Head of Data Security

City of London
2 days ago
Create job alert

HEAD OF DATA SECURITY - LONDON - UK ONLY

Key Responsibilities:

Define and drive the enterprise-wide data protection strategy, ensuring robust safeguards for sensitive information across cloud services, applications, and endpoints.
Develop and mature the organisation's DLP operating model, including policy frameworks, rule sets, alerting thresholds, and continuous monitoring enhancements.
Implement strong governance for data classification, handling, retention, and encryption, ensuring secure management of data throughout its lifecycle.
Lead the organisation's strategic direction on quantum‑resilient security, including assessments of quantum-related risks and the creation of a staged readiness plan.
Assess, recommend, and oversee the rollout of advanced cryptographic technologies, ensuring alignment with evolving standards and business risk appetite.
Embed secure data practices across projects and platforms, working collaboratively with Architecture, Technology, Risk, Legal, and Compliance to ensure security is built in from the outset.
Stay ahead of emerging data security and cryptography threats, continuously scanning the external environment for new risks and regulatory drivers.
Act as escalation point for data protection incidents, providing expert advice on containment, investigation, and lessons learned.
Manage relationships with specialist vendors, consultancies, and technology partners, ensuring solutions deliver value and meet security expectations.
Performance Objectives

Deliver a coherent organisational strategy for data protection and DLP, with clear controls, governance structures, and reporting mechanisms.
Reduce data‑exfiltration and insider‑risk exposures, supported by quantifiable improvements in control effectiveness and risk visibility.
Produce a credible, risk‑aligned post‑quantum cryptography roadmap, addressing future‑proofing, migration planning, and regulatory readiness.
Skills and Experience Specification
Essential

Extensive leadership experience in data security, information security, or cybersecurity, ideally within large or complex organisations.
Deep technical knowledge of DLP tooling, data classification models, encryption technologies, and secure data lifecycle controls.
Strong grounding in cryptographic fundamentals, key management schemes, and secure system design.
Demonstrable experience deploying enterprise-grade DLP solutions across hybrid cloud, on‑premises, and endpoint ecosystems.
Ability to convert complex technical risks into clear strategic insights for senior executives and board‑level stakeholders.
Proven capability in cross-functional collaboration, engaging effectively with technology, business, risk, and compliance teams.
Professional security certifications such as CISSP, CISM, CCSP, or cryptography‑specific accreditations.
Awareness of evolving cryptographic and security guidance, including NIST post‑quantum cryptography standards.
Desirable

Hands‑on experience with quantum‑safe cryptography, cryptographic agility programmes, or emerging quantum‑resilient security solutions.
Background in highly regulated sectors such as financial services, insurance, or healthcare.
Experience leading data security incident response, breach investigations, or complex data‑related forensics.

Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)

Related Jobs

View all jobs

The Head of Data and Information Security

Head of Data Compliance

Head of Data Compliance

Head of ICT

Information Assurance Team Manager

Compliance Coordinator

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

What Hiring Managers Look for First in Cyber Security Job Applications (UK Guide)

If you want to stand out in the highly competitive world of cyber security job applications, you need to understand what hiring managers look for before they even finish reading a CV. Cyber security hiring managers scan applications quickly and with specific priorities in mind. They assess not just your technical ability, but your judgement, professionalism, clarity, risk awareness and evidence of impact. This guide explains what hiring managers look for first in cyber security applications across roles like Security Analyst, Security Engineer, Penetration Tester, Incident Responder, Security Architect, Governance Risk and Compliance specialists and Cloud Security positions. Use this as a practical, step-by-step checklist to sharpen your CV, LinkedIn profile, cover letter and portfolio before you apply on www.cybersecurityjobs.tech .

The Skills Gap in Cyber Security Jobs: What Universities Aren’t Teaching

Cyber security has become one of the most critical disciplines in the modern economy. From protecting financial systems and healthcare data to securing national infrastructure, cloud platforms and supply chains, cyber security professionals now sit at the frontline of digital trust. Demand for cyber security talent in the UK has surged. Job vacancies remain high, salaries continue to rise, and organisations across every sector report difficulty hiring skilled professionals. Yet despite this demand, many graduates struggle to break into cyber security roles and employers consistently report that candidates are not job-ready. The problem is not intelligence, ambition or academic effort. It is a persistent and widening skills gap between university education and real-world cyber security work. This article explores that gap in depth: what universities teach well, what they routinely miss, why the gap exists, what employers actually want, and how jobseekers can bridge the divide to build sustainable careers in cyber security.

Cyber Security Jobs for Career Switchers in Their 30s, 40s & 50s (UK Reality Check)

If you’re thinking about switching into cyber security in your 30s, 40s or 50s, you’re in good company. Across the UK, organisations of all sizes are hiring people from diverse backgrounds to protect systems, data & customers. But with hype around “hackers” & quick-win courses, it’s hard to separate reality from fiction. This guide gives you a UK reality check: which roles genuinely exist, what employers actually want, how training really works, what to expect on salary & progression & whether age matters. Whether you come from finance, project management, operations, law, HR or customer service, there is a credible route into cyber security if you approach it strategically.