Skip to main content
AfterDuty

Chief Information Security Officer

NTT DATA · London, Greater London

Type
Full-time
Posted
16 days ago

Overview

Your command experience in major incidents, multi-agency coordination, and risk-based decision-making directly supports the strategic security leadership and governance responsibilities. The discipline of managing compliance with PACE, RIPA, and CPIA translates into ensuring regulatory and contractual obligations are met. However, the role's deep technical cybersecurity requirements and senior client advisory expectations are a significant stretch for a typical policing background.

About this role

At NTT DATA, you have endless opportunities to think big, act bold and take ownership. As a $30+ billion business and technology services, AI and digital infrastructure leader, we co-innovate solutions with clients and partners globally for business and societal impact. Serving 75% of the Fortune Global 100, with experts in over 70 countries, we encourage experimentation and recognize great work. Proudly a Global Top Employer, NTT DATA is part of NTT Group, which invests over $3 billion annually in R&D. Make this the place where you belong, learn, and build your network. Make this the place where you grow.

Strategic Security Leadership & Client Partnership

Act as the senior security representative for the account.

Build trusted relationships with client security, technology, risk, compliance, audit and business stakeholders.

Serve as the primary point of contact for strategic security matters across the account.

Provide strategic security advice and guidance to client executives, account leadership and delivery teams.

Represent security interests within governance, operational, service review and transformation forums.

Influence senior stakeholders to support effective risk-based decision making.

Act as a trusted advisor on security, resilience, compliance and risk matters.

Act as an escalation point for significant security issues affecting the account.

Facilitate effective communication between business, operational and technical stakeholders.

Promote a positive security culture across the account and wider delivery organisation.

Governance, Risk, Assurance & Security Oversight

Own, maintain and continually improve the Account Security Management Plan and associated security governance arrangements.

Ensure the Security Management Plan remains aligned with client requirements, contractual obligations, organisational policies and industry good practice.

Establish and maintain effective security governance and reporting arrangements across the account.

Ensure security risks are identified, assessed, communicated and managed in accordance with business objectives and risk appetite.

Provide independent oversight and challenge of security controls, assurance activities and risk treatment plans.

Ensure security requirements are understood, embedded and effectively managed throughout service delivery activities.

Drive accountability for security outcomes across delivery, operational and support teams.

Provide oversight of security posture, control effectiveness, risks, issues and remediation activities.

Ensure security obligations, commitments and compliance requirements are met and evidenced.

Support internal audit, external audit and client assurance activities.

Challenge decisions, practices or activities that introduce unacceptable levels of security risk.

Ensure security considerations are embedded within service delivery, operational processes, change activities and service improvement initiatives.

Drive remediation of security risks, audit findings and control weaknesses through to completion.

Provide meaningful security reporting, assurance and management information to stakeholders.

Promote transparency, ownership and continual improvement across the account.

Security Architecture and Design Authority

Provide strategic security architecture oversight across the account, ensuring security requirements are reflected within technology strategy, solution design and service evolution.

Act as the security authority for the review and challenge of significant architectural, technology and service changes.

Ensure security-by-design principles are embedded throughout the service lifecycle and considered within all material design decisions.

Assess the impact of architectural decisions on security risk, operational resilience, compliance obligations and business objectives.

Provide independent security challenge to proposed solutions, identifying opportunities to improve security, resilience and risk management outcomes.

Work collaboratively with client architects, service architects and delivery teams to ensure security architecture principles are consistently applied.

Support transformation initiatives by providing strategic security guidance and architecture oversight.

Ensure security architecture considerations are integrated into service roadmaps and future-state planning.

Maintain awareness of emerging technologies, threats and industry practices to ensure security architecture remains effective, proportionate and aligned with business objectives.

Regulatory, Contractual and Compliance Oversight

Maintain a strong understanding of applicable regulatory requirements, industry standards and evolving security expectations relevant to the client environment.

Develop and maintain effective working relationships with client Risk, Compliance, Legal, Audit and Operational Resilience stakeholders.

Provide trusted advice and guidance on the interpretation and application of regulatory, contractual and security requirements.

Ensure regulatory, contractual and policy obligations are understood and appropriately reflected within security governance, assurance and service delivery activities.

Work collaboratively with stakeholders to support the achievement and maintenance of compliance objectives.

Support organisational readiness for internal audit, external audit, assurance reviews and regulatory engagement activities.

Assess the impact of changes in regulatory, legal and industry requirements on the account and advise on appropriate actions.

Promote a proactive approach to compliance, ensuring security controls, processes and governance arrangements continue to support regulatory expectations.

Provide oversight and challenge to ensure identified compliance risks, findings and remediation activities are effectively managed through to completion.

Support the development of a strong control environment through effective governance, assurance and continuous improvement activities.

Ensure security governance and assurance arrangements evolve in line with changes in regulation, business strategy, technology and risk.

Continuous Improvement

Drive continual improvement in security governance, assurance and risk management practices.

Ensure lessons identified from incidents, audits, assessments and reviews are translated into measurable improvement activities.

Promote adoption of security best practice across account teams.

Encourage innovation and effective use of security capabilities to improve security outcomes.

Support the ongoing development of security maturity, operational resilience and assurance effectiveness across the account.

Minimum 7 years' experience in a senior information security leadership, Security Director, CISO or virtual CISO role.

Proven experience providing strategic security leadership within large, complex and regulated organisations.

Experience acting as a trusted advisor to executive leadership, client security teams and senior business stakeholders.

Experience developing and leading security governance, risk management and assurance programmes.

Experience owning and maintaining Security Management Plans and associated governance and reporting frameworks.

Experience leading security assurance activities, managing audit engagements and driving remediation activities through to completion.

Significant experience in enterprise security architecture, security design assurance and security-by-design principles.

Experience reviewing and challenging technology, cloud, infrastructure and transformation initiatives from a security, resilience and risk perspective.

Experience operating within outsourced, managed service and multi-supplier delivery environments.

Proven ability to influence senior stakeholders and drive security outcomes without direct management authority.

Knowledge and Skills

Security governance, risk management and assurance, including the design and operation of effective governance and reporting frameworks.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background

  • Working to legislation & regulation

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Full-time

    Your experience managing operational risk and leading incident reviews translates directly into shaping security culture and resilience.

    Posted 2 days ago

  • Information Security Analyst

    Europa Worldwide Group · London

    Full-time

    £40,000 – £45,000Estimated

    Your experience managing evidence, compliance, and risk under ISO standards translates directly into this security assurance role.

    Posted 2 days ago

  • Cyber Security & Compliance Analyst

    Shivom Consultancy Ltd · London

    Full-time

    Your incident management, evidence handling, and risk assessment from policing transfer directly to this role.

    Posted 2 days ago

  • £570 a dayEstimated

    Your experience managing security incidents and coordinating multi-agency responses transfers directly to this governance role.

    Posted 2 days ago