
Head of Cyber Security
British International Investment · London Area, United Kingdom
- On site
- Full-time
- £150,000 / year
- London Area, United Kingdom
Job highlights
- Lead cybersecurity operations and strategy for BII.
- Manage a team protecting against cyber-attacks.
- Oversee cyber risk and incident response.
- Collaborate with stakeholders and suppliers.
- Drive resilience and embed security practices.
About the role
About BII
British International Investment (BII) is the UK’s leading development finance institution, wholly owned by the UK Government. Our primary mission is to address global development challenges through strategic investments that promote sustainable and inclusive economic growth.BII focuses on catalysing economic development, creating jobs, and building resilient economies in some of the world's most complex and underserved markets. We invest in businesses and projects that prioritise inclusive development, environmental sustainability, and innovation.
Our approach is characterised by rigorous investment standards, high governance principles, and a commitment to delivering measurable development impact. Our team consists of highly skilled and passionate professionals dedicated to making a tangible difference globally.
We foster a collaborative and intellectually stimulating work environment that values curiosity, innovation, and professional growth. Our culture balances high performance with a strong emphasis on wellbeing, ensuring our employees can achieve their full potential while contributing to our mission.
BII at a glance:
- Over 75 years supporting sustainable business growth in developing and emerging markets
- More than £9.9 billion in net assets
- 1,600+ businesses invested in
- 950,000+ workers in the businesses we support
- 650+ people in our diverse global team
- 3 key development objectives: Productive | Sustainable | Inclusive
Team and role overview
The Cybersecurity Team protects BII’s technology, people, and processes from cyber-attacks. With top-tier tools and a leading Managed Security Service Provider, the team maintains the confidentiality, availability, and integrity of BII’s assets and data, supporting operations across markets. As a core part of the security function, the team is crucial in defending against evolving cyber threats. Given its role, the team is highly visible to the senior leadership of the organisation.Purpose
The Head of Cyber Security provides operational leadership, governance, and accountability for BII’s cybersecurity capability. The role manages a team of cybersecurity professionals responsible for protecting and defending BII from Cyber-attacks, whilst similarly managing identity as a security enabler. The role holder will own core and emerging cyber risk domains—spanning Cyber security operations, identity, and AI—ensuring risks are identified early, governed effectively, and managed within appetite. They will strengthen organisational resilience through incident readiness and response. The role also acts as Bronze Incident Manager for cybersecurity incidents.Role Background
BII’s technology and supplier landscape is evolving, increasing cyber risk. This role provides clear operational ownership of cyber defence, risk governance, and incident readiness, embedding security into change and decision-making.What Success Looks Like
Cyber risks are detected early, managed appropriately, and reported to senior leadership. Controls are proven effective through monitoring, vulnerability management, and measurable resilience improvements. Incidents are handled with rehearsed responses and applied lessons learned.How the Role Fits into the Organisation
Reporting to the Head of Security, the Head of Cyber Security leads day-to-day cybersecurity and works closely with Technology, senior stakeholders, and key suppliers to ensure that the Cybersecurity of BII is maintained and endures. The role turns cyber risk into prioritised actions and provides clear input to senior leadership forums to protect services, enable change, and strengthen resilience.Responsibilities
- Define and implement Cybersecurity strategy for BII, in order to keep BII safe.
- Lead and manage the cybersecurity team by setting direction, priorities, performance standards, and development plans.
- Deputise for the Head of Security when required by representing Security in senior forums and making decisions within delegated authority.
- Lead cybersecurity operations, including monitoring, vulnerability management, readiness, and control health reporting.
- Act as Bronze Incident Manager for cyber incidents by coordinating response and escalating to Silver/Gold when required.
- Manage cyber risk within agreed appetite by assessing, treating, and reporting risks with clear evidence and metrics.
- Set cybersecurity governance for key domains, including Identity, third-party security, AI risk, and data sovereignty.
- Translate cyber risk into prioritised actions and report clearly to OpCo/ExCo/Audit and other forums.
- Manage the outsourced Managed Security service provider (MSSP) and specialist suppliers by setting expectations, reviewing SLAs/KPIs, and driving remediation.
- Embed security into change by defining requirements and validating controls for patching, configuration, and new services.
- Maintain cyber playbooks, runbooks, and standards to improve consistency and reduce key-person dependency.
- Define and oversee cyber security training awareness across BII.
The candidate
The successful candidate brings a strong track record in senior cybersecurity roles, leading others to deliver effective security operations, incident management, and risk governance in complex environments. The background includes working with outsourced security providers, influencing technology and business stakeholders, and embedding practical security controls into day-to-day operations and change. The ideal candidate has a technical background and can translate complex topics into clear, business-focused discussions.Essential skills:
- Proven people leadership and the credibility to represent Security in senior forums and deputise for the Head of Security.
- Ability to set security standards and governance, and to present risk and control status clearly to senior stakeholders.
- Strong communication skills, with the ability to articulate complex technical matters to non-technical and senior audiences.
- Significant experience leading cybersecurity operations, including detection/monitoring and vulnerability management.
- Experience managing cyber incidents end-to-end, including communications, decision logs, and lessons learned.
- Strong knowledge of current threats, identity security, and third-party risk.
- Experience managing MSSPs and specialist suppliers through governance and SLAs/KPIs.
- Broad technical understanding across cloud, endpoints, networks, and logging sufficient to challenge and guide technical teams.
- Demonstrable understanding of emerging AI-driven threats, their implications for cyber security, and their mitigations.
- A relevant cybersecurity qualification and/or recognised certification (e.g., CISSP, CISM, SANS) with ongoing professional development.
Desirable criteria:
- Experience with cloud security controls and monitoring (e.g., Microsoft 365/Azure).
- Experience with SIEM/SOAR, detection engineering, or incident automation.
- Experience implementing IAM tooling and access governance (e.g., PAM, IGA).
- Experience commissioning security testing and remediation programmes (e.g., pen tests, scanning).
- Experience delivering security awareness and incident exercising programmes.
- Working knowledge of assurance frameworks and resilience expectations (e.g., ISO 27001, SOC 2, NIST CSF).
Our cultural values
We look for team members who aspire, as we do, to work at our best and to be:- Impact-led, commercially rigorous
- Tenacious in the face of challenges
- Collaborative and caring
Please provide a cover letter with your application
Salary: Competitive
Key skills/competency
- Cyber Security Strategy
- Team Leadership
- Incident Management
- Risk Governance
- Vulnerability Management
- Identity and Access Management
- Third-Party Risk Management
- AI Security Threats
- Cloud Security
- Cybersecurity Operations
Skills & topics
- Head of Cyber Security
- Cyber Security
- Information Security
- Risk Management
- Incident Response
- Security Operations
- IT Governance
- Leadership
- Cyber Defence
- Team Management
How to get hired
- Tailor your resume: Highlight leadership, incident management, and risk governance experience. Quantify achievements.
- Craft a compelling cover letter: Emphasize motivation for BII's development mission and your suitability for the Head of Cyber Security role.
- Prepare for interviews: Be ready to discuss strategic thinking, technical expertise, and stakeholder management.
- Showcase your leadership: Demonstrate your ability to lead teams and influence senior stakeholders in cybersecurity matters.
- Research BII's mission: Understand their development impact and align your experience with their values.
Technical preparation
Review BII's technology landscape.,Understand current cyber threats and mitigations.,Familiarize with cloud, endpoint, network security.,Prepare to discuss AI security implications.
Behavioral questions
Describe a major cyber incident you managed.,How do you influence senior stakeholders?,How do you balance security with business needs?,How do you foster team development and performance?
Frequently asked questions
- What are the key responsibilities for the Head of Cyber Security at British International Investment?
- The Head of Cyber Security at British International Investment is responsible for defining and implementing the cybersecurity strategy, leading the cybersecurity team, managing cyber risk, overseeing cybersecurity operations (including monitoring and vulnerability management), acting as Bronze Incident Manager, and setting cybersecurity governance for key domains like Identity and AI risk.
- What kind of experience is required for the Head of Cyber Security role at BII?
- The ideal candidate needs a strong track record in senior cybersecurity roles, with proven experience in leading security operations, incident management, and risk governance. Experience with outsourced security providers, influencing stakeholders, and embedding security controls is essential. A technical background with the ability to translate complex topics for business audiences is also required.
- Does British International Investment offer opportunities for professional development in this role?
- Yes, BII fosters a collaborative and intellectually stimulating work environment that values curiosity, innovation, and professional growth. The role requires ongoing professional development, and relevant certifications like CISSP or CISM are expected.
- How does the Head of Cyber Security role contribute to BII's overall mission?
- The Head of Cyber Security plays a crucial role in protecting BII's technology, people, and processes from cyber-attacks, ensuring operational continuity and the confidentiality, availability, and integrity of BII's assets. This directly supports BII's mission of promoting sustainable and inclusive economic growth by maintaining trust and security in their operations.
- What are the desirable criteria for the Head of Cyber Security position at BII?
- Desirable criteria include experience with cloud security controls and monitoring (Microsoft 365/Azure), SIEM/SOAR, detection engineering, IAM tooling, commissioning security testing, delivering security awareness programs, and knowledge of assurance frameworks like ISO 27001 and NIST CSF.
- How is cyber risk managed within BII for this role?
- The Head of Cyber Security is accountable for managing cyber risk within the agreed appetite. This involves assessing, treating, and reporting risks with clear evidence and metrics. The role ensures risks are identified early, governed effectively, and managed appropriately, with clear input to senior leadership forums.
- What is the team structure surrounding the Head of Cyber Security at BII?
- The Head of Cyber Security leads a team of cybersecurity professionals and reports to the Head of Security. This team is responsible for the day-to-day cybersecurity operations and works closely with Technology, senior stakeholders, and key suppliers.