<h3 class="theme-panel-header text-2xl pb-6 theme-vacancy-section-title">About the role</h3><p>The Head of Cyber Security / CISO is accountable for leading Matalan’s cyber security strategy, governance, risk management and operational resilience at a senior, non-board level. The role provides dedicated ownership of cyber risk, security architecture, incident readiness, supplier security and continuous improvement, ensuring cyber security priorities are translated into clear business outcomes, measurable risk reduction and effective protection of Matalan’s customers, colleagues, data and critical services.</p><p>Key Responsibilities</p><p>Leadership:</p><ul><li>Lead and develop Matalan’s internal cyber security capability, ensuring the right skills, succession plans and accountabilities are in place across cyber governance, architecture, delivery and continuous improvement</li><li>Provide senior cyber security leadership and advice to the Director of IT, Executive team and relevant governance forums, translating technical risk into clear business impact and decision options</li><li>Lead the performance management of cyber security contractors, managed service partners and specialist third parties, ensuring clear ownership, challenge and delivery against agreed outcomes</li></ul><p>Cyber Strategy, Governance and Risk Management:</p><ul><li>Own and maintain Matalan’s cyber security strategy and roadmap, ensuring priorities are risk-led, business aligned and focused on measurable improvements in resilience and recovery</li><li>Establish and embed cyber governance, risk and compliance processes, including policies, standards, risk appetite, risk assessment, control assurance and reporting</li><li>Maintain a transparent view of cyber threats, vulnerabilities, control gaps and enterprise cyber risks, ensuring decisions are prioritised using business impact and agreed risk appetite</li><li> Lead cyber security reporting for IT leadership, Executive forums and relevant governance groups, providing clear insight on risk posture, progress, investment choices and residual risk</li></ul><p>Security Architecture, Operations and Incident Readiness:</p><ul><li>Ensure cyber security is embedded into technology strategy, architecture, change delivery and supplier solutions from the outset, reducing risk and rework</li><li>Oversee security operations, monitoring, vulnerability management, identity security, endpoint controls, network security and logging improvements delivered through internal teams and managed service partners</li><li>Own cyber incident readiness and response leadership, including incident response plans, rehearsals, CIRT mobilisation, technical response coordination and lessons learned</li><li> Drive continuous improvement of cyber controls, ensuring audit findings, incident lessons, maturity assessments and threat intelligence translate into prioritised action</li></ul><p>Supplier and Third-Party Cyber Risk:</p><ul><li>Establish and oversee third-party cyber risk management, ensuring critical suppliers, SaaS providers and technology partners are assessed, governed and monitored proportionately to risk</li><li>Work with Procurement, Legal, Vendor Management and business owners to embed cyber security obligations into supplier onboarding, contracts, assurance activity and incident escalation routes</li><li> </li></ul><div class="absolute bottom-2 right-2"><button onclick="scrollToTop()" class="theme-primary p-2 rounded-lg flex"> <i translate="no" class="material-symbols-outlined"> arrow_upward </i> </button></div>





