Head of Information Security
Your Role in Our Story:
ACT is strengthening its data, technology and AI capabilities as we build a more integrated digital platform alongside our core environmental commodities trading and market-making business. This transformation is commercially driven, enabling us to scale, deepen client relationships and support increasingly complex and digital markets.
As Senior Information Security Officer, you will own ACT’s enterprise information security strategy and governance at Group level, spanning our core operations, emerging digital businesses and client-facing technology platforms. You will define the security risk appetite, lead our response to an evolving threat landscape, and ensure security and resilience are embedded by design as our technology landscape develops.
Working across business and technology leadership, you will translate commercial ambition into a pragmatic and scalable security posture that protects our systems and data while maintaining the trust of clients, counterparties and regulators. In essence, your role involves:
Strategy & Governance
- Own the Group-wide information security strategy and roadmap across ACT’s core market-making business and digital and client-facing platforms, aligned with business goals and industry frameworks such as ISO 27001 and NIST CSF. Define and maintain ACT’s cyber risk appetite.
- Establish and lead security governance, including policies, standards and control frameworks, with clear accountability across the Group. Report on security posture and material incidents to executive leadership and, where relevant, the Board.
Client Platforms & Secure-by-Design
- Embed security-by-design into new products and client platforms, partnering with Data, Architecture and Commercial teams to ensure emerging digital capabilities are secure from inception, while acting as a credible security voice to clients and counterparties.
- Oversee application, product and SaaS security, embedding security throughout the software development lifecycle for internal and client-facing platforms, and assessing third-party services handling ACT and counterparty data.
Risk & Resilience
- Lead enterprise security risk management, including risk assessments, vulnerability management and third-party/supply-chain risk, driving timely mitigation across core and digital environments.
- Direct incident preparedness and response, coordinating detection, containment, eradication and recovery, while continuously strengthening incident and crisis-management plans.
Infrastructure & Emerging Technology
- Secure ACT’s cloud and infrastructure through Zero-Trust-aligned controls, including identity and access management, segmentation and encryption, across a hybrid and multi-platform environment.
- Govern emerging technology and AI security, extending security oversight to AI and data platforms, including model and data-exposure risks and AI-enabled threats, as ACT expands its use of AI.
Compliance & Leadership
- Ensure regulatory and compliance alignment, including GDPR, DORA and relevant sector obligations, advising the business on required adaptations and coordinating audits and certifications.
- Lead the security function and strengthen security culture across the Group, developing the team, raising security awareness, and acting as ACT’s primary authority and trusted advisor on cyber security to executives and business leaders, working alongside existing teams and capabilities.
Your Expertise:
To be successful in this role, we are looking for candidates with the following qualifications and attributes:
- A Bachelor’s degree in Information Security, Computer Science or a related field. A relevant Master’s degree is an advantage.
- 10–15 years of progressive experience in information security and cybersecurity, including at least 5 years in a senior security role, with ownership of enterprise security strategy, governance and risk management.
- Broad security leadership experience across incident response, cloud and infrastructure security, product/application security and regulatory compliance. Experience securing client-facing platforms or digital products is highly valuable.
- Experience within trading, financial services, commodities or another data-intensive and regulated environment is highly advantageous.
- Strong knowledge of security frameworks and standards, including ISO/IEC 27001, NIST Cybersecurity Framework and CIS Controls, with practical experience implementing them.
- Good understanding of data protection, regulatory and compliance requirements, including GDPR, DORA and standards such as SOC 2.
- Professional certifications such as CISSP, CISM or CISA, or equivalent, are highly desirable.
- Strong analytical, communication and stakeholder-management skills, with the ability to translate complex security risks into clear business implications and advise technical teams, executives, business stakeholders and clients.
If you meet these criteria and are ready to contribute your expertise to a dynamic and challenging environment, we encourage you to apply.