Chief Information Security Officer
Grant Thornton UK
Job Description
Chief Information Security Officer (CISO) Location – London Grant Thornton UK is a leading professional services firm undergoing a significant technology‑led transformation. The CISO will be the senior IT security authority, reporting directly to the CIO. Key Responsibilities Security Strategy and Governance Develop and maintain the firm’s Information Security strategy, aligned with IT, CDO priorities and digital transformation programme.
Own and operate the Information Security Management System (ISMS), ensuring compliance with ISO 27001 and other applicable standards. Provide senior input to risk committees on AI and information security, and represent security at the AI Governance Board. Maintain and report on a cyber risk register, providing regular risk posture updates to the CIO, CDO and relevant governance forums.
AI and Digital Transformation Security Lead security governance for the firm’s generative AI programme. Assess and govern emerging risks from AI‑generated outputs, including artefact hosting, client‑facing microsites and third‑party MCP integrations. Risk, Compliance and Regulatory Obligations Ensure the firm’s security posture meets obligations to professional standards bodies (ICAEW, FRC), client contractual requirements and applicable regulation.
Lead incident response governance, including classification, escalation, investigation and lessons‑learned processes for cyber and information security incidents. Oversee third‑party and supplier security risk management, including due diligence on SaaS platforms and cloud infrastructure providers. Support or lead engagement with cyber insurers, clients, external auditors and any regulatory enquiries related to information security.
Security Culture and Awareness Drive a security‑aware culture across the firm, developing and maintaining the training and awareness programme. Champion a secure‑by‑design mindset across IT, the digital team and the wider business. Leadership and Stakeholder Engagement Lead, manage and develop the security function, including GRC, security engineering and awareness roles.
Act as the primary escalation point and senior authority for all security matters. Represent Grant Thornton UK in external forums, industry bodies and client conversations where security governance or assurance is relevant. Build influence and effective working relationships with the CISO community across the Grant Thornton International network.
Essential Experience Proven experience as a CISO or senior information security leader in a professional services, financial services or similarly regulated environment. Demonstrable track record of developing and operating an ISMS, managing a cyber risk register and reporting to senior leadership. Hands‑on experience governing AI platforms from a security and compliance perspective.
Experience owning DLP controls, incident response processes and third‑party security risk management in a cloud‑first environment. Strong grasp of relevant compliance frameworks: ISO 27001, NIST CSF, UK GDPR and professional services regulatory obligations. Desirable Experience Familiarity with generative AI platforms, LLM governance, and emerging risks from AI‑generated content and tool integrations.
Experience with CrowdStrike or equivalent EDR/SIEM platforms, including integration with compliance logging pipelines. Exposure to Microsoft Fabric, Databricks or similar data platform environments. Experience operating within a Big Four or Top Ten professional services firm, including understanding of client confidentiality obligations and engagement letter governance.
Qualifications CISSP, CISM or equivalent professional certification. ISO 27001 Lead Implementer or Auditor (desirable). Degree in Information Technology, Cybersecurity, Computer Science or related discipline, or equivalent professional experience.
Benefits Tailored development programmes and access to coaching. Flexible bank holidays. Benefits including pension, life assurance, private medical, additional holiday purchasing and health benefits.
Other benefits such as shopping discounts, gym memberships and financial advice. #J-18808-Ljbffr