Information Security Team Lead
What you'll be doing:
-
Maintain an active risk register that directly influences business decisions, conduct practical risk assessments, and keep the Board and leadership candidly informed on our true security posture.
-
Oversee ISO 27001, DSPT, and Cyber Essentials Plus. Define pragmatic, engineer-friendly policies, manage third-party/vendor risks, and establish strict AI governance frameworks for sensitive patient data.
-
Lead security incidents end-to-end (coordination, communication, regulatory reporting, and blameless post-mortems). Improve threat detection, logging, and BC/DR plans while engineering handles technical containment.
-
Execute our security roadmap across IAM, DLP, zero-trust, email, and endpoint security.
-
Build a pragmatic security culture where teams seek your advice early, balancing security and usability for engineers, clinicians, and executives alike.
What you'll need:
-
Experience owning end-to-end information security in a company of a similar scale, including running an ISMS and holding ISO 27001 or Cyber Essentials Plus.
-
Hands-on experience protecting sensitive personal data under UK GDPR (or equivalent) and navigating vendor/AI supply chain risks.
-
A strong technical foundation across core IT security domains (IAM, DLP, endpoint, network, and SaaS) so you can constructively challenge architectural designs with engineers.
-
Direct experience leading real security incidents, managing regulatory notifications, and conducting effective post-incident reviews.
-
The ability to size controls to actual risk, hold a firm line on patient safety, and help the business move fast everywhere else.
It's a bonus if you have:
- Prior experience in HealthTech, healthcare, or FinTech, and hands-on experience crafting AI governance frameworks.
