- Company Name
- PEXA UK
- Job Title
- Head of Cyber Security (FCA Experience essential)
- Job Description
-
**Job Title**
Head of Cyber Security (FCA Experience Essential)
**Role Summary**
Lead and execute the cyber security strategy for a UK‑based digital property settlement platform. Own security operations, engineering, governance, and compliance across the UK brands. Collaborate with senior technology, risk, legal, and operations stakeholders to embed a secure-by‑design culture and ensure alignment with FCA and ISO 27001 requirements.
**Expectations**
- Demonstrated senior leadership in cyber security, preferably with FCA exposure.
- Proven track record of developing and implementing enterprise‑wide security roadmaps.
- Ability to mentor and grow a multi‑disciplinary SOC, engineering, and information security team.
- Strong stakeholder management: influence senior leadership, risk, and external auditors.
- Hands‑on expertise in modern threat‑detection platforms, cloud security (Azure, AWS), vulnerability management, and policy governance.
- Commitment to continuous improvement, incident response excellence, and regulatory compliance.
**Key Responsibilities**
1. **Strategy & Governance**
- Define UK cyber security strategy, roadmap, and posture aligned with business and group objectives.
- Serve as the senior security authority for all UK brands.
- Own the information security framework, policies, and control standards (ISO 27001, FCA).
- Lead audit preparation, evidence collection, and control testing for certifications and lender assurances.
2. **Security Operations**
- Oversee SOC operations, ensuring timely threat detection, response, and resolution.
- Enhance detection capabilities using Cortex XDR, Abnormal Security, Splunk, Nucleus.
- Manage end‑to‑end vulnerability management: scanning, prioritisation, remediation tracking.
- Ensure secure configuration, endpoint management, and patch compliance across hybrid clouds.
3. **Team Leadership**
- Lead, mentor, and grow a multidisciplinary team across SOC, engineering, and information security functions.
- Foster a culture of security awareness through training, phishing simulations, and education.
4. **Collaboration & Culture**
- Partner with engineering, IT, legal, HR, operations, and third‑party vendors to embed security into daily practices.
- Provide input on vendor and third‑party risk assessments.
- Report cyber risk, maturity, and incidents transparently to senior leadership.
**Required Skills**
- Senior cyber security leadership and strategy formulation.
- Deep knowledge of FCA regulatory requirements and ISO 27001 implementation.
- Expertise in SOC management, threat detection, incident response, and vulnerability management.
- Cloud security (Azure, AWS) and secure configuration skills.
- Proven ability to conduct and manage audits and compliance reviews.
- Strong communication and stakeholder influence skills.
- Experience with third‑party risk management and vendor assessments.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, or related field (Master’s preferred).
- Professional certifications: CISSP, CISM, CISA, ISO 27001 Lead Implementer, or equivalent.
- FCA‑specific cyber security knowledge or equivalent regulatory compliance experience.