Chief Information Security Officer
Career Integrity & Compliance Audit Report
This vacancy has been independently reviewed by the OppaJob Transatlantic Career Intelligence Desk to confirm authentic direct employer recruiting, verify compensation transparency, and eliminate applicant processing fees.
Transatlantic Cost of Living & Purchasing Power Benchmark
Compare US ($) vs UK (Β£) Salary & Net Take-Home Pay
Calculate tax deductions, living costs, and purchasing power parity across US & UK metros.
Position Overview & Specifications
Job Title Chief Information Security
Officer (CISO)
Reports to Chief Technology Officer
Operating Group Information Security Location Isle of Man, Guernsey, Ireland
(Dublin / Navan), UK (Southampton),
home based
Job Purpose
The Chief Information Security Officer (CISO) is responsible for the long-term strategic management of
Utmostβs information security technology and governance according to the Information Security
Management System (ISMS) framework. The CISO is expected to define, develop, and maintain a
business-aligned Information and Cyber Security strategy and operating model for the ongoing
protection of computer networks and information.
You will be a strategic and lateral thinker with exceptional leadership credentials and a sophisticated
approach to stakeholder and supplier management (ideally within the finance sector).
The role requires:
a good overall understanding of the business and the jurisdictions in which we operate; the applicable
legal and regulatory obligations (in particular data protection requirements); a thorough understanding
of the technology underpinning Utmostβs IT systems; and a broad, up-to-date knowledge of information
security frameworks, vulnerability management, incident management and response, secure
development techniques and approaches, Cyber Security engineering and operations, and
management and governance of Cyber risk and Cyber Security.
Key Responsibilities include: ο·
Information Security Strategic leadership ο·
Governance & standard development and monitoring ο·
Security Incident Management ο·
Cyber Risk management ο·
Driving Information Security awareness
Main tasks and responsibilities Key Performance Indicators
Security incident Management ο·
Ownership and management of the Information Security
Incident Management Process. Manage incidents and
their follow-up actions, agreeing the required actions and
ensuring that all required actions are carried out as
required. ο·
Manage the documentation of policies, procedures,
security guidelines and runbooks to assist in the timely
resolution of Security Incidents. ο·
Assist with development of relevant BCP plans for IT and
business from a security perspective. ο·
Ensure that the business
process documentation
created as part of the ISMS
creation is maintained as and
when processes change. ο·
Security Incidents managed
and closed out as required ο·
Escalation of incidents within
agreed timeframes ο·
Adequate and robust testing
of BCP plans ο·
Ensure all new
implementations are included
in BCP plans/solution
Cyber Risk ο·
Oversight, management, and reporting on all risks
pertaining to information security, including all forms of
cyber risk and all risks relating to the protection of personal
data throughout the businesses in all locations. ο·
Developing and monitoring Key Risk Indicators (KRI) and
Key Performance Indicators (KPI), relating to the information
security controls of the businesses. ο·
Assist in the ongoing assessment of risk to the security of
information, assets, and personnel. ο·
Assist in management of cyber risk including risk reviews and
mitigation planning. ο·
Risk assessments carried out to
standard, to agreed schedule,
and as required. ο·
Ensure complete and
accurate risk register in place
and monitored
Governance / Standards ο·
Assist with the initial certification and ongoing adoption of
NIST framework. ο·
Develop and maintain information security documentation
to agreed standards. ο·
Facilitation of external information security audits,
management reviews and internal information security
audits. ο·
Define and manage the monitoring of key measures of ISMS
performance. ο·
NIST alignment and
accreditation ο·
Documentation that meets
standards and drives
processes. ο·
Audits progressed smoothly
and with least disruption to the
business as possible. ο·
All agreed security KPIs
(Including security controls)
monitored and reported as
required.
Information Security Strategic leadership ο·
Drive and coordinate the management of security through
the sharing of ideas between key security players; the
monitoring of threats and subsequent identification of
opportunities for improvement; and the on-going
monitoring of security activity (e.g., penetration testing
actions) to meet targets; and drive and manage the
development of information security to ensure approaches,
techniques and tools continue to meet needs. ο·
Ensure that the team become an active part of projects at
an early stage to ensure that all projects take information
security into account; and to carry out - or oversee -
information security risk assessments and ensure that the
results are acted upon. ο·
Provide training, coaching and internal consultancy to the
business at all levels in relation to the Information Security
Management System, the NIST framework and a wide
variety of IT controls and information security controls, and
in respect of new and evolving IT standards, cyber risks, and
information security issues. ο·
Authorise the release of system changes into production
environments according to agreed parameters and
processes. ο·
Provide information security guidance to IT team as part of
project and software development lifecycles. ο·
Perform regular internal and external security audits and
testing including penetration testing. ο·
Sharing of security ideas
actively promoted. ο·
Audit actions (inc. penetration
tests) managed and followed-
up in a timely fashion. ο·
Applicable threats identified
and actioned within agreed
timescales. ο·
Ongoing measurable
improvements to approaches
implemented to ensure
information security is
maintained long term. ο·
Guidance in security risk
assessments provided and
carried out as required. ο·
Corrective changes
documented and agreed
based on risk assessments and
carried out to plan. ο·
Change releases checked
and authorised as required
and in a timely manner. ο·
Project Security Risk
Assessments carried out as
required.
Information Security Awareness ο·
Assist in the development and delivery of training,
education, and initiatives to promote security awareness
throughout the businesses. ο·
Broad and effective staff
security awareness delivered
through various media and
judged to be effective.
Cyber Risk Management ο·
Preparation, management, and reporting of the
Information Security Risk Assessment in conjunction with the
overall Business Operational Risk Assessment. ο·
Reporting on Key Risk Indicators and Key Performance
Indicators. ο·
Provide IT and information security control risk input into
projects from inception. ο· ο·
Contributing to the creation
of a culture of risk awareness
and the highest standards of
corporate governance.
Preparation, management,
and reporting of the
Information Security Risk
Assessment in conjunction
with the overall Business
Operational Risk Assessment. ο·
Assess operational risks
associated with day-to-day
activities and implement risk
mitigation controls as
necessary. ο·
Ensure operational risk events
are reported on a timely
basis and risk event actions
are completed within
agreed timelines.
Customer Management ο· Maintain effective relations
with all key stakeholders
across company. ο·
Commits to exceeding expectations and needs to
internal/external customers, possesses βcustomer firstβ mind
set. ο·
Ensures that work is accurate and well presented, that
customer care is given priority above all else and that effort
is made to exceed the minimum standard required in all
areas. ο·
Shows concern for detail no matter how small. ο·
Takes a pride in doing a job well. ο· ο·
Quality and timeliness of
communication updates to
all relevant parties.
Appropriate service is
delivered at all times, across
all business lines and
feedback is sought from key
stakeholders to fully assess
the service quality.
Culture ο·
Is a role model in
demonstrating the
behaviours and culture
across the organization. ο·
Represents company
strategy and commercial
decisions in a proactive and
positive manner. ο·
Leads by example, to
motivate and assist with
managing change across
the organization
Knowledge, Skills, and Behaviours
Essential or Desirable
Knowledge ο· ο· ο· ο·
, Experience or qualifications
At least 8 yearsβ experience in Information Security, and
experience in people and IT management.
Experience in security tools, technology, and
architecture.
Management experience that encompasses information systems
or information security experience.
Relevant certification is preferred (ISO27001 or NIST lead auditor,
CISSP, CISM, CRISC, CCRO) along with following experience: ο§
NIST implementation ο§
Internal audit knowledge ο§
Risk analysis β systems/projects/changes ο§
Security technical knowledge / skills ο§
Information Systems such as Active
Directory, VMware, Firewalls, Network,
Storage, QRadar/SIEM ο§
IT hardware, software, process appreciation
Essential
Essential
Essential
Preferred
Skills ο· ο· ο· ο·
Process mapping and data analysis skills.
Analytical skills β Interprets quantitative and qualitative
information to achieve objective and produces effective
solutions to problems.
Ability to work within tight deadlines and deliver solutions within
defined time periods.
Experience working in a complex operational environment.
Essential
Essential
Essential
Essential
Effective verbal and written communication skills and strong
interpersonal skills, good at reporting.
Behaviours ο·
Cooperative, flexible, adaptable, and persistent. ο·
Diligence - Being careful about detail and thorough in completing
work ο·
Integrity - Being honest and ethical ο·
Must be willing to travel occasionally between offices in all Utmost
territories where required (infrequent)
Essential
Essential
Essential
If you would like to apply for this role, please send your cover letter and CV to
employment@utmostwealth.com
Utmost Group is an equal opportunities employer
Candidate Selection & Onboarding Process
Application & Resume Screening
Submit your tailored CV/Resume directly to the talent acquisition portal.
Technical & Competency Interviews
Virtual interviews with the hiring manager and multidisciplinary team.
Formal Offer & Benefits Negotiation
Written agreement outlining compensation, equity, retirement vesting, and relocation allowances.
Onboarding & Corporate Integration
Equipment provisioning, team orientation, and commencement of duties.
United Kingdom Right to Work & Skilled Worker Visa Guide
Employment in the United Kingdom requires legal Right to Work verified under the Home Office Points-Based Immigration System:
Sponsoring employers must hold an active Home Office A-rated Sponsor License and assign a valid Certificate of Sponsorship (CoS). Role must meet the general minimum salary threshold (Β£38,700) or occupation going rate.
Continuous employment under Skilled Worker status establishes eligibility for Indefinite Leave to Remain (ILR) after 5 continuous years, leading to British Citizenship.
Candidate Preparation Blueprint: Insurance Carriers
Based on transatlantic hiring benchmarks for Chief Information Security Officer roles across UTMOST WEALTH SOLUTIONS's corporate sector, successful applicants typically excel across three core dimensions:
Demonstrated portfolio evidence, architecture/system design case studies, or validated professional certifications directly applicable to Insurance Carriers.
STAR method competency responses highlighting cross-functional leadership, conflict resolution, and delivering measurable enterprise ROI under tight timelines.
Total compensation expectation aligned within the benchmarked Salary Disclosed on Application bracket, including retirement vesting and health parity.
Explore Related Opportunities (United Kingdom)
Other high-paying verified positions matching your industry profile.
Principal Data Analytics Specialist
Senior Clinical Diagnostic Radiographer
Senior Site Reliability & Kubernetes Engineer (SRE)
Consultant Acute Care Physician (General Medicine)
Head of Cyber Security & Zero Trust Architecture
Apply for this Position
Receive high-paying Insurance Carriers openings directly to your inbox.