definelycareers - Senior Information Security Officer
Requirements
• Proven experience in information security within a SaaS or product led environment • Strong track record of delivering ISO 27001, SOC 2, or similar certifications, with interest in ISO/IEC 42001 AI standards • Experience with compliance tooling such as Drata and working with ISO auditors, ideally in the UK • Solid understanding of GDPR and data protection best practices • Deep knowledge of secure SDLC, threat modelling, and securing AI and LLM based systems • Strong cloud security expertise across Azure or AWS, including access control, secrets management, and incident response • Experience running IT operations in a scaling business, including device management, SaaS tooling, and identity systems such as SSO and IAM • Excellent communication skills, with the ability to work cross functionally and manage customer security and due diligence processes • Relevant certifications such as CISSP, CISM, CCSK, or ISO 27001 Lead Auditor, and a degree in a related field • What we can offer you: • 💰 Competitive salary & annual bonus based on performance • 📈 Equity in Definely • 🎉 Quarterly team socials + holiday parties • 🏠 Hybrid working + 🌍 1 month “work from anywhere” • 🏖️ 25 days holiday + bank holidays • 🎂 Take your birthday off • 📚 £750 annual learning & development budget • 🩺 Private healthcare (incl. dental & optical) • ❤️🩹 Life assurance + income protection • 👶 Enhanced parental leave + Workplace Nursery salary sacrifice scheme
Responsibilities
• Governance & Compliance • Own and evolve Definely’s Information Security Management System (ISMS). • Lead ISO 27001 and SOC 2 Type II audits, ensuring controls remain effective. • Drive readiness for ISO/IEC 42001 AI certification • Apply prior experience successfully obtaining ISO and SOC certifications • Manage customer due diligence requests and run Definely’s SafeBase-powered Trust Center; streamline customer security questionnaires, DPAs, and RFP security sections. • Product & Engineering Partnership • Embed secure SDLC practices across product teams, from design to release. • Perform threat modelling, define non-functional security requirements, and review designs for security impact. • Guide security considerations in our AI/LLM-enabled products. • Risk & Incident Management • Own the company-wide incident response plan and lead tabletop exercises. • Perform ongoing risk assessments, vendor security reviews, and DPIAs. • Ensure strong access management, secrets management, and cloud security hygiene. • IT Support & Operations • Provide day-to-day IT support for employees, including device management, troubleshooting, and access provisioning. • Support onboarding and offboarding processes to ensure secure and efficient setup of accounts, devices, and permissions. • Help scale internal IT processes and tooling as the company grows. • Enablement & Communication • Deliver security training and awareness across the company. • Communicate risks and incidents clearly to technical and non-technical stakeholders.
Benefits
• £65K – £85K • Offers Equity • Offers Bonus • Up to 16% of base salary as a performance related bonus • Upload your resume here to autofill key application fields. • Drop your resume here! • Parsing your resume. Autofilling key fields... • Please note: we’ve introduced application limits across all roles to help us keep our process fair and focused for every candidate. • Please note: • Candidates may submit one application within any 90 day period across any of our open roles. • We really appreciate everyone’s interest in joining Definely and this approach allows us to give each application the time and attention it deserves. • Please provide your full name • Please attach your CV • or drag and drop here • Please give us your salary expectations in your local currency • We require a linked professional profile to verify applicant authenticity and prevent AI-generated or fake applications. This helps ensure fairness, transparency, and integrity in our hiring process. • If yes, please let us know what would be helpful. We are committed to running an inclusive and accessible hiring process. This information will be treated confidentially and will only be used to support your application. • I prefer not to answer • Another Gender Identity • Heterosexual / straight • Asian or Asian American • Black or African American • Hispanic or Latine • Indigenous or Native American • Native Hawaiian or Other Pacific Islander • Person with disability • Refugee or immigrant • None of the above • Definely may use Artificial Intelligence with this application. Learn more.
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT