personal Attributes
The ideal candidate will be:

Technically credible, curious and comfortable investigating complex systems and security challenges.
Pragmatic, with the ability to distinguish significant risks from lower-priority issues.
Commercially aware and able to balance security requirements with cost, usability and operational needs.
Confident influencing stakeholders and technical teams without direct management authority.
Comfortable challenging established practices constructively and supporting recommendations with evidence.
An effective communicator who can engage with both technical specialists and senior business leaders.
Calm, methodical and decisive when managing security incidents.
Self-sufficient and proactive, while working collaboratively with the wider technology function.

Working Arrangements and Application Process

This position offers a hybrid working arrangement, with two days per week onsite in Central London.

To apply, please submit your CV to Endeavour Recruitment, including the following information:

Confirmation of your legal right to work in the UK, including visa expiry details where applicable.
Confirmation that the hybrid working arrangement is suitable.
Your salary expectations.
Your current notice period.
Your availability to start.

Applications will be reviewed against the essential technical requirements and relevant experience.

Interested in discussing the opportunity? Contact Endeavour Recruitment to find out more and submit your application.

Similar jobs