Jobs
My ads
My job alerts
Sign in
Find a job Career Tips Companies
Find

Group head of information security

Birmingham (West Midlands)
Ampa Holdings LLP
Head of information security
€150,000 - €200,000 a year
Posted: 22h ago
Offer description

Group Head of Information Security

Department: Ampa Group Services - Chief Information Office - CIO Central - CIO Central - 9399

Employment Type: Permanent - Full Time

Location: Birmingham

Reporting To: Andrew Foreman



Description

The Opportunity
We are seeking a highly skilled and experienced Group Security Officer (GSO) to lead our information security strategy and operations. The GSO will be responsible for safeguarding our firm's digital assets, ensuring compliance with relevant laws and regulations, and mitigating risks associated with cyber threats. This role requires a strategic thinker with strong leadership capabilities and a deep understanding of the legal sector's unique security challenges.
Group Security Officer is a leadership role reporting directly to the CIO with close working relations to the Exec, the Board, Directors across the group and the compliance officer for legal practice (COLP).
The CIO team is responsible for Change (Business and Technology), Technology Operations, Applications, Information Security, Resilience and Risk across all our group companies and brands.



What you will be doing:

The role holder will be responsible for identifying, evaluating and reporting on legal and regulatory, IT, and cybersecurity risk to information assets, as well as key business risks, while supporting and advancing business objectives.
You will also embed knowledge and best practice on risk avoidance and information security and working with the COLP and other relevant post holders, ensure the group is in line with statutory, regulatory and industry compliance standards/guidelines as appropriate.
The role will also be responsible for enhancing our governance to include our emerging AI governance frameworks including ISO42001, as well as improving our group approach to resilience.

Key Responsibilities:
* Develop and Implement Security Strategy: Create and execute a comprehensive information security strategy that aligns with the firm's business objectives and regulatory requirements. Work closely with other departments, including our brands and group services to ensure security initiatives are integrated into all aspects of the firm's operations.
* Risk Management: Identify, assess, and mitigate information security risks. Conduct regular risk assessments and assurance to ensure the firm's security posture remains robust.
* Policy and Procedure Development: Develop, implement, and maintain security policies, standards, and procedures to protect the firm's digital assets.
* Compliance: Ensure compliance with relevant laws, regulations, and industry standards, including GDPR and other data protection regulations. This will include ensuring ongoing ISO27001 and CE+ accreditation.
* Incident Response: Lead the firm's response to security incidents and breaches, ensuring timely and effective resolution. Develop and maintain incident response plans.
* Security Governance: Review, evolve, and lead the security governance structure across the firm. Implement standard information security metrics and produce security reports.
* Security Assurance: Support and execute an appropriate assurance framework to validate security controls are effective. Facilitate risk assessment and risk management processes to ensure that risk is maintained at appropriate levels.
* Security Architecture: Working with the Security Architect as a Service capability, design and implement the firm's security architecture. Ensure that security controls are integrated into the design and implementation of all systems. Evaluate and recommend security technologies and solutions to protect the firm's digital assets. Collaborate with IT and other departments to ensure that security architecture aligns with business objectives and regulatory requirements.
* Security Operations: Oversee the day-to-day operations of the security team, including monitoring, detection, and response to security incidents. Ensure the implementation and management of security systems and tools.
* Security Awareness and Training: Promote security awareness across the firm. Develop and deliver training programs to educate employees on best practices for information security.
* Data Privacy and Data Protection Officer (DPO): Working with the DPOaaS capability, ensure the firm’s compliance with data privacy laws and regulations, including GDPR. Act as the Data Protection Officer (DPO) and oversee all data protection activities. Develop and implement data privacy policies and procedures. Conduct data protection impact assessments (DPIAs) and ensure that data subjects' rights are upheld. Provide guidance and training on data privacy matters to employees.
* Third-Party Supply Chain Security: Ensure information security assurance across the firm's supply chain, including clients and suppliers. Conduct security assessments of third-party vendors and partners. Develop and enforce security requirements for third-party contracts. Monitor and manage third-party compliance with the firm's security policies and standards.
* Reporting: Provide regular updates to senior management and the board of directors on the status of the firm's information security program and any emerging threats.



What you will need:

* Previously led teams of Information Security professionals.
* Depth of knowledge of Information Security standards, tools and processes.
* Good understanding of GDPR, COBIT, ISO27001, PCI DSS, Cyber Essentials (including Plus) and risk management frameworks.
* Familiarity with industry leading security products and solutions.
* Practical, real-life and hands-on experience of security technologies.
* Knowledge and experience of Business Continuity Management.
* Implemented crisis management processes and led responses to real crisis.
* Member of Institute of Information Security Professionals (M.IISP) or have the qualification, skills and experience to become a member.
* Certification(s) in one or more of CISSP, ISO27001 Lead Auditor, CISM, CISA is expected.
* Organised with a proven ability to prioritise workload, meet deadlines, and utilise time effectively
* Strong working knowledge of risk management and previous experience working with risk
* Strong interpersonal and communication skills; able to deal effectively with diverse skill sets and personalities, works effectively as a team players



Benefits, Agile Working and Additional information

We embrace agile working and offer a blended approach to where and how we work.

We appreciate that people have different needs and preferences and we’re keen to be flexible, after all, we value what you do, not where you do it.

We have hubs in a variety of different locations across the United Kingdom. This role will be a blend of home working and working from one of our London or Midlands hubs.

Additional information

Want to find more about our amazing benefits ?
-------------------------------------------------------------------
Please be aware, for some vacancies, where we receive high numbers of applications we may need to bring the close date forward.

Due to the nature of the work undertaken, confirmation of employment will be subject to a variety of checks which will be carried out once an offer of employment is accepted. Details of the checks can be found here.

Equal opportunities

Ampa Group is a committed equal opportunities employer. We seek to attract, develop and retain talented people from a diverse range of backgrounds and cultures. We value and respect individuality and encourage a culture within our business where people can be themselves and be valued for their strengths and experiences. Everyone who either applies to or works for the firm is treated equally, regardless of their gender, age, ethnic origin, nationality, marital status, sexual orientation or religious beliefs.
#J-18808-Ljbffr

Apply
Create E-mail Alert
Job alert activated
Saved
Save
Similar job
Head of information security
West Bromwich
JR United Kingdom
Head of information security
€150,000 - €200,000 a year
Similar job
Head of information security
Wolverhampton (West Midlands)
JR United Kingdom
Head of information security
€125,000 - €150,000 a year
Similar job
Head of information security
Birmingham (West Midlands)
JR United Kingdom
Head of information security
€150,000 - €200,000 a year
See more jobs
Similar jobs
Security jobs in Birmingham (West Midlands)
jobs Birmingham (West Midlands)
jobs West Midlands
jobs England
Home > Jobs > Security jobs > Head of information security jobs > Head of information security jobs in Birmingham (West Midlands) > Group Head of Information Security

About Jobijoba

  • Career Advice
  • Company Reviews

Search for jobs

  • Jobs by Job Title
  • Jobs by Industry
  • Jobs by Company
  • Jobs by Location
  • Jobs by Keywords

Contact / Partnership

  • Contact
  • Publish your job offers on Jobijoba

Legal notice - Terms of Service - Privacy Policy - Manage my cookies - Accessibility: Not compliant

© 2025 Jobijoba - All Rights Reserved

Apply
Create E-mail Alert
Job alert activated
Saved
Save