Our client is a fast-growing technology group spanning fintech, blockchain/Web3, payments, custody, stablecoins and they are hiring an InfoSec Lead to build and own security for the business as it scales into new regulated territory.
Role Overview
The Information Security Lead is a senior player-manager responsible for establishing and owning the information security policy framework and ISMS. This role leads ISO 27001:2022 certification, governs identity and access management, and ensures security standards are embedded across all engineering teams.
Key Responsibilities
Security Policy and ISMS Ownership
- Establish and maintain the information security policy framework, ISMS risk register, risk treatment plan, and Statement of Applicability (SoA)
- Lead the organisation through ISO 27001:2022 certification and ongoing surveillance audits; coordinate all departments on control implementation and evidence
- Conduct periodic policy reviews to ensure alignment with regulatory requirements and evolving threat landscapes
Identity, Access and Secure Development
- Design and implement IAM controls including SSO, MFA, and PAM; govern user provisioning and access review processes
- Define secure development standards (e.g. OWASP); conduct security architecture reviews and threat modelling with the applications team
- Configure and maintain email security gateways and endpoint protection platforms
Security Operations Oversight and Support
- Provide strategic direction and escalation support to the Senior Security Engineer and SOC team
- Review security incident post-mortems and ensure effective remediation
- Manage security service providers and vendors, including MSSPs and penetration testing firms
- On-call availability required to support 24x7 incident response coverage
Requirements
Experience
- 10+ years of progressive information security experience, with 3+ years in a lead or management role
- Demonstrated experience designing and implementing an ISMS and leading ISO 27001:2022 certification programmes
- Experience establishing IAM frameworks (SSO, MFA, PAM) and managing external audits and regulatory examinations
- Proven experience leading incident response, containment, and post-incident reviews in a production environment
- Experience managing MSSPs, penetration testing firms, and security tooling vendors; regulated industry background preferred
Technical Skills
- ISMS design and operation: risk register, SoA, control framework, continual improvement
- IAM platforms: SSO (e.g. Okta, Azure AD or equivalent), MFA, PAM (e.g. CyberArk, BeyondTrust, or equivalent)
- Secure development frameworks: OWASP, SANS CWE Top 25
- Security architecture review methodologies and threat modelling
- Email security gateways and endpoint protection platforms
- ISO 27001:2022 control framework implementation across all domains
Qualifications
- Bachelor's degree or higher in Information Security, Computer Science, or a related discipline
- CISSP or CISM strongly preferred