Director of Security & Compliance

Oscar Technology · HV Engineer

£110,000 - £140,000 per annum

London, Greater LondonPermanentFull-timeOn-site
Apply now
Closing date
29 Aug 2026
Posted
10d ago
Specialism
HV Engineer
Sector
Energy & Renewables
Reference
reed-57229193

This advert was published by Reed and is shown here for reference. BoQQs did not take this listing directly from the employer. View the original on Reed

Director of Security & Compliance | London | £110-140k + Benefits

A high-profile organisation with a complex international operating environment is looking for a Director of Security & Compliance to take ownership of its security, governance, risk and compliance function as it enters its next phase of maturity.

This is a newly created senior leadership position, reporting directly to the CTO. With Cyber Essentials Plus already achieved and a 24/7 outsourced SOC in place, the organisation is now focused on achieving ISO 27001 certification, strengthening its governance and compliance framework, and ensuring the secure adoption of a rapidly expanding enterprise AI estate.

You'll become the senior accountable owner for security certifications, organisational risk, business continuity, AI security and governance, and information security - acting as the authoritative voice on cyber and security matters across the organisation.


Location: London, hybrid (2-3 days onsite)

Package: £ + excellent benefits


Key Responsibilities:

  • Own security monitoring, incident response and security tooling, working closely with the outsourced SOC
  • Line manage the IT Security Engineer and lead the organisation-wide security awareness programme
  • Define identity, access and authentication standards, including RBAC, MFA and SSO
  • Own the IT governance framework and regulatory/standards compliance posture
  • Lead the programme to achieve ISO 27001 certification, including defining and managing scope
  • Own the central digital and data security risk register in partnership with Legal & Risk
  • Develop and maintain data classification, retention and GDPR operating frameworks
  • Own disaster recovery and business continuity planning, including RTO/RPO requirements for critical systems
  • Lead security governance across the enterprise AI estate, including access controls, data protection, prompt injection, jailbreaking and third-party AI risk
  • Own and develop the organisation's Responsible Use Policy for AI
  • Lead the DevSecOps security function, including secrets management, vulnerability scanning, pipeline security and workload protection
  • Own third-party security assessments and ongoing supplier/vendor security monitoring
  • Develop and mature the organisation's wider security strategy, policies and control environment


What You'll Bring:

  • Significant senior leadership experience across security, cyber, governance, risk and compliance
  • Experience operating within a mid-to-large, complex or internationally distributed organisation
  • Deep, demonstrable ISO 27001 expertise, ideally having led or owned a successful certification programme
  • Strong working knowledge of SOC 2, NIST CSF and other recognised security frameworks
  • Strong technical understanding across SIEM, EDR, IAM, vulnerability management and DevSecOps
  • Proven GDPR and data protection experience, ideally within a multi-jurisdiction environment
  • Strong understanding of AI security and governance, including prompt injection, model risk and third-party AI vendor risk
  • Experience establishing and managing enterprise-level security and risk registers
  • Excellent executive stakeholder management and communication skills
  • A pragmatic approach to security, with the ability to balance risk management with business delivery
  • Experience managing security professionals and outsourced security partners
  • The credibility to operate as the organisation's senior security authority while remaining commercially and strategically focused


Certifications:

One or more of the following certifications is required:

CISSP | CISM | ISO 27001 Lead Implementer | CIPP/E | CIPM | CRISC | CGEIT | CCSP | AIGP


Please note: candidates must have the legal right to work in the UK.




Oscar Associates (UK) Limited is acting as an Employment Agency in relation to this vacancy.

To understand more about what we do with your data please review our privacy policy in the privacy section of the Oscar website.

What you need to do now

Applications are handled by Oscar Technology on their own site — BoQQs does not collect CVs or hold your application. This listing closes on 29 Aug 2026.

Apply now

BoQQs publishes this advert but does not vet the employer or verify its claims, and is not party to any application, offer, or engagement. Never pay to apply, and do not send documents until you have verified the employer. Read the disclaimer.

Back to all listings →

Director of Security & Compliance at Oscar Technology | BoQQs