Chief Information Security Officer (CISO)
Testronic · United Kingdom
Skills in this posting
The posting
Testronic is a global leader in Quality Assurance and technology services for the games and entertainment industries. We work with some of the world's leading game developers and publishers, providing Functional QA, Compliance QA, Localization QA, Compatibility QA, and other specialized services.
With diverse teams across Europe, Asia, and North America, we foster an inclusive, collaborative culture built on four core values: We Care Deeply, Passion for Quality, Trust in Unity, and Pride in Ownership. Whether you're starting your career or looking for your next challenge, Testronic offers opportunities to learn, grow, and make a meaningful impact.
About the Role
We are looking for a Chief Information Security Officer (CISO) to lead Testronic ’s information and cyber security programme at a global level. The CISO will define and deliver the security strategy, oversee enterprise security risk and governance, lead the Information Security function, and provide senior leadership and Board-level advice on cyber security, resilience and compliance.
Responsibilities
Information Security Strategy
Develop and deliver Testronic ’s global information security strategy, aligned with business objectives, technology plans and risk appetite.
Translate security objectives into measurable programmes, capabilities and annual priorities.
Monitor the security landscape and adapt the strategy to emerging threats, technology and regulatory requirements.
Governance & Risk Management
Own the global information security governance framework, policies and risk management processes.
Ensure material security risks have clear ownership, treatment plans and appropriate escalation.
Oversee the Information Security Management System and promote security accountability across the organisation.
Board & Senior Leadership
Provide clear, regular reporting to the Board and senior leadership on cyber risk, security posture, incidents, compliance and resilience.
Advise executives on significant security risks and support informed business decisions.
Communicate complex security topics in clear business and financial terms.
Security & Incident Management
Act as the senior escalation point for significant information security incidents.
Lead or support executive-level response to major cyber incidents, working with IT, Legal, Privacy, Communications and business teams.
Ensure incident response exercises, lessons learned and remediation activities are effectively managed.
Security Programme & Assurance
Oversee security programmes covering corporate technology, cloud, applications, products and third parties.
Provide oversight of security architecture, vulnerabilities, penetration testing, control testing and independent assurance.
Monitor the effectiveness of internal and outsourced security services and ensure key security improvements are delivered.
Compliance & External Stakeholders
Oversee information security requirements arising from legislation, regulations, customer contracts and recognised standards.
Support ISO 27001 and other relevant certification and assurance programmes.
Represent Testronic in significant security matters involving clients, auditors, regulators, insurers and other external stakeholders.
Leadership & Business Partnership
Lead, develop and build a capable global Information Security function.
Work closely with IT, Legal, HR, Facilities, Commercial, QA and other departments to embed security into business and technology decisions.
Manage the security budget, strategic suppliers and major security investments.
Ensure security risks are considered in acquisitions, outsourcing and major organisational or technology changes.
Requirements
Significant senior-level experience in information and cyber security.
Experience developing and implementing an enterprise security strategy.
Experience advising Boards, executives or senior governance committees.
Strong experience in enterprise security risk management and governance.
Experience leading security programmes across complex technology environments.
Experience managing significant cyber security incidents or crisis situations.
Experience leading and developing multidisciplinary security teams.
Strong understanding of security governance, architecture, operations, assurance and operational resilience.
Knowledge of cloud, infrastructure, identity, application and product security.
Experience with security frameworks, ISO 27001 and third-party risk.
Strong stakeholder, programme, budget and supplier management skills.
Knowledge of relevant UK legal, regulatory and contractual requirements.
GOOD TO HAVE: CISSP, CISM, CCISO, ISO/IEC 27001 Lead Implementer/Lead Auditor, CRISC or equivalent qualifications.
Originally posted on Himalayas
The PivotHop read
- What a security engineer actually earnsmedian, seniority, by country
- What security engineers do insteadevery measured route out
- Penetration Tester → Security Engineer51% readiness
- All open security engineer rolesthe full board
Where these skills also reach
- 71 open penetration tester roles78% readiness from security engineer
- 279 open network engineer roles60% readiness from security engineer
- 522 open systems administrator roles52% readiness from security engineer
- 1642 open systems engineer roles51% readiness from security engineer
More security engineer roles
Cybersecurity Analyst at SalienseUnited States · Remote$70k–$75kTodayApply
Senior Infrastructure & Cybersecurity Engineer (UK) at A-GasUnited Kingdom · RemoteTodayApply
DevSecOps Security Engineer at MastercamUnited States · RemoteTodayApply- Security Engineer III , Vulnerability Management at Direct employerIndia - GurgaonTodayUnlock
- Information Security Engineer - Site Reliability at Direct employerMiddletown, RI, USTodayUnlock
Backfilled listing, refreshed with the nightly scrape; the employer has not claimed it yet. Are you the employer? Claim this listing and it can be featured to the candidates whose skills already reach it, first month free.