Head of Security (CISO)
Job Description
Location: Hybrid | Permanent
\n\nClearCourse is seeking an experienced Head of Security (CISO) to lead and evolve our group-wide security strategy across a diverse portfolio of 40+ software and payments businesses.
\n\nReporting to the Chief Technology & Transformation Officer, with a dotted line to the Board and Audit Committee, this is a pivotal executive leadership role responsible for security governance, operations, compliance, and risk management across a complex technology estate spanning payments, healthcare, and B2B SaaS.
\n\nWith ongoing M&A activity, active PCI-DSS obligations, and a rapidly evolving platform landscape, you'll play a critical role in protecting our customers, supporting business growth, and embedding security across the organisation.
\nWhat you'll do
\n\n- \n
- Define and lead the Group's security strategy, policies, and governance framework \n
- Provide Board-level reporting on security posture, risks, and compliance activities \n
- Oversee security operations, including threat detection, incident response, and remediation \n
- Act as the executive lead during security incidents and manage external stakeholder communications \n
- Own PCI-DSS compliance across ClearAccept and ClearDebit payment platforms \n
- Lead the Group's Governance, Risk and Compliance (GRC) function, including ISO 27001, Cyber Essentials, PCI-DSS, and data protection obligations \n
- Manage relationships with auditors, regulators, cyber insurers, and certification bodies \n
- Lead security assessments and integration activities for acquisitions, driving alignment to Group standards \n
- Partner with Platform Engineering teams to embed security practices into development lifecycles without impacting delivery velocity \n
- Lead and develop the GRC function to support a proactive and risk-aware security culture \n
Requirements
\n- \n
- Previous experience operating at CISO level within a multi-product or multi-entity organisation \n
- Hands-on experience leading PCI-DSS compliance programmes and QSA assessments \n
- Proven expertise building and managing enterprise-wide GRC frameworks and risk registers \n
- Experience assessing and integrating security functions following M&A activity \n
- Strong understanding of DevSecOps principles and embedding security into engineering practices \n
- Experience leading major security incidents, including external communications and stakeholder management \n
- Ability to influence at Board and executive leadership level \n
- Strong leadership skills with experience building and developing high-performing security teams \n
Benefits
\n- \n
- Competitive salary + benefits \n
- 25 days holiday + your birthday off \n
- Private medical insurance (Bupa) & health cash plan \n
- Life assurance & income protection \n
- Enhanced parental leave & family wellbeing support \n
- Perkbox discounts & perks \n
- Generous pension contributions \n
- Hybrid working model \n
This is a rare opportunity to shape and lead the security strategy of a fast-growing international software and payments group. You'll work at executive level, influence critical business decisions, and play a key role in safeguarding the future growth of the organisation. If you're passionate about security leadership and thrive in complex, evolving environments, we'd love to hear from you.
