United Kingdom · Technical roles · Director/VP (16-20 years)

Director of Information Security

Here is the whole job, in plain words. What it is, a real day, what you decide, how you're judged, how people get here and where they go next. Then the part no course gives you: twelve AI tutors who learn your work.

  • Experience bandDirector/VP (16-20 years)
  • Direct reports5-10 reports
  • Reports toChief Information Security Officer (CISO)
  • UK framework levelUsually a director, accountable for a division and its numbers

Also advertised as Head of Cyber Security · VP, Security Operations · Chief Security Architect · Information Security Director

Built on an analysis of 43,079 real UK job descriptions · grounded in qualifications employers recognise

Start with a free Future Fluency check, tuned to Director of Information Security

Ten quick questions, one per Future Fluency, asked against this role rather than a generic one. About five minutes, and no card.

Start the check, free

1What this role really is

This role isn't just about managing a team; it's about shaping our entire cybersecurity defence. You'll be the one translating complex threats into clear business risks for the executive team, making sure our security strategy actually protects what matters most. Honestly, it's a high-stakes game where your decisions directly impact our company's reputation and bottom line.

2What you'd actually use

The tools this job runs on, and how well you'd need to know each one.

Splunk / IBM QRadar / Microsoft Sentinel (SIEM)Strategic

Evaluating SIEM effectiveness, managing data ingestion costs, aligning SIEM capabilities with business risk, and reviewing high-level dashboards for strategic insights.

CrowdStrike Falcon / SentinelOne / Carbon Black (EDR)Strategic

Defining enterprise endpoint security strategy, negotiating contracts, and reporting on endpoint compliance and threat posture to leadership.

Tenable.io / Qualys / Rapid7 InsightVM (Vulnerability Management)Strategic

Owning the enterprise vulnerability management programme, setting risk appetite, and presenting risk exposure trends to the board.

Wiz / Palo Alto Prisma Cloud / AWS Security Hub (CSPM)Strategic

Governing the multi-cloud security architecture, setting cloud security standards, and being accountable for cloud compliance (e.g., PCI-DSS) across all cloud environments.

ServiceNow (SecOps/GRC) / Archer GRCStrategic

Managing the entire GRC platform, defining risk control frameworks, and using the system to report on enterprise risk to the board and regulators.

Recorded Future / Mandiant Advantage (TIP)Strategic

Selecting and managing TIP vendors, aligning intelligence requirements with business strategy, and briefing executives on the evolving threat landscape.

3What you get to decide, and how that grows

Power in a job isn't your title. It's what you're allowed to decide. Here's how it grows as you move up.

The choiceComing inWhere you are nowThe step above
Strategic Programme DirectionN/AN/AProposes strategic initiatives to Lead Security Engineer for review and input.
Budget Allocation & Vendor SelectionN/AN/ARecommends specific tools or services for project-level needs (e.g., a new penetration testing vendor).
Major Incident Response & CommunicationFollows defined runbooks and escalates immediately.Independently executes containment actions for routine incidents, escalates complex ones.Leads technical response for complex incidents, makes real-time tactical decisions, and recommends communication points to management.
Hiring & Performance ManagementN/AN/AProvides input on technical assessments for junior hires.

4How you'll be judged

The scoreboard, honestly: the hard targets, how often each one is actually looked at, and the quiet human signals that never make it onto a dashboard.

Mean Time to Detect (MTTD) Critical Incidents
The average time it takes from an incident occurring to our security team identifying it.
Target · Reduce by 25% year-over-year (e.g., from 4 hours to 3 hours)

After implementing new detection rules and tuning the SIEM, our average MTTD for ransomware-related incidents dropped from 6 hours to 4.5 hours in Q2.

Mean Time to Contain (MTTC) Critical Incidents
The average time it takes to stop an attacker's activity and prevent further damage after detection.
Target · Reduce by 20% year-over-year (e.g., from 2 hours to 1.6 hours)

Through improved SOAR playbooks and EDR automation, we contained a critical credential theft incident in 55 minutes, down from a previous average of 90 minutes.

Critical Vulnerability Remediation Rate
The percentage of critical vulnerabilities (CVSS 9.0+) that are remediated or mitigated within their defined SLA (e.g., 7 days).
Target · Maintain >95% adherence to critical vulnerability SLAs

In the last quarter, we had 45 critical vulnerabilities identified; 43 were resolved within 7 days, giving us a 95.5% remediation rate.

Security Programme Maturity Score (NIST CSF)
Our overall maturity level against the NIST Cybersecurity Framework across all five functions (Identify, Protect, Detect, Respond, Recover).
Target · Improve from 'Tier 3: Repeatable' to 'Tier 4: Adaptive' within 18 months

Our last assessment showed us strong in 'Protect' but weaker in 'Recover'. You'd be expected to drive initiatives to boost that 'Recover' score, perhaps through more frequent disaster recovery drills.

Executive & Board Confidence
The level of trust and confidence that senior leadership and the Board have in our cybersecurity capabilities and your ability to articulate risk.
  • You're proactively invited to strategic planning sessions, your input is sought on major business initiatives, and there are no surprises during Board-level security updates. They trust your judgment on security investments and risk acceptance.
Cross-Functional Collaboration & Influence
Your ability to work effectively with other departments (e.g., Engineering, Product, Legal) to embed security into their processes and gain their buy-in.
  • Security requirements are integrated early into product development lifecycles, engineering teams consult you before deploying new infrastructure, and you're seen as a partner, not just 'the department of no'. Feedback from peer directors is consistently positive about your collaborative approach.
Team Development & Retention
The growth and engagement of your direct reports and the wider security team.
  • Your team members are actively pursuing professional development, internal promotions are common, and regrettable attrition is low. You're known for developing talent and fostering a positive, high-performing culture.
Strategic Vision & Roadmap Execution
The clarity and effectiveness of the cybersecurity roadmap you develop and your ability to deliver on its key initiatives.
  • The security roadmap is well-defined, aligned with business objectives, and consistently reviewed and updated. Key projects (e.g., new EDR deployment, cloud security overhaul) are delivered on time and within budget, with clear benefits realised.

5Would you like it

The honest version. What people enjoy, and what grinds them down.

What people enjoy
Building a Robust Defence

You'll spend your days reviewing architectural designs, approving new security controls, and strategising how to outmanoeuvre sophisticated adversaries. You get a real kick out of seeing our defences mature and knowing you've made the organisation safer.

Successfully leading the deployment of a new EDR solution across 10,000 endpoints, significantly reducing dwell time for advanced threats.

Leading and Developing Talent

You'll be mentoring your managers and lead engineers, helping them grow their careers, and building a high-performing security team. You'll take pride in seeing your team members excel and take on more responsibility.

Promoting two senior analysts into management roles within your team, seeing them thrive in their new positions.

Influencing Strategic Direction

You'll be working closely with the CISO and other executive leaders, contributing to the overall company strategy by ensuring security is a core consideration, not an afterthought. You'll enjoy seeing your strategic input shape major business decisions.

Convincing the Board to invest an additional £1M in cloud security tooling after presenting a clear risk assessment and ROI.

What frustrates people
  • **Budget Battles:** Constantly having to justify significant security investments to executives who see security as a cost centre, not a business enabler. It's a never-ending fight for resources.
  • **Legacy Systems:** Inheriting a sprawling estate of old systems that are critical to the business but a nightmare to secure, requiring creative (and often expensive) mitigation strategies.
  • **Talent Shortage:** The struggle to find and retain top-tier cybersecurity talent in a highly competitive market, meaning you're often stretched thin.
  • **Executive Disconnect:** Presenting a critical risk to the Board, only for them to deprioritise it based on short-term revenue goals, leaving you feeling frustrated and exposed.
  • **Regulatory Treadmill:** The constant churn of new regulations and compliance requirements, demanding significant effort to adapt and prove adherence, often without clear security benefits.
  • **The Inevitable Breach:** Knowing that despite all your efforts, a breach is statistically inevitable, and you'll be the one to lead the response and face the fallout.
What this role does not give you
  • A purely hands-on, individual contributor technical role.
  • A quiet, predictable 9-to-5 job with no urgent crises.
  • A role where you can avoid difficult conversations or political navigation.
  • Complete autonomy without significant stakeholder engagement or justification.
  • The luxury of always having unlimited budget or resources for every security initiative.

6Who you work with

You're directly accountable for the effectiveness of our security operations, incident response, and threat management capabilities across the entire organisation. Your decisions shape our security posture, influence our risk appetite, and directly impact our ability to operate securely and compliantly. Frankly, without strong leadership here, everything else is at risk.

Inside the business
  • Chief Information Security Officer (CISO)
  • CTO and Engineering Leadership
  • Head of Legal & Compliance
  • Head of Internal Audit
  • Product Leadership
  • Finance Director
Outside the business
  • External Auditors (e.g., PwC, Deloitte)
  • Regulatory Bodies (e.g., ICO, FCA)
  • Key Security Vendors (e.g., Splunk, CrowdStrike)
  • Industry Peer Groups and Information Sharing Forums
  • Incident Response Retainer Firms

7What you need before you start

Not a wish list. The things you would be expected to already have.

  • Proven track record of leading and managing diverse cybersecurity teams (5+ direct reports, including managers) in a complex enterprise environment.
  • Extensive experience (10+ years) across multiple domains of cybersecurity, including security operations, incident response, vulnerability management, and cloud security.
  • Demonstrable experience developing and executing cybersecurity strategies and roadmaps that align with business objectives.
  • Strong financial acumen, including experience managing significant departmental budgets (multi-million £) and negotiating with vendors.
  • Experience presenting to and influencing executive leadership and Board-level stakeholders on cybersecurity risks and investments.
  • Deep understanding of common security frameworks (e.g., NIST CSF, ISO 27001) and regulatory requirements (e.g., GDPR).

8What to practise next

Where the job is going, and what to do about it starting this week.

Advanced Supply Chain Security & Software Bill of Materials (SBOM)

Recent attacks (e.g., SolarWinds) have highlighted the critical vulnerability of the software supply chain. You'll need to develop strategies to secure our entire software ecosystem, from third-party components to internal development practices, using tools like SBOMs to gain visibility.

Software Bill of Materials (SBOM) · SLSA Framework · Third-Party Risk Management (TPRM) Automation

  • This quarter: Review our current third-party risk management programme for software vendors.
  • Next 6 months: Pilot an SBOM generation tool for a critical internal application.
  • Next year: Develop a strategy for integrating SBOMs into our procurement and development processes.
  • Ongoing: Engage with industry groups on supply chain security best practices.

Quick win: Start by requiring SBOMs from new software vendors and incorporating supply chain security questions into your vendor assessment questionnaires.

Zero Trust Architecture (ZTA) Implementation & Optimisation

The perimeter-based security model is dead. Zero Trust is the future, but implementing it across a complex enterprise is a multi-year journey. You'll need to lead this transformation, moving beyond conceptual understanding to practical, phased deployment and continuous optimisation.

Identity-Centric Security · Micro-segmentation · Continuous Verification

  • This quarter: Review our current ZTA maturity against industry benchmarks.
  • Next 6 months: Develop a phased implementation plan for ZTA across a critical business unit.
  • Next year: Oversee the deployment of key ZTA components (e.g., next-gen MFA, micro-segmentation).
  • Ongoing: Stay current with ZTA vendor capabilities and evolving best practices.

Quick win: Identify a small, high-risk application or team and pilot a Zero Trust approach for their access, demonstrating tangible security benefits.

9Staying current once you are in

What people here do to keep up
  • Regular attendance at industry conferences (e.g., RSA Conference, Black Hat Europe, Infosecurity Europe) to stay abreast of emerging threats and technologies.
  • Active participation in industry peer groups and information sharing forums (e.g., ISACs, local CISO roundtables) to share insights and best practices.
  • Continuous learning through online courses, webinars, and certifications in areas like AI/ML security, quantum cryptography, or advanced cloud security.
  • Mentoring junior security professionals to give back to the community and reinforce your own knowledge.

10How the AI economy is changing work like this

Before we ask anything of you, here's what we can already say about AI and work of this kind:

The new skill this role is being asked for: AI Ethics & Governance for Security

As AI becomes more integral to both offensive and defensive cybersecurity, understanding its ethical implications—bias in detection, privacy concerns with data processing, and the 'explainability' of AI decisions—is becoming critical. You'll need to govern its use responsibly.

We'll only ever tell you what we can actually back up. No hype, no scare tactics.

Your PlanIllustration

Built for Director of Information Security

5 units that map to this job, from the qualifications that cover it.

  1. Incident Response, Investigations and ForensicsQualifi Ltd · covers 4 of 8 standardsLevel 5
  2. Incident response and disaster recoveryNCFE · covers 4 of 8 standardsLevel 3
  3. Incident Response and ManagementSFJ Awards · covers 4 of 8 standardsLevel 4
  4. Carrying out Information Security Incident Management activitiesCity and Guilds of London Institute · covers 3 of 8 standardsLevel 3
  5. Investigating Information Security incidentsCity and Guilds of London Institute · covers 2 of 8 standardsLevel 4
These are the real units behind this job, in the order they rank for it. Nothing here is marked done, because this plan has not been started by anyone yet. Yours would fill in as you go.

The rising capability

Zavmo analysis

What's rising in its place

This is where the work is heading, and the higher pay with it. Get fluent here and the shift stops being a threat and starts being your edge.

AI Ethics & Governance for Security

As AI becomes more integral to both offensive and defensive cybersecurity, understanding its ethical implications—bias in detection, privacy concerns with data processing, and the 'explainability' of AI decisions—is becoming critical. You'll need to govern its use responsibly.

  • AI Explainability (XAI)
  • Data Privacy in AI Models
  • Bias in AI Detection
  • Adversarial AI

Quantum-Resistant Cryptography Strategy

Quantum computing, while still nascent, poses a fundamental threat to current cryptographic standards. As a Director, you'll need to start planning for a 'post-quantum' world, assessing our cryptographic inventory and developing a migration strategy before it becomes a crisis.

  • Shor's Algorithm & Grover's Algorithm
  • Post-Quantum Cryptography (PQC)
  • Cryptographic Agility
  • Cryptographic Inventory & Discovery

What you’ll use

Skills this role draws on

Technical

  • MITRE ATT&CK Framework (Strategic Application)
  • NIST Cybersecurity Framework (Programme Maturity)
  • Incident Response Lifecycle (Strategic Oversight)
  • Threat Modelling (Architectural & Business Context)
  • Cloud Security Architecture & Governance
  • Data Protection & Privacy Regulations (GDPR, PECR)

The pathway

How you actually get there, here

How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.

  1. 1

    From Security Manager (L5)

    3-5 years as a Security Manager

    Skills to master

    • Expanding leadership scope beyond a single domain, strategic budget management, executive communication, and cross-functional influence.

    You're ready to move on when

    • Successfully led a major security initiative from conception to completion.
    • Consistently delivered on departmental objectives and managed a high-performing team.
    • Demonstrated ability to present complex technical topics to non-technical senior leaders.
    • Managed a significant budget (£500K+) and made strategic vendor decisions.
  2. 2

    From Principal Security Architect (L5)

    3-5 years as a Principal Architect

    Skills to master

    • Shifting from deep technical design to broader programme management, team leadership, and executive stakeholder engagement. Moving from 'how' to 'what' and 'why'.

    You're ready to move on when

    • Designed and oversaw the implementation of enterprise-wide security architectures.
    • Mentored and guided other architects and engineers on complex security challenges.
    • Demonstrated ability to translate architectural decisions into business risk and opportunity.
    • Proven track record of influencing technical direction across multiple teams.
  3. 3

    From Senior Consultant (Big Four / Specialist Firm)

    5-7 years at Senior Manager/Director level in consultancy

    Skills to master

    • Transitioning from client-facing advisory to direct ownership and execution of an internal security programme, including building and managing internal teams. Getting hands-on with the actual problems, not just advising.

    You're ready to move on when

    • Led large-scale security transformation programmes for multiple clients.
    • Managed significant client engagements and delivered measurable value.
    • Developed strong client relationships and influenced strategic security decisions.
    • Experience with internal team management and operational accountability.

11Where this role leads

The long view:This role is a launchpad for significant executive leadership within our organisation or across the broader industry. We're looking for someone with the ambition and capability to not just manage, but to truly lead and transform our cybersecurity capabilities for years to come.

Pay & demand

The figure is the median for full-time employees in the ONS occupation this job title codes to (Information technology directors), from the April 2025 survey — about six months old when published, as ASHE always is. It is that occupation's middle, not this role's. Half earn more.

The ten Future Fluencies

Zavmo analysis

The credential is what you can do today. These are what keep you valuable.

A qualification proves you can do the job as it's defined today. These ten are what decide whether you're still the obvious person for it in five years. They're the capabilities employers are now writing into senior roles faster than people are learning them. Zavmo weaves them through whatever you study, so you come out with both: the credential and the fluency.

The highlighted ones are the Fluencies your role leans on hardest, from how Director of Information Security is actually changing. In about two minutes, the free confidence check asks where you stand on each of the ten. That's the whole check, and it's what makes the plan yours rather than generic.

12The team that's yours

No two people are taught the same way. This is one-to-one, not one-to-many.

Zavmo is a hyper-personalised AI learning platform. Twelve virtual tutors, each with a different way of teaching, and one orchestration agent that picks the right one for the moment. So every single lesson is shaped around you, your role, and the way you learn. Not a course everyone sits through. A conversation built for you, and no one else.

…and nine more, matched to you after your first chat. Meet all twelve

13What it feels like

A conversation, not a course

Because your tutor knows your role, your projects and your last session, learning sounds like this. And it's different for every single person:

Incident Response, Investigations and ForensicsLevel 5

Applied to your work in Director of Information Security

This unit aims to equip learners with an understanding of incident response as a business function, including the operation of Computer Emergency Response Teams (CERTs) and aligned task forces for business continuity, disaster recovery, and crisis management. Learners will also understand how major computer incidents are formally investigated, including evidence gathering and analysis, and the relevant legal and ethical considerations.

How the thinking builds
  1. Remember
  2. Understand
  3. Apply
  4. Analyse
  5. Evaluate
  6. Create
An illustration of a Zavmo lesson, built from this role’s own route. The unit, its objective and every criterion above are the awarding body’s own words, not an example.

One to one, not one to many

No two people run this the same way

A course is written once and handed to everyone. This is assembled around you, and keeps changing as it learns you. Five things it reads, and what each one changes.

  1. Your actual work Every lesson is taught against a live piece of your own work, not a worked example from a textbook.
  2. What you already know The first conversation finds your starting point, so you skip what you can already do and spend the time on what you cannot.
  3. The conditions you learn under Not a learning-styles quiz. The evidence does not support those. The dimensions the research does back, read once and used to shape the plan.
  4. How far you got last time It picks up mid-thought. The tutor knows what you said, what you struggled with, and what it asked you to try.
  5. Which tutor suits the moment Twelve of them, each for a different kind of thinking. The one who walks you through a first idea is not the one who stress-tests it.

See how you learn, free. Eight questions, no sign-up. A directional taster; the diagnostic inside Zavmo goes deeper and keeps adapting.

DemonstrateIllustration

Evidenced on your work in Director of Information Security

You do not finish by watching something. You finish by showing it on the work you already do, against the measures this job is judged on.

  • Mean Time to Detect (MTTD) Critical IncidentsThe average time it takes from an incident occurring to our security team identifying it.After implementing new detection rules and tuning the SIEM, our average MTTD for ransomware-related incidents dropped from 6 hours to 4.5 hours in Q2.Reduce by 25% year-over-year (e.g., from 4 hours to 3 hours)
  • Mean Time to Contain (MTTC) Critical IncidentsThe average time it takes to stop an attacker's activity and prevent further damage after detection.Through improved SOAR playbooks and EDR automation, we contained a critical credential theft incident in 55 minutes, down from a previous average of 90 minutes.Reduce by 20% year-over-year (e.g., from 2 hours to 1.6 hours)
  • Critical Vulnerability Remediation RateThe percentage of critical vulnerabilities (CVSS 9.0+) that are remediated or mitigated within their defined SLA (e.g., 7 days).In the last quarter, we had 45 critical vulnerabilities identified; 43 were resolved within 7 days, giving us a 95.5% remediation rate.Maintain >95% adherence to critical vulnerability SLAs
  • Security Programme Maturity Score (NIST CSF)Our overall maturity level against the NIST Cybersecurity Framework across all five functions (Identify, Protect, Detect, Respond, Recover).Our last assessment showed us strong in 'Protect' but weaker in 'Recover'. You'd be expected to drive initiatives to boost that 'Recover' score, perhaps through more frequent disaster recovery drills.Improve from 'Tier 3: Repeatable' to 'Tier 4: Adaptive' within 18 months
These are this job's own measures, with its own targets. Nothing is marked evidenced, because nobody has started this yet. Yours would fill in from the work you bring.

Your passport

This isn't a certificate you file away. It's a passport to the life you're designing.

Every credit you earn and every fluency you build adds up: evidence where it counts, carried with you. Zavmo keeps the map: where you are, where you're heading, and the next step, at your pace, around your life. From Director of Information Security to Chief Information Security Officer (CISO), and whatever you decide comes after.

Level 7 · in progressAI Fluency→ Chief Information Security Officer (CISO)→ your design
Where this takes you

This role is a launchpad for significant executive leadership within our organisation or across the broader industry. We're looking for someone with the ambition and capability to not just manage, but to truly lead and transform our cybersecurity capabilities for years to come.

See Your Progress GrowIllustration
Director of Information Security
  • MITRE ATT&CK Framework (Strategic Application)
  • NIST Cybersecurity Framework (Programme Maturity)
  • Incident Response Lifecycle (Strategic Oversight)
  • Threat Modelling (Architectural & Business Context)
  • Cloud Security Architecture & Governance
  • Data Protection & Privacy Regulations (GDPR, PECR)
This is your Mind Palace on learn.zavmo.ai. Every skill above comes from this role's own record, not an example borrowed from another job. A node lights up when you evidence it, and what you build stays yours between jobs. That is the part a course cannot do.

14The detail, folded away

Everything else the record holds

The career branches in full, how AI is already showing up in the day-to-day, and the questions people ask about this job. Here when you want them, out of the way while you decide.

Where it leads next, rung by rung

Where it leads

The career path, and where it branches

Director of Information Security is a start, not a ceiling. Each step below asks for new skills and hands back more autonomy.

  1. Chief Information Security Officer (CISO)

    3-5 years as Director of Information Security

    Level 7 (C-Suite)

    • Enterprise Security Strategy: Defining the overarching 3-5 year security vision for the entire organisation.
    • Executive Leadership & Organisational Design: Building and leading a multi-functional security organisation, including other Directors and Managers.
    • External Representation: Acting as the public face of the company's security posture to media, regulators, and industry bodies.
Working with AI on the job

Working with AI

Where AI is starting to help

As a Director of Information Security, your time is precious. You're juggling strategy, team leadership, budget management, and crisis response. What if you could reclaim significant chunks of your week, not by working less, but by working smarter? That's where AI comes in.

We're not talking about replacing your strategic brain; we're talking about augmenting it. AI tools can handle the heavy lifting of data synthesis, report generation, and even some aspects of threat analysis, freeing you up to focus on the high-impact decisions only a human leader can make. Think of it as having a highly efficient, tireless assistant for your most time-consuming tasks.

Automated Board Report Drafting

Feed an AI model your raw security metrics, incident summaries, and strategic updates. It'll generate a comprehensive, executive-ready draft of your quarterly Board report, complete with key takeaways and risk summaries, saving you hours of writing and formatting. You then refine it, adding your strategic narrative.

Strategic Risk Trend Analysis

Use AI-powered analytics to sift through vast amounts of threat intelligence, vulnerability data, and industry reports. The AI can identify emerging risk patterns and potential impacts specific to our sector and technology stack, giving you a proactive edge in strategic planning and resource allocation. No more sifting through dozens of PDFs manually.

Security Programme Automation & Optimisation

Deploy AI-driven SOAR (Security Orchestration, Automation, and Response) platforms to automate complex security workflows, from alert triage to vulnerability remediation tracking. The AI optimises processes, identifies bottlenecks, and suggests improvements, allowing your team to focus on higher-value tasks and reducing operational overhead.

Policy & Compliance Query Assistant

Integrate an LLM with our internal security policies, compliance frameworks (e.g., GDPR, ISO 27001), and regulatory guidance. Your team, and even other departments, can then ask natural language questions and get instant, accurate answers, reducing the time spent on policy interpretation and compliance evidence gathering.

Common questions

Common questions

How do you become a Director of Information Security?

Common routes in include From Security Manager (L5) (3-5 years as a Security Manager), From Principal Security Architect (L5) (3-5 years as a Principal Architect) and From Senior Consultant (Big Four / Specialist Firm) (5-7 years at Senior Manager/Director level in consultancy). Times vary with prior experience.

Where can a Director of Information Security progress to?

This role can lead on to Chief Information Security Officer (CISO) (3-5 years as Director of Information Security), depending on the skills you build.

What level is a Director of Information Security in the UK?

This role aligns to RQF Level 7 on the UK framework, a guide to the depth of qualification it maps to, not a hard entry bar.

What new skills matter most for a Director of Information Security?

Increasingly, AI Ethics & Governance for Security and Quantum-Resistant Cryptography Strategy. These are the areas where the higher-paid, future-proof work is heading.

The honest bit

You’ve started things before

Most of them were built for a room full of people who aren’t you. A cohort moves on whether or not your week allowed it, and by the third week the thing you’re behind on becomes the reason you stop opening it.

There’s no cohort here, and no timetable to fall behind. Before anything starts, Zavmo asks when you’re sharpest and how long you can realistically sit down for, then builds the sessions around those answers. A bad fortnight changes your pace. It doesn’t put you behind.

And you only pay once you start learning. Searching and planning are free, and you can cancel any time — so the cost of finding out is an afternoon, not a year.

What it costs

Less than one coaching session. Every month.

A single career-coaching hour costs more than a month of this, and it ends when the hour does. Zavmo doesn't. It's £70 a month, about £2.30 a day, for a companion that knows a Director of Information Security, works on the job you actually do, and keeps going at your pace rather than a timetable's.

  • Searching and planning stay free. You only pay when you start learning.
  • Your credits are yours. Regulated, and they don't vanish when a subscription ends.
  • Cancel any time and billing stops. No notice period, no minimum term.

Your path, personalised

You have the map. Walking it is the part we do together.

This route runs to 8 national skill standards. That is a real journey.

Zavmo shapes a learning experience as unique as you are. It fits how you learn, your pace and the work you already do. Every step stays benchmarked to recognised national standards. That’s the plan for becoming a Director of Information Security: personal to you, and it still counts. The first steps are free.

Independent research finds well-designed intelligent tutoring performs nearly as well as one-to-one human tutoring: VanLehn (2011), Educational Psychologist.

A private tutor in the UK averages £35–40 an hour . Zavmo is £70/month.

A real plan on learn.zavmo.ai: Ofqual-regulated units, credits, and a three-month run at your own pace.
Start free No commitment. See your first steps free.

15Where to go from here

Other roles at Level 7

Same depth of qualification, different job. Useful if the work appeals but this particular role does not.

Other roles in Technical roles

Stay in the field you know and move sideways rather than up.

If you leave this industry

The skills you gain as a Director of Information Security are highly transferable across almost any industry, from finance and healthcare to technology and government. Every organisation needs strong cyber leadership, so your options are pretty wide open.

Not sure this is the right direction?

Work out what you actually want from work first, then come back and see which roles fit it. Takes about ten minutes.

This role profile is © 2026Growth Engineering Technologies Ltd. Built from UK occupational standards and regulated qualification data, and written for Zavmo.

You're not behind. You're right on time. The shift is only just beginning. Your role won't look the same in two years. Be the one who leads the change, not the one it happens to. Build my plan, free Here's the first ten minutes: a 2-minute confidence check → your personalised roadmap → meet the tutors matched to you. No card, cancel any time. No card. Build your plan, see your roadmap and meet the twelve tutors matched to you. All free. When you're ready to start learning, it's £70 a month, billed monthly. Cancel any time and billing stops.