Duco

Duco

London

Head of Information Security

Full-Time£60,000 - 100,000 per year前天United Kingdom
IT

Job Description

Salary: £60,000 - 100,000 per year

Requirements:
  • 8+ years of progressive experience in information security, including at least 3 years in a senior or leadership role
  • Hands-on ownership of ISO 27001 and SOC 1/SOC 2 programmes
  • Demonstrated experience managing security incidents end-to-end, including client and regulatory communications
  • Strong understanding of cloud security, particularly AWS, including IAM, logging, and observability infrastructure
  • Experience operating in a B2B SaaS or fintech environment, with exposure to enterprise client security requirements
  • Track record of building and managing third-party risk management programmes at scale
  • Excellent stakeholder management skills, including the ability to present to the board and client security teams
  • Ability to make pragmatic decisions based on company culture and risk appetite
  • Strong written communication skills, with the ability to translate complex security topics into plain language for non-technical audiences
  • Experience leading and developing a small, high-performing team
  • Familiarity with AI governance and the security implications of agentic AI systems
  • Beneficial: experience with DLP, SIEM, or SOC build-outs
  • Beneficial: relevant certifications such as CISSP, CISM, or ISO 27001 Lead Implementer
  • Beneficial: experience in capital markets, asset management, or securities services
Responsibilities:
  • Own our end-to-end security posture, risk and compliance programme, and IT Operations function
  • Define security architecture standards and lead threat modelling across the organisation
  • Establish and maintain long-term security architecture aligned to business strategy and regulatory requirements
  • Guide enterprise technology decisions, including cloud strategy and zero trust adoption
  • Oversee penetration testing, DLP, and advanced threat detection programmes
  • Own our vulnerability management programme
  • Implement enterprise frameworks including IAM, SIEM, and data classification
  • Anticipate emerging threats, leverage AI/ML for predictive security, and set the technology vision
  • Lead our Security Incident Response Programme
  • Define and own our GRC programme, including the ISMS, policy framework, risk registers, and audit readiness
  • Implement and maintain compliance with ISO 27001, SOC 1, SOC 2, NIST CSF, GDPR, and relevant financial services regulations
  • Implement appropriate controls and adapt as the threat and regulatory environment shifts
  • Own execution of GRC strategy across the organisation and ensure frameworks are scalable and adaptable
  • Own our Third Party Risk Management programme, including vendor assessments and ongoing oversight
  • Define and own our IT Operations programme, setting strategy and standards for the function
  • Ensure operational excellence across infrastructure, tooling, and end-user support
  • Lead, mentor, and develop a high-performing team across InfoSec, GRC, and IT Ops
  • Build strategic relationships with clients, regulators, and internal stakeholders
  • Engage directly with CISOs and security teams of global financial institutions to assure them of our risk management and data privacy practices
  • Work closely with Client Success and Pre-Sales teams on enterprise client assurance
Technologies:
  • Agentic AI
  • AI
  • AWS
  • Cloud
  • IAM
  • Support
  • Security

More:

We are Duco, a London-headquartered company with offices in New York, Wroclaw, Antwerp, and Singapore. We empower financial services firms to transform operations by automating manual work and elevating humans from task workers to decision makers through our agentic Operations platform. Our platform supports end-to-end reconciliation, data trust, and automation across any source, format, or structure, and is used by more than 10,000 users across 30+ countries to process billions of data records every week. We work with global banks, investment managers, exchanges, and insurance firms including CIBC Mellon, ING, and Man Group. This is a VP-level role with company-wide scope in a fast-moving team of approximately 200 employees, where information security, governance, and IT operations are central to our growth.

last updated 34 week of 2026

Interested in this role?

Submit your application now

How to Apply

Ready to apply for this position? Here's what you need:

  • An updated resume highlighting relevant experience
  • A compelling cover letter (if required)
  • Portfolio or work samples (for relevant positions)

About Duco

Duco

Duco

London

IT

Skills & Technologies

GoRustScalaAWSAIUI

Inferred from job description

Salary Insight

£80,000

This role

£55,000

UK median

This salary is 45% above the UK median for UK tech roles55,000/yr).

Based on 2024–2025 UK technology sector benchmarks

Explore More UK Opportunities

Thousands of tech jobs across the United Kingdom