Director of Security & Compliance

Director of Security & Compliance | London | 110-140k + Benefits A high-profile organisation with a complex international operating environment is looking for a Director of Security & Compliance to take ownership of its security, governance, risk and compliance function as it enters its next phase of maturity.This is a newly created senior leadership position, reporting directly to the CTO. With Cyber Essentials Plus already achieved and a 24/7 outsourced SOC in place, the organisation is now focused on achieving ISO 27001 certification, strengthening its governance and compliance framework, and ensuring the secure adoption of a rapidly expanding enterprise AI estate.You'll become the senior accountable owner for security certifications, organisational risk, business continuity, AI security and governance, and information security - acting as the authoritative voice on cyber and security matters across the organisation.Location: London, hybrid (2-3 days onsite) Package: 110,000-140,000 + excellent benefits Key Responsibilities: Own security monitoring, incident response and security tooling, working closely with the outsourced SOCLine manage the IT Security Engineer and lead the organisation-wide security awareness programmeDefine identity, access and authentication standards, including RBAC, MFA and SSOOwn the IT governance framework and regulatory/standards compliance postureLead the programme to achieve ISO 27001 certification, including defining and managing scopeOwn the central digital and data security risk register in partnership with Legal & RiskDevelop and maintain data classification, retention and GDPR operating frameworksOwn disaster recovery and business continuity planning, including RTO/RPO requirements for critical systemsLead security governance across the enterprise AI estate, including access controls, data protection, prompt injection, jailbreaking and third-party AI riskOwn and develop the organisation's Responsible Use Policy for AILead the DevSecOps security function, including secrets management, vulnerability scanning, pipeline security and workload protectionOwn third-party security assessments and ongoing supplier/vendor security monitoringDevelop and mature the organisation's wider security strategy, policies and control environmentWhat You'll Bring: Significant senior leadership experience across security, cyber, governance, risk and complianceExperience operating within a mid-to-large, complex or internationally distributed organisationDeep, demonstrable ISO 27001 expertise, ideally having led or owned a successful certification programmeStrong working knowledge of SOC 2, NIST CSF and other recognised security frameworksStrong technical understanding across SIEM, EDR, IAM, vulnerability management and DevSecOpsProven GDPR and data protection experience, ideally within a multi-jurisdiction environmentStrong understanding of AI security and governance, including prompt injection, model risk and third-party AI vendor riskExperience establishing and managing enterprise-level security and risk registersExcellent executive stakeholder management and communication skillsA pragmatic approach to security, with the ability to balance risk management with business deliveryExperience managing security professionals and outsourced security partnersThe credibility to operate as the organisation's senior security authority while remaining commercially and strategically focusedCertifications: One or more of the following certifications is required:CISSP | CISM | ISO 27001 Lead Implementer | CIPP/E | CIPM | CRISC | CGEIT | CCSP | AIGPPlease note: candidates must have the legal right to work in the UK.Oscar Associates (UK) Limited is acting as an Employment Agency in relation to this vacancy.To understand more about what we do with your data please review our privacy policy in the privacy section of the Oscar website.

Job Details

Company
Oscar
Location
London, UK
Hybrid / Remote Options
Posted