Head of Cyber Security at PEXA UK overseeing security strategy and governance across UK brands. Leading operations and collaboration to ensure security and compliance while driving culture awareness.
Responsibilities
As the Head of Cyber Security at PEXA UK, you’ll play a key role in protecting the digital backbone of our business.
Working closely with the UK CTO, Group CISO in Australia, and the PEXA UK leadership team, you’ll define and drive the security strategy, standards, and posture across our three UK brands: PEXA UK, Smoove, and Optima Legal.
You’ll lead our Security Operations (SOC), Security Engineering, and Information Security and Governance functions, covering everything from incident response and secure architecture to audits, lender assurance, and compliance with ISO 27001 and FCA requirements.
This is a senior leadership role offering the opportunity to define security strategy, strengthen governance, and protect critical systems, data, and operations.
You’ll shape how we manage threats, embed secure-by-design principles, and foster a culture of security awareness across the organisation.
You’ll also collaborate closely with technology, legal, risk, and operations teams, as well as external partners, to ensure alignment and resilience, making cyber security a trusted enabler for our customers and colleagues.
Requirements
Proven experience leading cyber security operations in a regulated or financial services environment (FCA exposure preferred).
Strong understanding of security governance, assurance frameworks, and audit processes (ISO 27001, NIST, GDPR, Cyber Essentials Plus).
Experience with modern security tooling such as:
o Cortex XDR / Palo Alto Networks
o Splunk (SIEM and dashboarding)
o Abnormal Security (email security)
o Prisma Cloud (cloud security posture management)
o Airlock (application and API security)
o Nucleus (vulnerability management and reporting)
Deep knowledge of incident response, threat hunting, and vulnerability management.
Excellent stakeholder management and communication skills — able to explain complex risks in simple terms.
Experience building and mentoring high-performing teams across technical and governance functions.
Confident working in partnership with global teams and external partners to deliver consistent, secure outcomes.
Benefits
We encourage you to hit your personal and professional learning and development goals with our tailored programs and tools.
We care about your holistic wellbeing
We want to help you create your ideal work/life blend, rather than squeezing in life around work.
Cloud Security Architect integrating cyber defense strategies across cloud platforms for Elevance Health. Lead collaboration with infrastructure and engineering teams to enhance security in cloud environments.
Senior Security Advisor designing advanced security solutions for Optiv’s clients. Driving sales and building relationships in a competitive cyber security landscape.
Personnel Security Specialist leading intake operations at PSI. Focused on case coordination, quality assurance, and team training for security suitability tasks.
Security Coordinator overseeing supervision and training of security personnel for BronxWorks' homeless services programs. Ensuring compliance, safety, and coordination with social services directors in Bronx area.
Part - Time Security Officer safeguarding personnel and property at Kaman Air Vehicles. Providing access control, monitoring systems, and responding to incidents in Bloomfield, CT.
Security Officer responsible for maintaining a safe environment for clients and employees. Enforcing policies and responding to emergencies at the client's site.
Senior Security Advisor enhancing security measures to align with corporate objectives at Desjardins. Leading development of strategic initiatives and overseeing best practices in security.
Controls Professional assessing internal control frameworks at Barclays, improving control effectiveness and managing risks to ensure compliance with regulations.
Senior Information Security Engineer at Wells Fargo investigating insider threats and strengthening cybersecurity measures. Conducting advanced investigations and collaborating with cyber teams to mitigate risks.