Job Search and Career Advice Platform

Enable job alerts via email!

Head of IT Security

Mecsia Group

United Kingdom

On-site

GBP 75,000 - GBP 100,000

Full time

Today
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading UK technical services provider is seeking a Head of IT Security responsible for establishing and executing the organization's information security strategy. The role requires hands-on oversight of security tooling, governance, and compliance efforts, primarily focusing on Microsoft security architectures. The ideal candidate will have proven experience in cyber security management and a strong understanding of relevant security frameworks and compliance mandates. The position offers a competitive salary and bonus structure along with comprehensive benefits.

Benefits

Bonus / performance incentives
Pension and benefits

Qualifications

  • Proven experience in an Information Security Manager role.
  • Strong hands-on experience with Microsoft 365 security tooling.
  • Solid understanding of GDPR and incident reporting.

Responsibilities

  • Establish and maintain the enterprise vision for information security.
  • Define and execute Mecsia's information security strategy.
  • Coordinate incident response across internal teams and partners.

Skills

Microsoft 365 security tooling
GDPR understanding
Incident response
Cyber Essentials Plus
ISO 27001 experience
Cloud security principles
Stakeholder engagement

Education

CISSP, CISM, or equivalent

Tools

Microsoft Defender
Microsoft Sentinel
Job description

Mecsia is a leading UK provider of technical inspection, maintenance, and engineering services, aiming to transform the industry with a 'Local Service, National Reach' approach. The company has grown significantly through organic expansion and strategic acquisitions, including seven business units serving large clients in different sectors including Commercial offices, healthcare and educational facilities. Under private equity ownership since 2020, Mecsia has expanded to approximately 1,200 employees, including 700 engineers. In 2024, Mecsia was acquired by Synova, recognised as PE house of the year for four of the last seven years, who supports an ambitious growth strategy through service excellence and further acquisitions.

About the Role

The Head of IT Security is responsible for establishing and maintaining the enterprise vision, strategy, and program to ensure information assets and technologies are adequately protected. This role leads the organization’s cybersecurity initiatives, risk management, and compliance efforts, ensuring alignment with business objectives.

This role combines strategic security leadership with hands‑on oversight of tooling, suppliers, controls, and assurance activities. The position will act as the organization’s day‑to‑day security authority, working closely with IT, engineering, operations, and third‑party security partners.

One of the main ambitions of the Group is to get all Group companies to Cyber Essentials Plus level and to obtain ISO 27001 accreditation. The Head of Information Security will lead and drive this initiative.

The role is particularly focused on Microsoft‑centric security architectures, outsourced SOC management, and security governance and compliance (GDPR, Cyber Essentials Plus, ISO 27001).

Key Responsibilities
  • Security strategy & governance
    • Define, maintain, and execute Mecsia’s information security strategy, aligned with business growth and risk appetite
    • Own security policies, standards, and control frameworks across the group
    • Provide regular security risk reporting to the CIO and senior leadership team
    • Act as the organization’s primary security design authority
  • Microsoft security platform ownership
    • Own and optimise the Microsoft security stack, including:
      • Microsoft Defender (Endpoint, Identity, Office 365, Cloud Apps)
      • Entra ID (Conditional Access, Identity Protection)
      • Intune/MDM for mobile and endpoint security
      • Ensure security controls are proportionate for a mixed workforce (mobile‑only users and desktop/laptop users)
  • SOC & third‑party security management
    • Act as service owner for the outsourced 24/7 SOC (Microsoft Sentinel‑based)
    • Define use‑cases, alerting thresholds, escalation paths, and response playbooks
    • Oversee supplier performance, SLAs, and continuous improvement
    • Coordinate incident response across internal teams and external partners
  • Security architecture and policy oversight for Cato SASE
    • Ensure effective integration between network security, identity, endpoint, and SIEM tooling
    • Work closely with infrastructure and cloud teams to ensure secure‑by‑design solutions
  • Compliance, assurance & risk
    • Own and maintain compliance with:
      • GDPR (in collaboration with Legal / DPO where applicable)
      • Obtain and maintain Cyber Essentials Plus accreditation
      • Obtain and maintain ISO 27001 accreditation (ISMS operation, audits, continuous improvement)
    • Manage risk registers, DPIAs, supplier security assessments, and audit findings
    • Lead internal and external audits and remediation activities
    • Own and test incident response plans, playbooks, and escalation models
    • Coordinate response to security incidents, including regulatory and customer communications where required
    • Support business continuity and disaster recovery planning from a security perspective
  • Trusted advisor & stakeholder engagement
    • Act as a trusted advisor to IT, operations, and senior management
    • Provide pragmatic security guidance to non‑technical stakeholders
    • Lead security awareness and training initiatives across the organization
Skills and Experience
  • Proven experience in an Information Security Manager / Cyber Security Manager role
  • Strong hands‑on experience with Microsoft 365 security tooling, especially Defender and Sentinel
  • Experience working with outsourced SOC services and MSSPs
  • Solid understanding of GDPR, including DPIAs and incident reporting
  • Practical experience delivering and maintaining Cyber Essentials Plus
  • Experience operating or contributing to an ISO 27001 ISMS
  • Strong knowledge of identity, endpoint, network, and cloud security principles
  • Experience supporting environments with mobile‑first and frontline workers
Preferred
  • Experience in multi‑entity or acquisitive organizations
  • Familiarity with SASE platforms (especially Cato Networks)
  • Knowledge of NCSC / NIST / CIS security frameworks
  • Experience working in regulated or safety‑critical environments
Qualifications & certifications (desirable)
  • CISSP, CISM, or equivalent
  • Microsoft Security certifications (SC‑200, SC‑300, SC‑400, etc.)
Personal attributes
  • Pragmatic and risk‑based (not “checkbox security”)
  • Comfortable balancing strategic leadership with operational oversight
  • Able to influence without authority and work cross‑functionally
  • Calm and structured under pressure during incidents
  • Strong written and verbal communication skills
Salary & package
  • Bonus / performance incentives
  • Pension and benefits

We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, colour, sex, age, national origin, religion, sexual orientation, gender identity, status as a veteran, and basis of disability.

I agree with having my data stored for 36 months.

When you apply, we may conduct a background check using public databases and websites and utilising a web search engine. Your CV may be retained for a maximum period of one year.

Stay up to date with our latest news and job offers.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

National Account Director

Mecsia Group

United Kingdom
Hybrid
GBP 85,000 - 100,000
Full time
30+ days ago
Information Security Manager

Smartdesc Ltd

City of London
Hybrid
GBP 70,000 - 80,000
Full time
30+ days ago
Operations Director – Fire Safety and Compliance

Mecsia Group

City of London
On-site
GBP 80,000 - 120,000
Full time
30+ days ago
Information Security Manager

Dubizzle Limited

Aberdeen City
On-site
GBP 60,000 - 80,000
Full time
30+ days ago
Identity and Access Management Consultant Managed Services · London, United Kingdom, Manchester[...]

Advania Company

Greater London
On-site
GBP 80,000 - 100,000
Full time
30+ days ago
Cloud Platform Security Consultant

Simpson Associates

Sheffield
Hybrid
GBP 60,000 - 80,000
Full time
30+ days ago
InfoSec Manager

Tetra Tech Limited

Leeds
On-site
GBP 80,000 - 100,000
Full time
30+ days ago
Cyber Security Engineer - Level 2

Dubizzle Limited

Manchester
On-site
GBP 29,000 - 35,000
Full time
30+ days ago
Executive Head, Information Security

Methodfi

City of London
On-site
GBP 100,000 - 150,000
Full time
30+ days ago
Group Cyber Security Specialist

Arrow

Manchester
On-site
GBP 60,000 - 90,000
Full time
30+ days ago