At a Glance
- Tasks: Lead our information security strategy and ensure compliance across multiple jurisdictions.
- Company: Join ApprovalMax, a fast-growing fintech company transforming finance management.
- Benefits: Flexible working hours, competitive salary, and opportunities for professional growth.
- Why this job: Make a real impact on security in a dynamic, innovative environment.
- Qualifications: 8+ years in information security with experience in B2B SaaS and cloud environments.
- Other info: Be part of a collaborative team focused on cutting-edge security solutions.
The predicted salary is between 72000 - 108000 £ per year.
ApprovalMax is redefining how finance teams manage the Money Out cycle — from purchase orders and supplier bills to employee expense management. Trusted by 18,000+ businesses worldwide, our platform empowers companies to automate financial controls, ensure compliance, and scale efficiently. At the end of 2024, ApprovalMax secured a £10 million growth investment from Yttrium, a leading European technology investor. This funding marks the beginning of a new chapter in our journey — scaling our category leadership in Money Out automation, expanding enterprise capabilities, and accelerating product innovation.
We are seeking an experienced Fractional CISO to provide hands-on security leadership as we evolve our security function to support continued growth and European expansion. This is a permanent fractional engagement reporting directly to the CTO.
You will own our information security strategy, maintain our ISO 27001 certification, build our security roadmap, and prepare the organisation for SOC 2 readiness. This role requires someone who can operate both strategically and tactically — developing policy one day and reviewing cloud configurations the next.
Responsibilities
- Develop and own the Information Security strategy aligned with ApprovalMax's business objectives and European expansion plans.
- Maintain and continuously improve the Information Security Management System (ISMS).
- Create, review, and maintain core security policies, standards, and procedures.
- Establish and chair a cross-functional Security Working Group (Engineering, Architecture, IT, HR).
- Build and present a multi-year security roadmap with clear milestones, resource requirements, and priorities.
- Serve as the central authority on risk assessment, risk treatment, and risk acceptance decisions.
- Assess and provide guidance on secure AI adoption across the organisation, including AI-powered product features and internal AI tooling.
Compliance & Certification
- Maintain ISO 27001 certification and prepare for the 2027 recertification audit.
- Lead SOC 2 Type II readiness programme, including gap analysis and control mapping.
- Ensure compliance with GDPR and data protection requirements across EU/UK/US/AU/NZ/CA/ZA jurisdictions.
- Collaborate with external DPO support provider on privacy-related matters and customer security questionnaires as needed.
Cloud & Technical Security
- Provide security oversight across Azure, AWS, and Google Workspace environments.
- Conduct access reviews and advise on identity and access management best practices.
- Evaluate and guide implementation of security tooling (SIEM, vulnerability management, endpoint protection).
- Oversee VMware Workspace ONE MDM deployment and device security policies.
- Advise engineering teams on secure SDLC practices, DevSecOps integration, and application security principles.
Operational Security
- Develop and maintain incident response plans and procedures.
- Lead incident response tabletop exercises and post-incident reviews.
- Provide guidance on business continuity and disaster recovery planning.
- Advise on vendor security assessments and third-party risk management.
Awareness & Culture
- Design and deliver company-wide security awareness training programmes.
- Mentor and upskill internal staff on security best practices.
- Foster a security-first culture across all departments.
- Act as a trusted advisor to leadership on emerging threats and security trends.
Stakeholder Engagement
- Report regularly to the CTO on security posture, risks, and programme progress.
- Prepare board-level security presentations as required.
- Support commercial teams by contributing to customer security discussions when escalated.
Qualifications
- 8+ years of progressive experience in information security, with at least 3 years in a CISO, Head of Security, or senior security leadership role.
- Demonstrated experience in B2B SaaS environments, ideally in fintech, finance software, or similarly regulated industries.
- Proven track record of achieving and maintaining ISO 27001 certification.
- Experience preparing organisations for SOC 2 Type II certification.
- Hands-on experience securing cloud environments (Azure and/or AWS required; GCP a plus).
- Experience with Google Workspace security configuration and administration.
- Background working with distributed, remote-first engineering teams.
Technical Knowledge
- Strong understanding of cloud security architecture, identity management, and zero-trust principles.
- Familiarity with secure software development lifecycle (SDLC) and DevSecOps practices.
- Knowledge of MDM solutions (VMware Workspace ONE experience preferred).
- Understanding of API security and integration risk management.
- Practical experience with security tooling: SIEM, vulnerability scanners, endpoint protection, etc.
- Awareness of AI/ML security risks, including secure AI adoption practices and emerging AI governance frameworks (desirable).
Compliance & Regulatory
- Deep knowledge of ISO 27001:2022 requirements and audit processes.
- Familiarity with SOC 2 Trust Service Criteria (Security, Availability, Confidentiality, Privacy).
- Understanding of GDPR, UK Data Protection Act, and international data protection regulations.
Fractional Chief Information Security Officer in London employer: ApprovalMax
Contact Detail:
ApprovalMax Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Fractional Chief Information Security Officer in London
✨Tip Number 1
Network like a pro! Attend industry events, webinars, and meetups to connect with folks in the fintech and security space. You never know who might be looking for a Fractional CISO or can refer you to someone who is.
✨Tip Number 2
Show off your expertise! Create content around information security trends, especially in B2B SaaS and fintech. Share it on LinkedIn or relevant forums to get noticed by potential employers and showcase your knowledge.
✨Tip Number 3
Don’t just apply; engage! When you find a role that excites you, reach out to the hiring manager or team members on LinkedIn. A friendly message expressing your interest can set you apart from the crowd.
✨Tip Number 4
Keep an eye on our website for openings! We’re always looking for talented individuals to join us at ApprovalMax. Applying directly through our site gives you a better chance of being seen by the right people.
We think you need these skills to ace Fractional Chief Information Security Officer in London
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience in information security, especially in B2B SaaS environments. We want to see how your skills align with our needs at ApprovalMax!
Showcase Your Achievements: Don’t just list your responsibilities; share specific achievements that demonstrate your impact in previous roles. Whether it’s maintaining ISO 27001 certification or leading a SOC 2 readiness programme, we love to see results!
Be Clear and Concise: Keep your application straightforward and to the point. Use clear language and avoid jargon where possible. We appreciate a well-structured application that makes it easy for us to see your qualifications.
Apply Through Our Website: We encourage you to submit your application directly through our website. It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it’s super easy!
How to prepare for a job interview at ApprovalMax
✨Know Your Stuff
Make sure you brush up on your knowledge of ISO 27001 and SOC 2 requirements. Be ready to discuss how you've maintained certifications in the past and any specific challenges you've faced in B2B SaaS environments, especially in fintech.
✨Show Your Strategic Side
Prepare to talk about how you would align the information security strategy with ApprovalMax's business objectives. Think about examples where you've successfully developed security roadmaps and how you can apply that experience to their European expansion plans.
✨Hands-On Experience Matters
Be ready to share specific instances where you've secured cloud environments like Azure or AWS. Discuss your hands-on experience with security tooling and how you've implemented best practices in identity and access management.
✨Cultural Fit is Key
ApprovalMax values a security-first culture, so think about how you can foster this within the team. Prepare examples of how you've designed security awareness training programmes and mentored staff on security best practices in previous roles.