Head of Information Security & Data Privacy
Protecting a business like ours is a big deal. With a heritage estate, modern digital platforms and a complex Group structure, Travis Perkins plc needs someone who can confidently own our information security and data privacy agenda across a very large and varied technology landscape. That is where this role comes in.
We are looking for a Head of Information Security & Data Privacy who can set strategy, inspire people, and turn complex cyber risks into clear, commercial decisions that help our businesses trade with confidence. You will partner with our brands, shaping how we protect customer, colleague and business data end to end.
In this role you will:
Work with the Director of Infosec & Enterprise Solution Assurance to design and maintain a Group wide infosec strategy that recognises the different risk profiles and ambitions of each business unit. You will balance agility in our digital environments with the resilience required in our heritage systems.
Develop and maintain a policy and control framework that helps colleagues make safe decisions in the real world. You will move us beyond box-ticking compliance, providing clear, pragmatic guidance and ensuring that any risk based exceptions are well understood, documented and regularly reviewed.
Build strong relationships with executive colleagues, helping them understand the evolving threat landscape in plain, commercial language. You will help define risk appetite, shape investment decisions and ensure that information security is seen as a strategic enabler, not a blocker.
Own and continually strengthen our approach to key regulations and standards such as GDPR, PCI DSS and Cyber Essentials. You will enhance our risk management frameworks so that technology and business leaders have the insight they need to own and manage their risks effectively.
Lead awareness and education in a way that works for a builders merchant environment, from branches and distribution sites to offices and digital teams. You will drive the message that colleagues are the first line of defence, creating a psychologically safe culture where people feel confident to raise concerns and report incidents.
Work closely with product, platform, engineering and service teams to build security into the technology delivery lifecycle from day one. You will help us move away from security as a late stage gatekeeper towards a consultative, embedded model, using automation where possible to reduce friction and speed up safe delivery.
Oversee our 24/7 security operations capability and hold overall accountability for information security incident management. You will coordinate internal stakeholders, including Group Counsel, and run blameless post incident reviews that focus on learning and continuous improvement. You will also ensure that we regularly test our response against realistic scenarios that reflect how our business actually operates.
You will lead a dedicated team of c.10 information security specialists in varying roles, a network of security champions and multiple third party partners, but you will set the tone, direction and standards for how we manage information security and data privacy across the Group.
Who we are looking for:
We are looking for someone who is as comfortable in the boardroom as they are in a technical design review. Someone who can talk to engineers about threat models, then step into a commercial conversation about risk and trade offs with senior leaders.
You will likely bring:
Extensive experience in information security, including leadership of people, services and third parties
A strong track record of turning complex security and privacy topics into clear, business focused conversations
Deep understanding of modern security practices and frameworks, for example NIST CSF, ISO27000, PCI DSS, OWASP, GDPR and ITIL
Experience building and leading high performing, multidisciplinary teams
The ability to distinguish between theoretical risk and material business risk, making pragmatic decisions in a complex organisation
A collaborative leadership style, with a focus on empowering experts rather than micromanaging them
A mindset that combines resilience, curiosity and a willingness to challenge the status quo in a constructive way
Relevant qualifications such as a degree in a related field and certifications like CISSP or CISM would be helpful, but we are especially interested in your real world impact and leadership experience.
Experience of being on the receiving end of one or more significant cyber incidents so you can speak from experience
Why join Travis Perkins plc?
You will have the opportunity to:
Shape how a FTSE listed, UK wide Group protects its customers, colleagues and brands
Work at genuine executive level influence on one of the most important agendas in the business
Help modernise and secure a diverse technology estate that spans digital platforms, heritage systems, logistics, stores, branches and more
Join a supportive leadership community that values integrity, pragmatism and long term partnership
As you’d expect from an industry leading employer, this position is attached to a highly competitive annual salary, bonus earning potential and car allowance. Our Head Office is based in Northampton so regular travel to here and our branches is essential in this hybrid role, so location is not too important, but being willing to travel is.
Ready to make a difference? Apply today
We’re driving to become a truly inclusive employer. We want everyone to be at their best and it’s our ambition that everyone within our Group feels safe, welcome and confident to be their authentic selves.
You be you, it makes us, us.
Do you want to be notified every time a job like this gets added? Follow the link below and we'll send you an email
Building better communities
Our businesses span the trade, home improvement and DIY markets and our aim is to offer the best for our employees, customers, suppliers and the communities around us which helps bring our strategy to life.
Who we are
Roles you may be interested in
Salary
Competitive + Benefits
Location
Northampton
Contract Type
Permanent - Full time
Location
Northampton, Northamptonshire
Business
Travis Perkins plc
Job Family
Technology
Remote or Office based
Office based only
Description
Lead Platform Engineer What will you do? Travis Perkins have recently completed a data centre exit programme which has migrated all of our operational services into AWS as our primary cloud provider.
Reference
50988
Expiry Date
01/01/0001
Salary
Location
Northampton
Contract Type
Permanent - Full time
Location
Northampton, Northamptonshire
Business
Travis Perkins plc
Job Family
Technology
Remote or Office based
Office based only
Description
Senior Software Full stack engineer This role requires to be in our Northampton head office at least once a week Are you looking for your next challenge and want to be part of a team that is hard wor
Reference
50899
Expiry Date
01/01/0001
Salary
£Competitive + Benefits
Location
Northampton
Contract Type
Permanent - Full time
Location
Northampton, Northamptonshire
Business
Travis Perkins plc
Job Family
Technology
Remote or Office based
Office based only
Description
Are you looking for your next challenge and want to be part of a team that is hard-working and driven to make a difference in our business? What will you do? Service Desk Team Leader This role is bas
Reference
50869
Expiry Date
01/01/0001
Our stories
Content Type
BlogsPublish date
01/10/2024
Summary
Meet Vanessa Vasani: Head of Enterprise Architecture Vanessa Vasani, Head of Enterprise Architecture at Travis Perkins plc, brings a wealth of experience to the table. Having worked as a Manage
Content Type
BlogsPublish date
10/24/2023
Summary
Technology is the power behind our operation at Travis Perkins plc, from where we design and develop innovative solutions in-house to bring our businesses together, transforming the way our colle
Teaser
CultureContent Type
BlogsPublish date
10/10/2023
Summary
In honour of Black History Month, we wanted to shine a spotlight on Jade Hurst, a Software Operations Engineer at Travis Perkins plc, who has been with us since 2012.Armed with a passion for c
Teaser
GeneralContent Type
BlogsPublish date
08/08/2022
Summary
The Travis Perkins Group is a leading partner to the construction industry and the UK’s largest distributor of building materials. But behind the scenes, we’re so much more than that! With over 200 ye
Teaser
GeneralContent Type
BlogsPublish date
11/17/2021
Summary
Vaida is a Data Scientist within the Travis Perkins Group’s Data Office function. Having joined us fresh out of university with a degree in Statistics, Mathematics, and Operational Research from Card
Teaser
GeneralContent Type
BlogsPublish date
03/03/2021
Summary
International Women’s Day 2021 has arrived, under the global theme, #ChooseToChallenge. This year, we’re doing just that. Every year we’ve enjoyed hearing stories from women around the globe speak abo