Full-Time

Head of Cyber and Information Security

Cyber Security, Information Security

Posted on 8/5/2025

MHRA

MHRA

1,001-5,000 employees

Regulates medicines and medical devices

No salary listed

United Kingdom

In Person

Category
IT & Security (1)
Required Skills
Risk Management
Requirements
  • Significant experience leading multi-disciplinary cyber and information security teams, with a track record of delivering complex cyber programmes and developing high-performing teams.
  • Holds one or more industry-recognised certifications such as CISSP, CISM, CCISO or equivalent executive-level security certification
  • Demonstrable experience leading security investigations and incident response, including handling malware outbreaks, data loss events, and network intrusions.
  • Experience in setting and executing cyber and information security strategy, with the ability to engage, influence, and advise stakeholders at all levels, including senior executives and board members.
  • Strong background in managing information and cyber security risks, with a proactive approach to identifying emerging threats and developing strategic mitigation plans.
Responsibilities
  • Champion a security-first culture across MHRA, modelling Civil Service values and fostering professional development within the Information Security community.
  • Develop and implement MHRA’s cyber security strategy in alignment with the Government Cyber Security Strategy, GovS 007, and NCSC guidance.
  • Evaluate and continuously assess MHRA’s cyber security maturity, defining and delivering a roadmap to achieve target resilience levels.
  • Identify and prioritise areas for cyber security investment, building business cases and securing executive support.
  • Promote secure innovation by embedding security into agile delivery and emerging technologies, enabling safe experimentation and scaling.
  • Lead the Cyber and Information Security team within DTG, ensuring effective budget management, workforce planning, and capability development.
  • Oversee the cyber programme and operational security functions, ensuring delivery against strategic objectives and measurable outcomes.
  • Direct cyber defence operations including threat detection, monitoring, incident response, and integration of threat intelligence.
  • Provide technical assurance for new and legacy systems, embedding Secure by Design principles and architectural risk assessments.
  • Define and maintain MHRA’s security architecture framework, ensuring alignment with enterprise architecture and secure development lifecycle practices.
  • Promote cyber security awareness and behavioural change across MHRA, embedding good security practices at all levels.
  • Advise the SIRO, Security Risk Working Group, Board and senior department heads on cyber risk, threat landscape, and incident response readiness.
  • Maintain oversight of MHRA’s Information Security Management System (ISMS), ensuring compliance with ISO/IEC 27001:2022, NCSC CAF, and other relevant standards.
  • Lead assurance activities including internal audits, control testing, and third-party assessments to validate the effectiveness of security controls.
  • Supporting the development and implementation of KRIs/KPIs to measure cyber risk exposure, control effectiveness, and compliance maturity.
  • Act as the primary point of contact for cyber security matters across MHRA and with external partners including NCSC, DHSC, NHSE, and ALBs.
  • Establish and manage a third-party risk management framework, including due diligence, contractual controls, and ongoing monitoring of supplier security practices.
  • Ensure third-party suppliers meet MHRA’s security expectations and contractual obligations, delivering high-quality outcomes on time and within budget.

MHRA is an executive non-departmental public body responsible to the Secretary of State for Environment, Food and Rural Affairs. Its purpose is to protect and improve England’s natural environment and to encourage people to enjoy and get involved in their surroundings. It carries out policy implementation, land stewardship, conservation funding, and public engagement through government-backed programs and partnerships with landowners, communities, and volunteers. Its goal is to safeguard natural spaces, biodiversity, and landscapes while inviting people to participate in caring for and enjoying the environment.

Company Size

1,001-5,000

Company Stage

N/A

Total Funding

N/A

Headquarters

London, United Kingdom

Founded

1989

Simplify Jobs

Simplify's Take

What believers are saying

  • Flexible wildlife licensing for infrastructure projects balances conservation with necessary development.
  • Evidence-based standards and partnerships target 30x30 nature recovery and species decline halt.
  • Green infrastructure integration through spatial planning delivers combined environmental and community benefits.

What critics are saying

  • 20% MHRA workforce reduction undermines regulatory capacity and clinical trial oversight.
  • Only five operational Approved Bodies create bottlenecks for Class III device conformity assessments.
  • Post-Brexit regulatory divergence forces UK medtech firms into separate UKCA marking processes.

What makes MHRA unique

  • MHRA independently regulates UK medicines, vaccines, and medical devices post-Brexit.
  • Three-year Strategy for Improving Safety Communications transforms patient and healthcare professional engagement.
  • New regulations effective April 28, 2026 align UK clinical trial oversight standards.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Flexible Work Hours

Hybrid Work Options

Remote Work Options

Company News

energy365
Apr 16th, 2026
UK's Geothermal Engineering secures government grant to scale Cornwall lithium extraction to 18,000 tpa

Geothermal Engineering Ltd has secured government funding through the DRIVE35 programme to expand lithium extraction at its United Downs plant in Cornwall. The company began the UK's first commercial-scale lithium production at the site in February, currently producing 100 tonnes annually. The facility extracts lithium from geothermal brines containing over 340 parts per million of lithium, one of the highest concentrations found globally. GEL aims to scale production to over 18,000 tonnes per annum within a decade, sufficient for approximately 250,000 electric vehicle batteries yearly—equivalent to 65% of the UK's 2024 battery electric vehicle registrations. The DRIVE35 programme, delivered by the Department for Business and Trade with Advanced Propulsion Centre UK and Innovate UK, supports automotive sector innovation and industrial transformation.

East Midlands Business Link
Apr 10th, 2026
Derby seafood firm secures £200k innovation deal - East Midlands Business Link

A Derby-based seafood wholesaler has secured £200,000 in government-backed funding to modernise its operations using digital technology and artificial intelligence.

EIN Presswire
Apr 9th, 2026
UK's CyberASAP secures $12.7M as alumni raise $60.2M and women-led teams reach 43%

CyberASAP, a UK programme accelerating cyber security startups from universities, has secured £10 million in additional government funding over four years. The Department for Science, Innovation and Technology commitment comes as the Innovate UK-delivered initiative approaches its 10th anniversary. The programme's alumni have raised £47.4 million in follow-on investment, creating 43 companies. At its Year 9 Demo Day in February, 14 finalists presented innovations addressing challenges from deepfake detection to quantum security. The cohort marked progress in diversity, with 43% of project teams led by women, compared to just 17% female representation in the UK cyber workforce. Year 9 projects included SynapTrack, an anti-money laundering framework for blockchain systems from the University of Birmingham. Six alumni recently showcased their innovations at RSA Conference in San Francisco.

MEM Magazine
Mar 26th, 2026
Wienerberger secures funding for world's first commercial-scale hydrogen-fired brick kiln

Wienerberger UK & Ireland has secured government funding through the Industrial Energy Transformation Fund to convert its Denton brickworks to run on 100% green hydrogen, creating the world's first commercial-scale hydrogen-fired brick plant. The £6 million programme will retrofit two tunnel kilns, replacing 224 natural gas burners whilst maintaining existing kiln structures. Hydrogen will be supplied under a 15-year agreement with Trafford Green Hydrogen, developed by Carlton Power and Schroders Greencoat. One kiln is targeted for full operation by autumn 2027, with complete transition across the site commencing in autumn 2028. The conversion is expected to reduce CO₂ emissions by over 11,600 tonnes annually, equivalent to 9% of Wienerberger Limited's Scope 1 and 2 emissions. Testing confirmed the switch will not affect brick quality or performance.

The Associated Press
Mar 24th, 2026
Unilever and UK government back Kenya-India waste tech partnership to automate recycling

Kenyan waste management enterprise TakaTaka Ni Mali and India-based TrashCon have partnered to modernise Kenya's circular economy infrastructure through decentralised waste segregation technology. The collaboration was facilitated by TRANSFORM, an impact accelerator led by Unilever, the UK Government's FCDO, and EY. The partnership addresses implementation challenges of Kenya's Sustainable Waste Management Act (2022), which requires household waste separation. TrashCon's TrashBot technology automatically separates wet organic material from dry recyclables, creating safer conditions for waste workers whilst improving recovery rates. Urban waste collection in Kenya currently reaches only 20-30%. TakaTaka Ni Mali will serve as local reseller for TrashBot, supporting installation and maintenance whilst deploying its Ecomali digital traceability platform. The first TrashBot model will be showcased at Kenya International Investment Conference from 25-27 March, with two additional machines planned.

INACTIVE