Define and own the overall cybersecurity strategy and roadmap for the business
Establish a security-first culture across engineering and business teams
Act as the primary security authority and advisor to senior leadership
Report on security risks and posture to executive leadership and the board
Build and develop a small but high-performing security team
Own and maintain ISO 27001 and SOC 2 compliance programmes
Develop and maintain security policies, standards, and procedures
Maintain the enterprise risk register and ensure mitigation strategies are in place
Oversee cloud security across AWS and Azure environments and SaaS application security
Implement and improve security monitoring, detection, and response capabilities
Requirements
Proven, senior-level experience in Information Security
Track record of building and maturing security functions in a SaaS or cloud-native environment
Deep practical knowledge of ISO 27001, SOC 2, NIST CSF, or similar frameworks
Strong understanding of cloud security principles, ideally across AWS and Azure
Excellent written and verbal communication skills — able to articulate complex security concepts clearly to technical teams, C-level executives, and external clients
Relevant security certifications such as CISSP, CISM, CRISC, or CISA
Familiarity with GDPR and its operational requirements