About the job
Kroo Bank is redefining banking by creating a customer-centric experience that prioritizes responsible financial management and leverages technology to simplify, democratize, and enhance transparency in everyday banking. As a fully regulated UK bank, we are supported by dedicated investors and are on a mission to grow our customer base while pursuing ambitious goals. Our commitment to excellence is evident in our fast-paced operations, thoughtful decision-making, and adherence to the highest standards of service, product development, risk management, and employee care.
Job Overview:
We are seeking a dynamic Head of Information Security (HoIS) to lead our IT security strategy and safeguard the organization against security threats targeting our digital assets. In this role, you will direct the security strategy, oversee operations, and drive product development to protect our enterprise information. Your responsibilities will include fostering security awareness, managing security operations, and ensuring robust policies and procedures are in place.
Key Responsibilities:
- Oversee the daily operations and execution of the information security strategy.
- Design and maintain a proactive security roadmap encompassing cloud, mobile, AI, and software platforms.
- Work collaboratively with technology leaders to implement innovative security technologies and next-generation solutions.
- Guarantee secure configurations and ensure continuous compliance across IaaS, PaaS, and SaaS environments.
- Conduct ongoing assessments of existing security practices and systems, identifying and addressing areas for enhancement.
- Perform security audits and risk assessments, providing recommendations to mitigate threats and vulnerabilities.
- Manage the Information Security Management System (ISMS) and uphold ISO 27001 certification.
- Ensure adherence to relevant compliance and governance standards.
- Collaborate with operational teams to develop, implement, and test business continuity plans for security breaches and disaster recovery scenarios.
- Safeguard the organization's intellectual property consistently.
- Monitor security vulnerabilities and potential hacking threats across network and host systems.
- Lead security operations, including Managed SOC, threat intelligence, detection, and response capabilities.
- Establish KPIs and KRIs to measure security maturity and provide consistent security reporting to Executive and Board stakeholders.
- Manage and nurture the information security team.
- Promote and educate the organization on the latest security strategies and technologies.
- Oversee the IT security budget and communicate effectively with stakeholders.
