Skip to content

General information

Posting ID
PSR1JP00104415
Type of employment
Contract
Organisation
HS2
Contract duration
6 Months
Location
Birmingham
Workplace Type
Hybrid

Description & Requirements

On behalf of HS2, we are looking for a Head of Information & Cyber Security Inside IR35 for a 6 months contract based Birmingham Hybrid


HS2 is Britain’s new high-speed railway that supports the government’s number one mission growth. When it’s fully operational, the line will connect London and Birmingham in just 49 minutes. This will create better journeys for passengers. The railway links our two biggest economic centres, connects people with jobs and is attracting major investment before services begin. It then extends north of Birmingham to Handsacre in Staffordshire. Here, HS2 trains will connect to the West Coast Main Line for the Northwest and Scotland.


HS2 provides benefits for everyone faster, more reliable journeys for passengers; better connections to markets and people for businesses; and investment in infrastructure and skills for local communities.


As a Head of Information & Cyber Security, your main responsibilities will be:


  • Lead the development and delivery of the organisation-wide Information & Cyber Security Strategy.
  • Provide executive leadership for all Information & Cyber Security activities, ensuring alignment with business objectives and risk appetite.
  • Act as the senior authority and subject matter expert for cyber security, information security and cyber risk.
  • Lead a multidisciplinary cyber security function covering:
    • Security Operations
    • Governance, Risk & Compliance (GRC)
    • Identity & Access Management (IAM)
    • Information Governance
    • Data Protection
    • Security Architecture
    • Incident Response
  • Own and continuously improve the Information Security Management System (ISMS).
  • Ensure compliance with relevant regulatory, contractual and industry security requirements.
  • Lead the response to major cyber security incidents, directing investigation, remediation and recovery activities.
  • Provide regular cyber risk reporting and strategic advice to Executive Leadership and Board stakeholders.
  • Manage and develop a team of cyber security professionals while overseeing outsourced security service providers.
  • Drive a culture of security awareness, resilience and continuous improvement across the organisation.
  • Manage significant security budgets, resources and third-party suppliers.


About You

We are looking for a proven cyber security leader with experience leading enterprise-wide security functions within complex, regulated environments.


Essential Experience

  • Experience leading a broad Information & Cyber Security function at Head of Cyber Security, Director, Deputy CISO or CISO level.
  • Demonstrable ownership of cyber security strategy, governance and risk management.
  • Experience leading cross-functional cyber security teams and managing security operations at scale.
  • Strong track record of executive and Board-level stakeholder engagement.
  • Experience leading and managing major cyber security incidents and remediation programmes.
  • Experience delivering and maturing Information Security Management Systems (ISMS).
  • Experience working with outsourced and managed security service providers.
  • Proven responsibility for cyber security budgets, suppliers and resources.


Technical Knowledge

  • Information Security Governance, Risk & Compliance frameworks.
  • ISO 27001 and Information Security Management Systems.
  • NCSC guidance and recognised cyber security frameworks.
  • Cyber risk management and audit remediation.
  • Security Operations and Incident Response.
  • Identity & Access Management.
  • Security Architecture and infrastructure security controls.
  • ITIL, Agile or other recognised IT service management methodologies.


Key Attributes

  • Strategic thinker with strong commercial and operational judgement.
  • Credible and influential leader capable of engaging at Executive and Board level.
  • Ability to translate complex cyber risks into clear business language.
  • Strong people leadership and stakeholder management skills.
  • Resilient decision-maker, particularly in high-pressure incident scenarios.



Please be aware that this role can only be worked within the UK and not Overseas.


In applying for this role, you acknowledge the following "this role falls in scope of the Off Payroll Working in the Public Sector legislation. Any rates of payment quoted will reflect the gross rate per day for the assignment and will be subject to appropriate taxes and statutory costs. As such the payment to the intermediary and your income resulting from this contract will be different".