Chief Information Security Officer
CurrentIn my current role I have overall responsibility for IT security across Rightmove Group Ltd - covering all technology domains (including the website and also the systems supporting the organisation’s business operations).My main achievements during my time in this role have included:● Defining the security posture and standards for the whole organisation ● Building an IT Security Team in an environment that previously did not have one and building a ‘brand’ internally that stakeholders across the company have grown to value and trust.● Leading the response to cyber security incidents – including co-ordinating technical response activities across internal IT teams and our retained third-party Incident Response (IR) partners, as well as advising internal stakeholders and senior management on potential implications.● Building relationships, and collaborating closely, with Rightmove’s Legal, Compliance, Supplier Management and Risk teams on all matters relating to Information Security and Data Protection.● Advising on technical controls to protect the Rightmove website and corporate IT estates.● Selecting and onboarding managed service providers for 24*7 SIEM / SOC coverage (for both the website hosting and corporate estates), and managed Endpoint Detection and Response (EDR).● Defining security standards for the Software Development Lifecycle (SDLC) - as well as providing developer education on secure software development.● Defining security requirements for a major replatforming of the website to a cloud-based hosting platform.● Leading projects to attain Cyber Essentials Plus, PCI-DSS and FCA compliance.● Planning various third-party assurance activities (penetration test, maturity assessments, audits etc.)● Educating the Rightmove board and Audit Committee on various aspects of cyber security – from demystifying some of the technical aspects to explaining the controls we have in place and projects that are in progress.