Head of Cyber-Security

Division: CFO Office

Location: United Kingdom, London

Employment Type: Permanent

Salary: competitive

Closing Date: 31 May 2026

Head of Cyber-Security

Team and role overview

The Cybersecurity Team protects BII’s technology, people, and processes from cyber-attacks. With top-tier tools and a leading Managed Security Service Provider, the team maintains the confidentiality, availability, and integrity of BII’s assets and data, supporting operations across markets. As a core part of the security function, the team is crucial in defending against evolving cyber threats. Given it’s role the team is highly visible to the senior leadership of the organisation.

Purpose

The Head of Cyber Security provides operational leadership, governance and accountability for BII’s cybersecurity capability. The role manages a team of cybersecurity professionals responsible for protecting and defending BII from Cyber-attacks, whilst similarly managing identity as a security enabler. The role holder will own core and emerging cyber risk domains—spanning Cyber security operationsidentity and AI—ensuring risks are identified early, governed effectively and managed within appetite. They will strengthen organisational resilience through incident readiness and response. The role also acts as Bronze Incident Manager for cybersecurity incidents.

Role Background

BII’s technology and supplier landscape is evolving, increasing cyber risk. This role provides clear operational ownership of cyber defence, risk governance and incident readiness, embedding security into change and decision-making.

What Success Looks Like

Cyber risks are detected early, managed appropriately, and reported to senior leadership. Controls are proven effective through monitoring, vulnerability management, and measurable resilience improvements. Incidents are handled with rehearsed responses and applied lessons learned.

How the Role Fits into the Organisation

Reporting to the Head of Security, the Head of Cyber Security leads day-to-day cybersecurity and works closely with Technology, senior stakeholders and key suppliers to ensure that the Cybersecurity of BII is maintained and endures. The role turns cyber risk into prioritised actions and provides clear input to senior leadership forums to protect services, enable change and strengthen resilience.

Responsibilities

  • Define and implement Cybersecurity strategy for BII, in order to keep BII safe.
  • Lead and manage the cybersecurity team by setting direction, priorities, performance standards and development plans.
  • Deputise for the Head of Security when required by representing Security in senior forums and making decisions within delegated authority.
  • Lead cybersecurity operations, including monitoring, vulnerability management, readiness and control health reporting.
  • Act as Bronze Incident Manager for cyber incidents by coordinating response and escalating to Silver/Gold when required.
  • Manage cyber risk within agreed appetite by assessing, treating and reporting risks with clear evidence and metrics.
  • Set cybersecurity governance for key domains, including Identity, third-party security, AI risk and data sovereignty.
  • Translate cyber risk into prioritised actions and report clearly to OpCo/ExCo/Audit and other forums.
  • Manage the outsourced Managed Security service provider (MSSP) and specialist suppliers by setting expectations, reviewing SLAs/KPIs and driving remediation.
  • Embed security into change by defining requirements and validating controls for patching, configuration and new services.
  • Maintain cyber playbooks, runbooks and standards to improve consistency and reduce key-person dependency.
  • Define and oversee cyber security training awareness across BII. 

The candidate

The successful candidate brings a strong track record in senior cybersecurity roles, leading others to deliver effective security operations, incident management and risk governance in complex environments. The background includes working with outsourced security providers, influencing technology and business stakeholders, and embedding practical security controls into day-to-day operations and change. The ideal candidate has a technical background and can translate complex topics into clear, business‑focused discussions.

Essential skills:

  • Proven people leadership and the credibility to represent Security in senior forums and deputise for the Head of Security.
  • Ability to set security standards and governance, and to present risk and control status clearly to senior stakeholders.
  • Strong communication skills, with the ability to articulate complex technical matter to non-technical and senior audiences.
  • Significant experience leading cybersecurity operations, including detection/monitoring and vulnerability management.
  • Experience managing cyber incidents end-to-end, including communications, decision logs and lessons learned.
  • Strong knowledge of current threats, identity security and third‑party risk.
  • Experience managing MSSPs and specialist suppliers through governance and SLAs/KPIs.
  • Broad technical understanding across cloud, endpoints, networks and logging sufficient to challenge and guide technical teams.
  • Demonstrable understanding of emerging AI‑driven threats, their implications for cyber security and their mitigations.
  • A relevant cybersecurity qualification and/or recognised certification (e.g., CISSP, CISM, SANS) with ongoing professional development

Desirable criteria

  • Experience with cloud security controls and monitoring (e.g., Microsoft 365/Azure).
  • Experience with SIEM/SOAR, detection engineering or incident automation.
  • Experience implementing IAM tooling and access governance (e.g., PAM, IGA).
  • Experience commissioning security testing and remediation programmes (e.g., pen tests, scanning).
  • Experience delivering security awareness and incident exercising programmes.
  • Working knowledge of assurance frameworks and resilience expectations (e.g., ISO 27001, SOC 2, NIST CSF.

Candidates should be strongly motivated by BII’s development mission and ideally demonstrate some commitment to development or social goals through previous executive or non-executive activity.

Our cultural values

We look for team members who aspire, as we do, to work at our best and to be:

  • Impact-led, commercially rigorous
  • Tenacious in the face of challenges
  • Collaborative and caring

British International Investment is committed to diversity and inclusion and welcomes all applicants regardless of age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race, religion or belief, sex, sexual orientation or educational background. 

Please provide a cover letter with your application

Salary: Competitive

 

Apply now