At Yeo Valley, we're about more than just making great food – we're here to Nurture & Nourish People & Planet by Making Great Food the Right Way. Forever. As a co-owned business, we invest in our people, encourage growth, and believe in doing things properly.
To lead Yeo Valley’s Cyber and Information Security function — ensuring our systems, data, and people remain secure while enabling the business to operate efficiently and confidently.
You’ll own and deliver the organisation’s cyber and information security strategy, manage the protection and monitoring of our technology estate, and embed a strong culture of security awareness across all teams. Working closely with IT, data, and operational leaders, you’ll ensure our defences are robust, risks are managed proactively, and Yeo Valley remains compliant with all relevant standards and regulations.
Your responsibilities:
- Design, own and lead the Cyber and Information Security strategy, aligning it to Yeo Valley’s wider business and IT objectives.
- Design, implement, and manage security controls, processes, and technologies that protect the confidentiality, integrity, and availability of information assets.
- Own the Information Security Management System (ISMS), ensuring compliance with relevant frameworks as deemed appropriate.
- Oversee incident response and threat management, leading investigations and coordinating with IT and external partners to contain, resolve, and learn from security incidents.
- Maintain proactive awareness of the external threat landscape, staying informed on emerging risks, vulnerabilities, and trends. Translate this intelligence into actionable improvements to strengthen Yeo Valley’s defences.
- Monitor and report on security posture, using metrics and dashboards to inform the business and executive team of risk levels, improvements, and vulnerabilities.
- Define and own the vulnerability management process, ensuring regular assessments, patching, and remediation of security weaknesses across the estate.
- Lead supplier assurance and third-party risk management, ensuring external partners meet Yeo Valley’s security requirements.
- Work closely with IT infrastructure and delivery teams to ensure new systems, applications, and solutions are secure by design.
- Create and embed a culture of security awareness, running training, communications, and engagement programmes to upskill colleagues.
- Support business continuity and disaster recovery planning, ensuring security requirements are embedded in wider IT resilience activities. Coach and enable the Cyber Security Engineer to contribute to develop the business continuity plan for cyber incidents.