Назад
Company hidden
2 часа назад

Senior IT Security & Compliance Lead (AI)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior/lead
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior IT Security & Compliance Lead (AI): Owning security and compliance for an AI-enabled legal technology platform with an accent on IT infrastructure security, SOC 2 and ISO certification, AI governance, and GDPR privacy operations. Focus on building scalable controls and automation, assessing AI and vendor risk, leading incident response, and translating technical risk for executives, customers, and the board.

Location: Edinburgh, UK; hybrid with office attendance expected as the default

Company

hirify.global is building an AI-enabled command centre for in-house legal teams.

What you will do

  • Set and own the multi-year IT security and compliance roadmap, including priorities, budgets, tooling, and function-building plans.
  • Lead security architecture for corporate IT and infrastructure, including identity and access management, endpoint protection, cloud and network security, and incident response.
  • Run SOC 2 Type II, ISO 27001/27017/27018, and ISO 42001 certification programs, including policies, controls, audit evidence, and audits.
  • Manage AI governance and privacy operations, including AI impact assessments, model and vendor risk reviews, GDPR, DPIAs, RoPA, sub-processors, and data subject requests.
  • Assess third-party and AI-tool risks, establish contractual safeguards, and support enterprise deals through security questionnaires, DPAs, and the Trust Center.
  • Report security and compliance risks to executives, customers, and the board while building lean, automation-first tooling and growing the team.

Requirements

  • 8–10+ years of experience in security, IT, or compliance, including end-to-end ownership of a security or compliance function at a fast-growing SaaS or technology company.
  • Experience building or scaling a security and compliance program from an early stage, ideally as the sole or founding function owner.
  • Deep hands-on expertise with SOC 2 and the ISO 27000 series, with ISO 42001 experience preferred.
  • Strong knowledge of identity and access management, endpoint and device security, cloud or network infrastructure security, GDPR, and related privacy regulations.
  • Experience presenting security posture, risk, and roadmaps to executives, boards, or investors, and building or managing teams.
  • Ability to partner across Security, IT, Legal and Privacy, Engineering, Sales, and Customer Success while owning strategic budgets and vendor decisions.

Nice to have

  • Previous experience as Head of Security, Director of Security or IT, or in a similar leadership role.
  • Relevant certifications such as CISSP/ISC2, CISM, AIGP, CIPP/E, CIPT, CCSK, or FIP.
  • Experience in legal tech, AI, or another highly regulated SaaS environment.
  • Experience designing AI risk or impact-assessment processes from scratch.
  • Familiarity with Datagrail, MineOS, Whistic, or SafeBase.

Culture & Benefits

  • In-office collaboration in Edinburgh across product, engineering, and legal teams.
  • High ownership and autonomy in a small leadership group.
  • Competitive compensation, benefits, and meaningful equity.
  • Clear opportunity to build and lead a security and compliance team as the company scales.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →