Virtual Chief Information Security Officer

Palo Alto Networks Logo

Palo Alto Networks

πŸ“Remote - United Kingdom

Summary

Join our leading consultancy as a dynamic and visionary vCISO to champion and operationalize cybersecurity best practices for a key public sector client. This crucial role involves acting as an account CISO, engaging with various client stakeholders, and delivering security services as part of a large-scale transformation program. You will identify and develop additional opportunities within the client organization, managing and reducing operational security risks. Success requires exceptional relationship management skills and the ability to drive adoption of recommended security solutions. The vCISO will be the primary point of contact for all client cybersecurity matters, requiring a broad understanding of security control implementation. This position is key in managing and reducing operational security risks for our public sector clients.

Requirements

  • Proven experience as an in-house CISO, or as vCISO within a consulting or systems integrator organisation
  • 10+ years of experience in cybersecurity, with expertise in areas like email security, cloud security, incident response, application security, vulnerability management, network security, cloud security, security operations, physical security, and supplier risk management
  • Strong experience in implementing and operating security controls in complex corporate environments
  • Demonstrated ability to engage with C-level executives and deliver impactful presentations
  • UK public sector experience, preferably within Emergency Services
  • Deep understanding of UK public sector security policies, compliance/assurance requirements, and audit practices
  • Understanding of industry-recognised cybersecurity frameworks (NIST, ISO 27001, CIS), global privacy regulations, and emerging threats
  • Current holder of (or able to be cleared to) SC and ideally DV security clearance
  • Experience of working in multi-provider, multi-year programmes
  • Proven track record of building and implementing account growth strategies, both in terms of security maturity and business development
  • Exceptional communication (written/verbal), presentation, and interpersonal skills, including the ability to communicate technical concepts to diverse audiences

Responsibilities

  • Serve as a trusted security advisor to client stakeholders, including CISOs, security teams, IT management, and executive leadership
  • Work with different delivery partners across a complex product and service ecosystem to pragmatically manage risk and drive successful outcomes
  • Develop and own the programme delivery and security services operational risk register
  • Develop deep, trusted relationships across the client organization, fostering open communication and collaboration
  • Provide strategic guidance and mentorship to client security teams, empowering them to effectively manage security risks
  • Present security recommendations and findings to various client audiences, tailoring communication to the specific group
  • Represent our consultancy on client calls and escalations, offering expert security advice and guidance
  • Champion security best practices within the client organization and drive the adoption of recommended solutions
  • Maintain an up-to-date understanding of UK government security policies
  • Stay abreast of industry best practices, emerging threats, and regulatory changes to provide cutting-edge guidance to clients
  • Share relevant industry insights and best practices with the client's security team to foster continuous improvement
  • Support executive engagement / peer relationships across the UK Public Sector and international peers
  • Conduct cybersecurity risk assessments, vulnerability analyses, and maturity assessments for clients
  • Develop and implement client-specific cybersecurity roadmaps, strategies, policies, and procedures
  • Provide expert advice on security architecture, incident response, disaster recovery, and business continuity planning
  • Oversee and guide client security teams in implementing and managing security controls
  • Assist clients with compliance requirements related to various regulations (GDPR, CCPA, HIPAA, PCI DSS, etc.) and standards (e.g., ISO 27001, SOC 2)
  • Manage security risk committees to support client cyber risk management practices
  • Track and manage remediation of security audit and compliance findings for clients
  • Review security metrics and lead remediation programs within the client's environment
  • Lead or sponsor client security initiatives
  • Ensure necessary security controls are in place in conjunction with client data privacy initiatives

Preferred Qualifications

  • Advanced degree in Cybersecurity, Business Administration, or a related field
  • Professional certifications such as CISSP, CISM, CCISO, or GIAC
  • Experience with ISO 27001, Cyber Essentials+, and other relevant compliance standards
  • Published thought leadership and public speaking experience at major industry events

Benefits

  • FLEXBenefits wellbeing spending account with over 1,000 eligible items selected by employees
  • Mental and financial health resources
  • Personalized learning opportunities

Share this job:

Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.