Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Head of Security image - Rise Careers
Job details

Head of Security

About Allica Bank

Allica is the UK’s fastest growing company - and the fastest-growing financial technology (Fintech) firm ever. Our purpose is to help established SMEs, one of the last major underserved opportunities in Fintech.

Established SMEs are the backbone of local communities - representing over a third of our economy - yet have been largely neglected both by traditional high street banks and modern fintech providers.

Department Description

The Allica Security team play a key role in protecting the bank and are responsible for all aspects of security surrounding Applications, Infrastructure and Security Operational Policy.  Our mission is to provide the best-in-class security to protect the bank. We live and breathe the Allica values and deliver services intelligently using automation, intelligence, and innovation.  

Role Description

An experienced Head of IT Security is required to join a fast-paced IT division in an interim basis, to facilitate and enhance all aspects of security within the bank.  

The role will have responsibility for identifying potential threats, proposing and implementing mitigative activities and managing these items through to delivery.    

Using a rich source of Application and Network data, you will have experience of designing and implementing effective security monitoring and alerting strategies whilst remaining a very much hands-on approach to driving forward continuous improvement and using your experiences to feed into the wider strategy of enhancing the bank’s IT security further.  

Using a combination of third-party tooling and custom solutions to assist you with security threat analysis and detection, you will help drive the security strategy for current and future product implementations. With good mentoring and coaching capabilities, you will help engineering and infrastructure experts adopt a secure by design strategy.  

Principal Accountabilities

Strategic Leadership  

  • Define and execute a comprehensive, forward-thinking information security strategy that supports decentralized decision-making under centralized governance.  

  • Cultivate a security-first culture across the organization, empowering teams to integrate security into their workflows.  

  • Collaborate with executive leadership to align security strategies with organizational goals and regulatory requirements.  

Security Operations 

  • Oversee security operations to monitor, detect, and respond to potential threats in real-time.  

  • Lead the establishment of a Security Operations Center (SOC) for continuous monitoring and threat intelligence.  

  • Continuously evaluate and enhance security tools, technologies, and processes to stay ahead of evolving threats.  

Application and Cloud Security  

  • Implement best practices for secure development and deployment of cloud-native applications.  

  • Drive adoption of secure coding practices and DevSecOps methodologies across product engineering squads.  

  • Establish and manage robust cloud security frameworks that safeguard sensitive data and applications.  

Incident Response and Disaster Recovery  

  • Develop, implement, and test Cybersecurity Incident Response Plans (CSIRP) and Disaster Recovery Plans (DRP).  

  • Lead the response to cybersecurity incidents, ensuring rapid containment and recovery.  

  • Conduct post-incident analysis along with the incident team to identify root causes and enhance defenses.

Third-Party Security and Due Diligence  

  • Conduct risk assessments and due diligence on third-party vendors and partners.  

  • Establish and enforce third-party security standards and monitor compliance.  

  • Manage security reviews during vendor onboarding and contract renewals.  

Governance, Risk, and Compliance  

  • Ensure compliance with relevant regulations (e.g., PCI DSS, GDPR, SOC 2, ISO 27001) and internal policies.  

  • Maintain up-to-date knowledge of emerging threats, regulatory changes, and best practices.  

  • Establish and report key security metrics to the executive team and board.  

 

Personal Attributes & Experience

  • Proven experience in a senior security leadership role, preferably in fintech or technology sectors.  

  • Demonstrated success in building security awareness programs and fostering decentralized accountability.  

  • Expertise in security operations, cloud security, application security, and incident response.  

  • Relevant certifications such as CISSP, CISM are highly desirable.  

  • Strong knowledge of security frameworks (e.g., NIST, CIS, ISO 27001) and compliance standards (e.g., PCI-DSS, PSD2, GDPR).  

  • Hands-on experience with security technologies (e.g., SIEM, endpoint protection, cloud security tools).  

  • Exceptional leadership and communication skills, with the ability to engage and influence diverse stakeholders. 

Working at Allica Bank

At Allica Bank we want to ensure our employees have the right tools and environment in which to succeed in their role and in support of our customers.

Our employees are at the heart of everything we do, so our benefits are designed with you in mind:

  • Full onboarding support and continued development opportunities

  • Options for flexible working

  • Regular social activities

  • Pension contributions

  • Discretionary bonus scheme

  • Private health cover

  • Life assurance

  • Family friendly policies including enhanced Maternity & Paternity leave

Don’t tick every box?

Don’t worry if you don’t have all the skills or requirements listed on the job description. If you think you’ll be a good fit, we’d still love to hear from you!

Flexible working

We know the ‘9-to-5’ isn’t right for everyone. That’s why Allica Bank is fully committed to flexible and hybrid working. Please let us know what is best for you and, if we can, we will do our best to accommodate.

Diversity

We’re a diverse bunch here at Allica, with all kinds of experiences, backgrounds and lifestyles. Our openness and differences make us stronger, and we want everybody to feel comfortable bringing as much of themselves to work with them as they like.

Allica Bank Glassdoor Company Review
4.0 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Allica Bank DE&I Review
4.1 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
CEO of Allica Bank
Allica Bank CEO photo
Richard Davies
Approve of CEO

Average salary estimate

$125000 / YEARLY (est.)
min
max
$100000K
$150000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Head of Security, Allica Bank

At Allica Bank, we are excited to announce an opportunity for an experienced Head of Security to join our innovative team in London. As the fastest-growing fintech company in the UK, we are committed to empowering established SMEs, the backbone of our economy. In this pivotal role, you will play a critical part in safeguarding our bank by implementing a robust security framework that encompasses Applications, Infrastructure, and Security Operational Policy. Your mission will be to identify potential threats and develop strategies for effective threat detection and response. The ideal candidate will have a hands-on approach to enhancing our security posture and the ability to leverage data to continuously improve our security strategies. You will also be instrumental in adopting DevSecOps methodologies, which promote security by design across all teams. With a focus on cultivating a security-first culture, you’ll work closely with leadership to align our security objectives with overall organizational goals. We offer a collaborative environment, access to cutting-edge security technologies, and a chance to lead the establishment of a Security Operations Center. Join us at Allica Bank in shaping the future of fintech while making an impact on the security landscape for our organization and our customers.

Frequently Asked Questions (FAQs) for Head of Security Role at Allica Bank
What are the responsibilities of the Head of Security at Allica Bank?

The Head of Security at Allica Bank is responsible for overall security strategy, overseeing security operations, implementing best practices for application and cloud security, and managing incident response procedures. Additionally, this role involves leading the establishment of a Security Operations Center and ensuring compliance with regulations such as PCI DSS and GDPR.

Join Rise to see the full answer
What qualifications are needed for the Head of Security position at Allica Bank?

Candidates applying for the Head of Security role at Allica Bank should possess proven experience in senior security leadership, particularly in fintech or technology sectors. Relevant certifications like CISSP or CISM, alongside knowledge of security frameworks like NIST and ISO 27001, are highly desirable.

Join Rise to see the full answer
How does Allica Bank support the development of the Head of Security?

At Allica Bank, we provide full onboarding support, continuous development opportunities, and flexible working arrangements, ensuring our Head of Security has the right tools and environment for success. We also encourage leadership in security awareness within the team and across the organization.

Join Rise to see the full answer
What does the team culture look like for the Head of Security at Allica Bank?

The culture at Allica Bank emphasizes diversity and collaboration. As the Head of Security, you will cultivate a security-first mindset among teams, empowering them to integrate security into their workflows while enjoying a supportive environment that values each individual’s contributions.

Join Rise to see the full answer
What opportunities for growth exist for the Head of Security at Allica Bank?

The Head of Security at Allica Bank has abundant growth opportunities, including the chance to lead cutting-edge security initiatives, influence organization-wide security practices, and mentor engineering and infrastructure teams towards secure development. The dynamic nature of fintech also presents continuous learning and professional development avenues.

Join Rise to see the full answer
Common Interview Questions for Head of Security
Can you describe your experience in building security awareness programs?

In building security awareness programs, I focus on cultivating a culture where all employees understand their role in security. My approach involves creating engaging training materials, incorporating real-world scenarios, and advocating for regular discussions on security topics to ensure ongoing awareness.

Join Rise to see the full answer
How do you approach risk management and assessment in a fintech environment?

My approach to risk management involves regularly conducting thorough assessments, identifying potential vulnerabilities, and implementing a tiered response strategy. In a fintech environment, I prioritize compliance with regulations like GDPR and PCI DSS while actively engaging with all departments to ensure comprehensive risk solutions.

Join Rise to see the full answer
What strategies do you use to ensure compliance with security regulations?

To ensure compliance, I establish clear policies and procedures that align with relevant regulations. Regular audits and assessments are important, as well as training staff on compliance requirements. I also collaborate with legal and operational teams to stay updated on any regulatory changes.

Join Rise to see the full answer
Can you detail your experience with Security Operations Center (SOC) implementation?

I have successfully led the implementation of a Security Operations Center by defining its mission, establishing best practices for monitoring, and ensuring effective incident response protocols. This involved choosing the right technologies and training staff to enable proactive detection and response to threats.

Join Rise to see the full answer
How do you foster a culture of security within an organization?

Fostering a culture of security involves engaging employees at all levels, integrating security training into onboarding processes, and providing regular updates and information on security best practices. I also encourage open communication regarding security and make it a shared responsibility among all staff.

Join Rise to see the full answer
What methods do you employ for continuous improvement in security practices?

Continuous improvement in security practices is achieved through regular reviews of incident reports, staying informed on emerging threats, and adapting strategies according to lessons learned. I also gather feedback from my team and stakeholders to identify areas for enhancement.

Join Rise to see the full answer
How do you handle cybersecurity incidents when they arise?

When handling a cybersecurity incident, I initiate our Incident Response Plan immediately, ensuring the appropriate teams are alerted. My focus is on swift containment, thorough investigation, and clear communication throughout the process to minimize damage and prevent future occurrences.

Join Rise to see the full answer
In your opinion, what is the most critical security challenge facing fintech companies today?

I believe the most critical challenge facing fintech companies today is the constantly evolving threat landscape. Cyber attackers are becoming more advanced, and it's essential to not only protect sensitive data but also to build resilience against potential breaches through proactive threat intelligence and robust security policies.

Join Rise to see the full answer
What role do third-party vendors play in security strategy?

Third-party vendors can present significant risks, which is why I prioritize thorough risk assessments and maintaining stringent security standards for them. Ensuring that third-party contracts include security requirements and compliance is critical in mitigating risks associated with vendors.

Join Rise to see the full answer
How do you balance innovation with security in product development?

Balancing innovation with security involves integrating security from the very start of the product development lifecycle. By adopting DevSecOps practices, I ensure that security measures are built into processes and workflows, facilitating innovation while safeguarding our products and customers.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 9 days ago
Photo of the Rise User
Posted 2 days ago
Photo of the Rise User
Posted 10 days ago
Photo of the Rise User
Posted 5 days ago
Inetum Remote Paris, France
Posted 9 days ago
Photo of the Rise User
Posted 4 days ago
Photo of the Rise User
Posted 2 days ago
MATCH
VIEW MATCH
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
March 26, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Columbus just viewed Store Manager - New Store Opening at Curaleaf
S
Someone from OH, Dayton just viewed Senior Director, Employee Engagement at Scout Motors
Photo of the Rise User
Someone from OH, Akron just viewed Finance Intern - Summer 2025 at Spectrum
Photo of the Rise User
Someone from OH, Norwalk just viewed Hybrid Account Manager-Commercial Lines at AssuredPartners
Photo of the Rise User
Someone from OH, Loveland just viewed Animator at Apex Systems Bellevue, WA at Apex Systems
Photo of the Rise User
Someone from OH, Canton just viewed Lead Jr. Toddler Teacher at All Around Children
Photo of the Rise User
Someone from OH, Mentor just viewed Site Merchandising Manager at Lovepop
Photo of the Rise User
Someone from OH, Batavia just viewed Restaurant Busser at Outback Steakhouse
Photo of the Rise User
Someone from OH, New Albany just viewed Customer Success Manager at Quisitive
Photo of the Rise User
Someone from OH, Columbus just viewed UGC Creator - USA, Female 40-50 - Contract to hire at Upwork
Photo of the Rise User
25 people applied to IT Intern at USAA
Photo of the Rise User
59 people applied to Jr SOC Analyst at IBM
Photo of the Rise User
Someone from OH, Strongsville just viewed Automotive Buyer at Sonic Automotive
Photo of the Rise User
Someone from OH, Strongsville just viewed Experienced Automotive Buyer at Sonic Automotive
Photo of the Rise User
Someone from OH, Columbus just viewed Business Systems Analyst, Apps & Automations at Deel
Photo of the Rise User
Someone from OH, Findlay just viewed Marketing Analyst at ITW
R
Someone from OH, Cleveland just viewed Marketing Lead at Redi.Health
Photo of the Rise User
Someone from OH, Cleveland just viewed Associate Conversion Data Analyst at Bloomerang
Photo of the Rise User
Someone from OH, Cleveland just viewed Material Buyer/Planner at Aston Carter
F
Someone from OH, Cleveland just viewed Senior Materials Planner at Fortune Brands
Photo of the Rise User
Someone from OH, Cleveland just viewed Junior Data Analyst at Arkana Laboratories
Photo of the Rise User
Someone from OH, Cleveland just viewed BI Analyst, Junior at Emi Labs