Director of Cyber Security & Compliance
Sectora Group · Southampton, England, United Kingdom
Apply & track with Apply EdgeDirector of Cyber Security & ComplianceSouth Coast / Hybrid | Global remit | Future CISO opportunity£90,000 - £100,000We’re looking for a cyber security leader who has built their career from the technology upwards. Someone who understands infrastructure because they’ve worked with it, can sit alongside software engineers and talk credibly about secure development, and is still comfortable getting underneath a technical problem rather than immediately delegating it.You’ll also have accumulated enough cyber security experience to know what good looks like across ISO 27001, Cyber Essentials Plus, data privacy, security operations, third-party risk and compliance. You’ll be capable of moving from an Azure security discussion with an engineer to a conversation about organisational risk with senior leadership.The opportunityFollowing a significant acquisition and continued international growth, our client is building the next generation of its cyber security capability across its UK and US operations.Reporting directly to the Global CIO, you’ll take broad ownership of cyber security and compliance, working across a proprietary SaaS platform, software development, cloud and infrastructure environments, external MSP/MSSP partners and the wider organisation.Initially, you’ll be the organisation’s principal dedicated cyber security specialist.That means this isn't a role for someone who needs a large security team underneath them to be effective.You’ll have the autonomy to assess the existing environment, determine priorities, shape the security roadmap and then get involved in making it happen.We’re particularly interested in your technical foundations.Your career may have started in infrastructure, networking, systems, cloud engineering, software engineering or security engineering before progressing into broader cyber security leadership.Whatever the route, you should still be technically credible today.You might be comfortable:Assessing an Azure/Microsoft environment, particularly identity, permissions, privileged access, Conditional Access, network security and least privilege.Working directly with software engineering and DevOps teams, embedding security into architecture, development and deployment rather than introducing it at the end.Understanding vulnerabilities, security tooling, SIEM/SOC capability, endpoint protection and incident response.Reviewing an MSP or MSSP's recommendations and being technically confident enough to challenge them when something doesn't stack up.Investigating an issue yourself when that's the quickest way to understand what's happening.Translating all of the above into a clear assessment of business risk for senior leadership.We don't expect you to be the engineer configuring every control personally. Equally, if your technical career is now something you mainly talk about in the past tense, this probably isn't the right opportunity.Your cyber & compliance experienceAlongside that technical grounding, you'll have developed meaningful experience across the broader cyber security landscape.We're particularly interested in people who have personally worked with:ISO 27001Cyber Essentials / Cyber Essentials PlusSecurity operationsData protection & privacyThird-party securityA particularly important part of this role is the relationship with the organisation’s software development team.Our client owns and develops a proprietary SaaS platform, with an established engineering team based on the South Coast.We're looking for someone developers will respect.Someone capable of challenging an architecture, asking difficult questions about access or identifying a vulnerability, but who understands that great cyber security shouldn't simply tell engineering teams “no”.You'll help them find the secure route to “yes”.The environmentThis is a relatively lean technology organisation operating within a much larger and growing international group.You'll work across:UK software engineering | US infrastructure | Azure/Microsoft environments | MSP/MSSP partners | SaaS technology | Executive leadershipThere will be competing priorities. There won't always be a playbook. And sometimes you'll be the person expected to work out what happens next.That autonomy is a fundamental part of the opportunity.Where could it lead?This isn't intended to be the final destination for the person joining.As the organisation continues to grow and its UK and US technology operations become increasingly integrated, there is a genuine opportunity for the remit to develop towards Group CISO.We're therefore interested in someone who already has enough experience to take ownership today, but still has the appetite, curiosity and technical connection to grow significantly from here.You might already be a Head of Cyber Security, Head of Information Security, Cyber Security Director, Security Engineering Leader or CISO.Your current title matters considerably less than the journey that got you there.If you've spent your career building from the technical foundations upwards and can now combine hands-on technical credibility with mature cyber security and compliance ownership, we'd particularly like to hear from you.