Interim Chief Information Security Officer (CISO) - Contract
London/Hybrid - Insurance
Outside IR35
Our client, a well-established player in the insurance sector, is looking for an experienced, immediately available Interim CISO to take the reins of their cyber security function during a pivotal period of security uplift and risk maturity.
This is a strong opportunity for a seasoned security leader who's comfortable operating in complex, heavily regulated, data-rich environments. Background gained Financial Services or comparable regulated sectors would be an advantage.
The successful candidate will own and elevate the organisation's cyber security capability across operational security, governance, risk, assurance, strategy and stakeholder engagement. The business runs a managed SOC model, so you'll be expected to get maximum value from existing security operations while driving meaningful strategic improvement across the wider function.
Key Responsibilities
- Provide executive-level leadership across the information and cyber security function.
- Shape and deliver a pragmatic, business-aligned cyber security strategy.
- Own cyber governance, risk management and security assurance end to end.
- Manage operational security capability, including oversight of a third-party SOC and associated security partners.
- Build and maintain robust security policies, standards and control frameworks.
- Present security reporting and risk positions to Exec, Board, Audit & Risk Committees and key stakeholders.
- Lead incident readiness, response oversight and operational resilience planning.
- Push cyber maturity forward across people, process and technology.
- Run security risk assessments and drive remediation programmes to closure.
- Ensure alignment with relevant regulatory, legal and governance obligations (FCA/PRA, operational resilience, data protection and sector-specific expectations).
- Advise on emerging threats, vulnerabilities and the firm's overall cyber risk exposure.
- Partner with technology, data protection, risk and business leaders to embed security across the organisation.
What We're Looking For
- Prior experience as a CISO, Interim CISO, Head of Cyber Security, Director of Information Security or equivalent senior role.
- A track record of leading enterprise-wide cyber security programmes.
- Strong grounding across:
- Operational Security
- Security Governance
- Cyber Risk Management
- Cyber Assurance
- Security Strategy
- Third-Party/Supply Chain Security
- Incident Response & Cyber Resilience
- Experience overseeing or working closely with managed SOC services.
- Excellent stakeholder management, with the ability to flex between technical and non-technical audiences.
- Proven ability to influence at executive and board level.
- Experience within complex, regulated environments - insurance or wider financial services ideal.