Head of IT & Information Security

GoHenry
London
GBP 100,000 - 125,000
Job description

GoHenry

GoHenry's debit card and app lets kids ages 6-18 learn practical money management skills that they can go out and apply in the real world.

GoHenry is a UK-based fintech company created by parents to pioneer financial education. More recently, GoHenry moved into Europe and the US by joining forces with French fintech company PixPay and US investing app, Acorns.

Together, Acorns, PixPay, and GoHenry have over 6 million members across 5 countries. GoHenry offers a debit card and app for kids and teens and companion apps for the family, with in-app tools for sending money, automating allowance, managing chores, setting savings goals, giving to charity, and in-app financial education lessons where kids can watch videos, take quizzes and earn points & badges. This is all designed to help kids and teens build good money habits that will last a lifetime.

The Role

As GoHenry Head of IT & Information Security, you'll own all elements of GoHenry's global information security program and be accountable for the security and protection of all information entrusted to us by our customers, partners, and employees. Ultimately, you'll be responsible for creating an organisational culture where information security is ingrained into the fabric of GoHenry standard business operations.

Reporting to the company Chief Product & Technology Officer, the Head of IT & Information Security will be responsible for proactively communicating to the executive team and board on the progress of the cyber security vision, strategy, roadmap and key performance indicators.

This position will closely work with Acorns CISO and be accountable to both Acorns CISO and GoHenry CPTO.

Responsibilities

Leadership & Team Management

  1. Lead, motivate, and manage a small team of IT & Security professionals
  2. Set clear performance expectations, objectives, and goals for team members.
  3. Conduct regular one-on-one meetings, performance reviews, and provide constructive feedback to the team.
  4. Foster a positive and inclusive team culture, encouraging professional and personal development and growth.
  5. Develop and implement a strategic security plan aligned with the organisation’s goals and objectives.
  6. Help manage the department budget

Security Operations

  1. Design, develop and maintain an information security management system and supporting roadmap to align and scale with the company growth
  2. Manage security assessment and testing processes, including but not limited to penetration testing, vulnerability management, and secure software development at a global level
  3. Implement and manage industry security standards including SOC 2 and be inline with ISO-27001, NIST800-53 as well as card payment industry standards (PCI-DSS)
  4. Develop and extend security tooling and automation efforts across the company
  5. Conduct comprehensive risk assessments to identify potential security threats and vulnerabilities.
  6. Develop and implement risk mitigation strategies to protect the organisation’s assets and reputation.

Compliance & Standards

  1. Proactively identify security issues and potential threats and continuously build processes and design systems to watch for and protect against them
  2. Improve risk posture to support and inform business stances and security investments
  3. Plan for and manage cyber incident response plans while minimising effect on the business
  4. Develop and conduct regular security drills and training programs.
  5. Educate the company about security threats and implement threat protection measures at a global level
  6. Advocate for secure application and infrastructure best practices, ensuring a security presence at all stages of the software development lifecycle
  7. Manage relationships with external information security technology vendors and specialised information security professional services firms

IT Operations

  1. Work closely with Acorns Team to ensure IT Operations are merging practices
  2. Ensuring processes are as efficient as possible
  3. Ensuring services provided are up to the agreed standard

What we’re looking for

  1. At least 10 years experience in the information security space. We would love it if that had been spent with high growth Fintech companies
  2. Expert experience with cloud security, platforms and services, including understanding of current security offerings from cloud service providers (ideally GCP) applied to microservice infrastructures
  3. Experience in developing and embedding an information security management system
  4. Experience in the evaluation, implementation and management of industry standard enterprise wide information security technologies and concepts, including but not limited to Network/Application/Cloud Security, Data Security, Threat and Vulnerability Management, runtime protection and Identity & Access Management
  5. Clear understanding of relevant information security governance, technical and security standards and regulations
  6. Hands on familiarity and experience implementing industry security standards like NIST 800-53, SOC-2, PCI-DSS, Digital Operational Resilience Act (DORA), Prudential Regulation Authority (PRA) and NIS-2 as well as current data privacy regulations, including GDPR and regional standards
  7. Deep knowledge of networking and network security
  8. Strong understanding and experience with Secure SDLC and DevSecOps or security automation
  9. Ability to work under pressure across multiple stakeholders
  10. Excellent written and communication skills and ability to communicate across all levels of an organisation.
  11. Relevant certifications (e.g., CISM, CISMP, CISSP, CCNA, SSCP) are highly desirable.

We're proud to say...

  1. We ranked #38 in Newsweek's Top 100 Most Loved Workplaces in the UK in 2023
  2. We’re one of Tech Track’s top 50 fastest-growing UK companies.
  3. We won Finders Kid’s Cards Customer Satisfaction Awards in 2022 and 2023.
  4. We won the Tech for Good award at the Better Society Awards 2023
  5. Our kids and parents have donated over £500,000 of their own money to NSPCC via their GoHenry accounts

GoHenry is an equal-opportunity employer, and we’re on a mission to foster a diverse & inclusive workplace. Individuals seeking employment at GoHenry are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law.

Want to join our mission?

If GoHenry sounds like a place you’d like to be, please apply using the link below.

Get a free, confidential resume review.
Select file or drag and drop it
Avatar
Free online coaching
Improve your chances of getting that interview invitation!
Be the first to explore new Head of IT & Information Security jobs in London