Job Description
Job Title:  Head of Information Security
Posting Start Date:  29/10/2025
Job Id:  1784
School/Department:  IT Services
Work Arrangement:  Full Time (Hybrid)
Contract Type:  Permanent
Salary per annum (£):  £61,759 - £69,488, potential to progress to £80,524
Closing Date:  13/11/2025

The University of Sheffield is a remarkable place to work. Our people are at the heart of everything we do. Their diverse backgrounds, abilities and beliefs make Sheffield a world-class university.

We offer a fantastic range of benefits including a highly competitive annual leave entitlement (with the ability to purchase more), a generous pensions scheme, flexible working opportunities, a commitment to your development and wellbeing, a wide range of retail discounts, and much more. Find out more about our benefits (opens in a new window) and join us to become part of something special.

 

Overview

 

The University is seeking to enhance its Information Security function with the recruitment of the Head of Information Security.

 

You will lead a high performing information security team, protecting the University from cyber attacks and providing assurance to the University and its partners on information security matters.

 

Information Security has been a significant area of growth for the University and we are now focussed on continual improvement. You will work with the CISO to develop and embed mature and sustainable capabilities. As the leader of the Information Security function for the University you will build and develop the teams responsible for security operations, assurance, and identity and access management.

 

You will be working in a high profile role in a trusted team who strive to ensure that information security activities enable research and education across the University. The team is based in the department of IT Services, responsible for the delivery of trusted IT services to the University.

 

You will report to the University’s CISO, www.sheffield.ac.uk/it-services/about 

 

Main duties and responsibilities

 

  • Lead a high performing Information Security function to include;
    • Security operations across threat intelligence, security testing, investigations and incident response
    • Security assurance across risk management and compliance. Overseeing the development, implementation and management of policies, standards, procedures and strategies that align to adopted and forecasted security compliance frameworks
    • Identity and Access Management. Responsible for the development and operations of core IDAM capabilities across account provisioning, authentication and housekeeping - using a breadth of both commercial and in-house tooling
  • Build and maintain a high performing Information Security Team
    • Effective and goal driven leadership and management of the University’s Information Security functions
    • Manage the Information Security team leads; specifying the target operating model, defining specific job roles and responsibilities and supporting the team leads in managing performance
    • Develop and mentor staff in the Information Security team and other supporting areas, as required
    • Build and maintain strong relationships with, and influence over, key stakeholders, including security suppliers across the industry marketplace
    • Ensure the team is an active member of the security community; including international HE communities and law enforcement
  • Act as a trusted advisor to the CISO, deputising where required
    • Authority to make operational and strategic decisions and representing the CISO at meetings as required
    • Work in collaboration with the CISO to define and deliver the information security strategy and roadmap
  • Deliver security projects and change
    • Develop business cases for security improvements
    • Aligning change with other initiatives delivered thorough product teams
    • Delivering on University Strategy and goals outside of IT Services - e.g. strategic research partnerships
  • Ensure resources are managed effectively to include the development of business cases and operational plans as well as tracking delivery and managing budgets
  • Provide expert internal consultancy to senior stakeholders within the University in relation to security
  • Carry out other duties, commensurate with the grade and remit of the post

 

Person Specification

Our diverse community of staff and students recognises the unique abilities, backgrounds, and beliefs of all. We foster a culture where everyone feels they belong and is respected. Even if your past experience doesn't match perfectly with this role's criteria, your contribution is valuable, and we encourage you to apply. Please ensure that you reference the application criteria in the application statement when you apply.

 

Criteria

Essential or desirable

Stage(s) assessed at

Significant previous experience of information security in a large and complex organisation.

Essential

Application/interview

Expert knowledge of information security theory and practice, ideally demonstrated through a recognised Information Security professional qualification, e.g. CISM, CISSP, CISA

Essential

Application/interview

Vision, strategy and planning - Ability to specify, maintain and uphold a strategic vision for security and embed that vision into yours and others plans

Essential

Application/interview

Experience of building, managing and motivating a high performing team

Essential

Application/interview

Ability to support the development and improvement of information security governance, risk and compliance to support business activities, e.g. supplier assurance, support and advice, specialist IT services, including working with relevant standards and frameworks (e.g. CE+, ISO 27001, PCIDSS, GDPR/DPA)

Essential

Application/interview

Cyber security & technical controls - Expert understanding of the cyber security threat landscape and the most effective techniques to stay secure and implementing technical information security solutions such as encryption, firewalls, vulnerability management and identity and access management

Essential

Application/interview

Experience of working with colleagues to raise awareness and engagement with security; delivering positive change across your organisation

Essential

Application/interview

Excellent communication skills, both written and verbal, report writing skills, experience of delivering presentations; communicating to staff at all levels

Essential

Application/interview

Familiarity with related disciplines such as IT Service Management, Business Continuity, Disaster Recovery, Information Management

Essential

Application/interview

Familiarity with project management methodologies and frameworks (eg. Agile), preferably with previous practical experience of working on a security related project

Desirable

Application/interview

Previous experience of working in the HE sector

Desirable

Application/interview

 

Further Information

 

Grade

9

Salary

£61,759 - £69,488 per annum with the potential to progress to £80,524 through sustained exceptional contribution 

Work arrangement

Full-time

Line manager

Chief Information Security Officer

Direct reports

Security Assurance Manager, Security Operations Manager, IDAM Manager

Our website

https://www.sheffield.ac.uk/it-services/about (opens in new window)

For informal enquiries about this job contact Tom Griffin, CISO at t.griffin@sheffield.ac.uk

 

 

Next steps in the recruitment process

It is anticipated that the selection process will consist of an interview and a presentation. We plan to let candidates know if they have progressed to the selection stage within two weeks of the closing date. If you need any support, equipment or adjustments to enable you to participate in any element of the recruitment process you can contact it-services-recruitment@sheffield.ac.uk

 

Our vision and strategic plan

We are the University of Sheffield. This is our vision: sheffield.ac.uk/vision (opens in new window).

What we offer

  • A minimum of 41 days annual leave including bank holiday and closure days (pro rata) with the ability to purchase more.
  • Flexible working opportunities, including hybrid working for some roles.
  • Generous pension scheme.
  • A wide range of discounts and rewards on shopping, eating out and travel.
  • A variety of staff networks, providing opportunities for social interaction, peer support and personal development (for example, Race Equality, LGBT+, Women’s and Parent’s networks).
  • Recognition Awards to reward staff who go above and beyond in their role.
  • A commitment to your development access to learning and mentoring schemes.
  • A range of generous family-friendly policies
    • paid time off for parenting and caring emergencies
    • support for those going through the menopause
    • paid time off and support for fertility treatment
    • and more


More details can be found on our benefits page: sheffield.ac.uk/jobs/benefits (opens in a new window).

 

We are a Disability Confident Employer. If you have a disability and meet the essential criteria for this job you will be invited to take part in the next stage of the selection process.

Criminal record/security clearance
The successful candidate will need to obtain SC (Security Check) clearance. More information can be found here https://www.gov.uk/government/publications/united-kingdom-security-vetting-clearance-levels (opens in a new window).

Possession of a criminal record is not an automatic bar to employment at the University of Sheffield. We recognise the value of steady employment in the rehabilitation process and examine each case in its own right. More information can be found on our Information for candidates page:- sheffield.ac.uk/jobs/candidates (opens in a new window).

 

We are a research university with a global reputation for excellence. Our ideas and expertise change the world for the better, making a real difference to society. We know that when people come together with different views, approaches and insights it can lead to richer, more creative and innovative teaching and research and the highest levels of student experience. Our University Vision (www.sheffield.ac.uk/vision) outlines our commitment to building a diverse community of staff and students that recognises and values the abilities, backgrounds, beliefs and ways of living for everyone.

Disability Confident Leader