Head of Security
Job Description
Location: Swindon/London | Type: Full‑time, Senior Leadership Role
Role Overview\nAs the Head of Information Security, you will be a senior leader responsible for defining, implementing, and maintaining PayTech’s information security strategy. You will protect the confidentiality, integrity, and availability of our information assets, intellectual property, and customer data, ensuring strict compliance with regulatory frameworks including FCA, DORA, PCI DSS, and Edenred group security requirements.
Key Responsibilities\n- \n
- Lead the PayTech Information Security function with alignment to Edenred’s wider cyber risk management strategy. \n
- Develop and enhance security policies, standards, and procedures across the organisation. \n
- Manage the information security risk program, maintaining a comprehensive risk register. \n
- Oversee AI/ML security risk management, including the development of policies for generative AI technologies. \n
- Collaborate with Financial Crime and Anti‑Fraud teams to mitigate cyber risks related to financial crime. \n
- Manage third‑party security risk due diligence programs. \n
- Lead and maintain PCI DSS and PCI PIN compliance and engagement with Qualified Security Assessors (QSAs). \n
- Drive cyber awareness programs and phishing simulations to embed a security‑aware culture. \n
- Manage security incident response planning and coordinate with Security Operations Centre (SOC). \n
- Report regularly to PayTech Executive Leadership and Edenred Group CISO on security program status and risks. \n
- Lead a team of approximately 6 security professionals. \n
Solid experience in senior information security leadership roles. Proven hands‑on experience managing PCI DSS and other compliance programs. Experience in complex corporate structures with multi‑stakeholder compliance demands. Strong background in developing security governance frameworks and policies. Experience with financial services, FinTech, or payments sector preferred. Familiarity working with financial crime, fraud, and AML functions. Experience managing risks associated with emerging technologies like AI/ML.
Desired Certifications\n- \n
- CISSP (Certified Information Systems Security Professional) – highly desired \n
- CISM, PCIP, ISA, or QSA qualifications are advantageous \n
- \n
- Strong leadership and mentoring capabilities. \n
- Deep technical knowledge in network security, cryptography, IAM, and cloud security (AWS, Azure, GCP). \n
- Excellent communication skills, able to convey complex security topics to non‑technical stakeholders. \n
- Pragmatic, calm, and resilient under pressure during incident management. \n
Be part of a dynamic and strategic security leadership team within a pioneering FinTech environment. Influence the protection of critical technologies and data, contribute to innovative AI risk frameworks, and help shape the future of PayTech’s secure growth.
What you will get\n- \n
- 25 days annual leave plus Bank Holidays \n
- Hybrid working environment (min. 3 days per week in the office) \n
- Pension Scheme – employer 6% with minimum employee contribution 3% \n
- Discretionary bonus scheme based on company and personal performance \n
- Medical and international travel cover (leisure and action sports) \n
- Life insurance (4x salary) \n
- Wellbeing Employee Assistance Program (extended access to family members) \n
- Monthly gym allowance \n
- Holiday trading scheme \n
- Season ticket loan \n
- Cycle to Work scheme \n
- Employee discount shopping platform \n
- Employee referral bonus scheme \n
- Digital learning platform \n
- Complimentary fruit and other ‘in office’ snacks & refreshments \n
- Volunteering programme \n
- Social events \n
Nous nous engageons à prévenir toute forme de discrimination et à proposer à tous nos candidats des opportunités égales indépendamment de leur genre et expression de genre, handicap, origine, croyance religieuse et orientation sexuelle ou tout autre critère.
\nWe will not discriminate against any applicant or employee based on age, race, colour, creed, religion, sex, sexual orientation, gender, gender identity or expression, national origin, citizenship, marital status or civil partnership/union status, disability, pregnancy, genetic information, or any other basis prohibited by applicable country or local laws.
\n