The Head of Information Security is a senior leadership position within the Office of the CISO, reporting directly to the Group CISO. The role carries accountability for the design, implementation, and continuous improvement of the Group Information Security Management System (ISMS) across all Davies entities globally, including newly acquired businesses.
The role is based in the India Global Capability Centre (GCC) and carries enterprise-wide authority for Group information security governance, assurance and risk leadership across all Davies entities globally.
This is a strategic role that goes beyond traditional ISMS stewardship. The Group Head of Information Security is expected to provide business-driven security and information risk leadership, influencing outcomes at Board and Executive Committee level and enabling growth within risk appetite.
In a rapidly evolving threat landscape, the role now explicitly encompasses risk identification across identity security strategy, AI governance oversight, post-quantum cryptography readiness, and operational resilience engineering — ensuring Davies is prepared not only for today’s threats but for the emerging challenges of 2026 and beyond.
Governance, Risk & Board Engagement
- Define and operate Group-wide information security governance, including risk appetite translation, risk acceptance/exception processes, and escalation through Group risk and governance forums with measurable outcomes.
- Own the Group assurance model (control assurance, audit readiness, continuous monitoring) to provide risk owners with objective, decision-grade evidence of security posture.
- Deliver monthly Board reporting on security risk posture, control effectiveness, and emerging threats, translating technical risk into clear business options and trade-offs.
- Maintain and continuously improve the Group risk register, ensuring alignment with enterprise risk management frameworks and regulatory expectations.
ISMS Ownership & Compliance
- Own and continuously improve the Group ISMS (aligned to ISO 27001), ensuring it remains fit for business purpose and scaled appropriately across all Davies entities globally.
- Drive the annual ISO 27001 surveillance/recertification cycle, coordinating internal audits, management reviews, and external audit engagements.
- Ensure the Group policy framework is current, proportionate, and effectively communicated, with demonstrable compliance monitoring and exception management.
- Maintain alignment with relevant regulatory and contractual obligations (including data protection regulations, client contractual security requirements, and sector-specific standards).
Security-by-Design & Identity
- Chair or set direction for security-by-design governance across architecture and change delivery, including control patterns/standards, design assurance, and pragmatic exception handling.
- Establish a Group identity security strategy covering workforce, privileged access, third parties, and service/bot identities, including defences against deepfake/impersonation attacks and insider/fake employee scenarios.
- Ensure security requirements are embedded in enterprise and solution architecture decisions, balancing risk, policy, and cost of controls.
- Govern cloud security posture including consumption/cost-abuse controls, resource guardrails, anomaly detection, and FinOps+SecOps integration.
AI & Automation Governance
- Define and oversee security controls for AI-enabled tooling and automation across the Group, including acceptable use policies, data handling requirements, and monitoring/assurance.
- Reduce exposure to AI-assisted social engineering through modern security awareness programmes that explicitly address AI-crafted persuasion and impersonation techniques.
- Govern shadow AI risk through discovery, policy enforcement, and pragmatic onboarding pathways that balance productivity with control.
- Contribute to enterprise AI/algorithm governance, ensuring controls, monitoring, auditability, and risk management for third-party models and automated decisioning.
Supplier & Ecosystem Assurance
- Strengthen third-party and supply chain assurance beyond initial assessment, including contractual security controls, ongoing assurance cadence, concentration risk analysis, and cascading supply-chain compromise readiness.
- Ensure supplier risk is integrated into Group risk reporting and that material third-party security risks are escalated to appropriate risk owners.
Incident Reporting & Monitoring
- Oversee threat-led security planning and incident response maturity across the Group, working closely with the Cyber team.
- Ensure robust incident reporting, classification, root cause analysis, and lessons-learned processes are embedded and continuously improved.
- Maintain deepfake/impersonation preparedness for executives and high-risk business processes.
M&A Security Integration
- Lead security due diligence and risk assessment for mergers, acquisitions, and divestitures.
- Design and deliver security integration plans for newly acquired businesses, ensuring alignment with Group ISMS standards within defined timescales.
- Identify and manage inherited security risks from acquisitions, including legacy technology, unmanaged identities, and contractual obligations.
Team Leadership & Development
- Lead, develop and mentor the four Divisional Information Security Officers, creating consistent standards, clear accountability and a high-performing federated security leadership community across the Group
- Build team capability in emerging disciplines (identity security, AI governance, resilience engineering, PQC readiness) through targeted development and recruitment.
- Promote security culture across the wider organisation through engagement, awareness, and collaboration with business stakeholders.
-
Significant experience in a senior information security leadership role, with demonstrable ability to influence senior risk owners and embed security decision-making across multiple business units and geographies.
- Expert capability in enterprise security risk management, including risk appetite translation, risk acceptance pathways, measurable risk treatment plans and independent assurance reporting.
- Proven track record of maintaining ISO 27001 certification and managing external audit cycles in a complex, multi-entity organisation.
- Strong experience implementing security-by-design governance across architecture and change delivery, including control patterns, design assurance and pragmatic exception handling.
- Strong understanding of identity-led security, including privileged access, third-party identity and anti-impersonation controls.
- Excellent communication skills, with the ability to tailor messages for Board, CISO, technical and business audiences, including concise risk narratives and clear escalation.
- Experience governing cloud security and modern attack surfaces, including vulnerability and exploit response expectations and secure operational patterns.
- Strong supplier assurance experience beyond initial assessment, including contractual controls, ongoing assurance programmes and supply-chain compromise readiness.
- Demonstrated success leading through federated and matrix structures, including directing divisional security leaders and aligning stakeholders without relying solely on line authority.
- Demonstrated ability to lead and influence senior stakeholders across multiple cultures and geographies through clear governance, strong written communication and disciplined decision-making.
We are a specialist professional services and technology firm, working in partnership with leading insurance, highly regulated and global businesses.
We help our clients to manage risk, operate their core business processes, transform and grow. We deliver professional services and technology solutions across the risk and insurance value chain, including excellence in claims, underwriting, distribution, regulation & risk, customer experience, human capital, digital transformation & change management.
Our global team of more than 8,000 professionals operate across ten countries, including the UK & the U.S. Over the past ten years Davies has grown its annual revenues more than 20-fold, investing heavily in research & development, innovation & automation, colleague development, and client service. Today the group serves more than 1,500 insurance, financial services, public sector, and other highly regulated clients.