- Company Name
- Impellam Group
- Job Title
- Director of Information Security & Privacy
- Job Description
-
Job title: Director of Information Security & Privacy
Role Summary: Lead the global Information Security and Privacy function as the Chief Data Protection Officer. Own strategic direction, regulatory compliance, and day‑to‑day operations, ensuring protection of digital assets and alignment with corporate objectives.
Expactations:
- Deliver end‑to‑end security and privacy leadership across the enterprise.
- Maintain culture of Data Privacy by Design and embed security awareness throughout the organization.
- Drive continuous improvement, audit readiness, and achievement of global certifications.
- Build and nurture high‑performing, inclusive teams and maintain strong stakeholder relationships.
Key Responsibilities:
- Act as Group‑wide DPO; develop, maintain, and enhance control frameworks (ISO 27002, SOC 2, NIST, CIS, etc.).
- Lead cyber‑security strategy (2–3 year roadmap) and operational security initiatives.
- Oversee privacy legislation compliance (GDPR, CCPA, NIS 2, Cyber Essentials, regional laws).
- Conduct performance reviews, coaching, and succession planning for the Cyber Security & Privacy team.
- Support sales and bids with security a‑grade proposals and presentations.
- Manage client audits, vendor security assessments, and third‑party risk programs.
- Coordinate with Governance, Legal, and IT operations to align policy, controls, and incident response.
- Liaise with internal and external auditors; design controls to meet global security certifications.
- Champion an inclusive, transparent, and innovative security culture.
Required Skills:
- Proven stakeholder management in complex, global environments.
- Deep knowledge of ISO 27001/27002, SOC 2, NIST, CIS Controls, ITIL, COBIT, TOGAF.
- Expertise in privacy laws (GDPR, CCPA) and regional standards.
- Strong IT operations acumen; experience implementing security frameworks.
- Leadership: team building, performance management, inclusive culture development.
- Excellent communication, negotiation, and presentation skills.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Information Security, Law, or related field (Master’s preferred).
- Relevant certifications: ISO 27001 Lead Implementer/Lead Auditor, CISSP, CISM, CIPP/E (or equivalent).