Head of Information Security
Job description
Head of Information Security at Bamboohr.
About the role
As the Head of Information Security at Bamboohr, you will play a pivotal role in safeguarding our organization's data and technology assets. This leadership position requires a strategic thinker who can develop and implement robust security policies and practices. You will be responsible for overseeing the information security framework, ensuring compliance with industry standards, and leading a team of security professionals dedicated to protecting our systems against threats. Your expertise will be crucial in fostering a culture of security awareness across the organization.
Key facts
What you'll do
- Develop and implement a comprehensive information security strategy that aligns with Bamboohr's business objectives and regulatory requirements.
- Lead and manage the information security team, providing mentorship and guidance to enhance their skills and performance.
- Conduct regular risk assessments and vulnerability analyses to identify potential security threats and develop mitigation strategies.
- Establish and maintain security policies, procedures, and standards to protect sensitive information and ensure compliance with relevant regulations.
- Collaborate with cross-functional teams to integrate security best practices into all aspects of the organization's operations.
- Oversee incident response planning and execution, ensuring that the organization is prepared to respond effectively to security breaches.
- Monitor and report on the effectiveness of security measures, providing insights and recommendations for continuous improvement.
- Stay abreast of the latest security trends, threats, and technologies, and adapt the security strategy accordingly.
- Foster a culture of security awareness by providing training and resources to employees at all levels.
- Liaise with external partners, vendors, and regulatory bodies to ensure that security practices meet industry standards and requirements.
- Prepare and present security reports to senior management and the board, highlighting risks, incidents, and mitigation strategies.
- Drive initiatives to enhance the organization's overall security posture and resilience against cyber threats.
Requirements
- Proven experience in information security management, with at least 7 years in a relevant role.
- Strong knowledge of security frameworks and standards such as ISO 27001, NIST, and GDPR.
- Demonstrated experience in risk management and incident response.
- Excellent leadership and team management skills, with the ability to motivate and develop a high-performing team.
- Strong analytical and problem-solving abilities, with a keen attention to detail.
- Exceptional communication skills, both written and verbal, with the ability to convey complex security concepts to non-technical stakeholders.
- Relevant certifications such as CISSP, CISM, or equivalent are highly desirable.
- Experience with security technologies, including firewalls, intrusion detection systems, and encryption methods.
- Familiarity with cloud security and securing remote work environments is a plus.
Nice to have
- Experience in a financial services or fintech environment is advantageous.
- Knowledge of emerging technologies such as AI and machine learning in the context of security.
- Previous experience in developing and delivering security awareness training programs.
- Understanding of privacy laws and regulations beyond GDPR, such as CCPA or HIPAA.
Skills & tools
- Proficiency in security information and event management (SIEM) tools.
- Familiarity with endpoint protection, identity and access management (IAM), and data loss prevention (DLP) solutions.
- Experience with vulnerability management tools and penetration testing methodologies.
- Knowledge of network security protocols and best practices.
- Ability to analyze security logs and reports to identify anomalies and potential threats.
Practical notes
- This role is based in Barbican, London, and may require occasional travel for conferences or meetings.
- The successful candidate will be expected to work collaboratively with various departments to foster a security-first culture.
- Bamboohr is committed to diversity and inclusion, and we encourage applications from individuals of all backgrounds.
- The application process will include interviews and assessments to evaluate both technical skills and cultural fit within the organization.
META
Company: Bamboohr
Title: Head of Information Security
Listed
location: Barbican, London, City of
Job type: Full-time
Apply URL: https://duco.bamboohr.com/careers/581
Tags: Security