Head of Security in London

Head of Security in London

London Full-Time 80000 - 100000 Β£ / year (est.) No home office possible
Fresha

At a Glance

  • Tasks: Lead security strategy and protect our innovative beauty tech platform.
  • Company: Join Fresha, the AI-powered OS for beauty and wellness, trusted globally.
  • Benefits: Competitive salary, dynamic work environment, and opportunities for growth.
  • Other info: Collaborative culture with a focus on teamwork and innovation.
  • Why this job: Shape security in a fast-paced industry and make a real impact.
  • Qualifications: Experience in security under regulatory pressure and strong technical skills.

The predicted salary is between 80000 - 100000 Β£ per year.

The AI-powered OS for beauty, wellness and self-care. Fresha is the AI-powered operating system for the global beauty, wellness and self-care industry, connecting and powering everything from salons and barbers to spas, medspas, fitness studios and health practices. Trusted by millions of consumers and businesses worldwide, Fresha is used by 140,000+ businesses and 450,000+ stylists and professionals worldwide, processing over 1 billion appointments to date.

About the role

Reports to: VP of Security, IT and Compliance. We're looking for someone to own security end-to-end at Fresha. You'll shape the security strategy alongside the VP, build and run the controls that protect the business, and be the person everyone β€” engineers, execs, auditors, customers β€” looks to regarding security questions. You'll work alongside the Head of Compliance as a peer. They own the frameworks, the audits, and the evidence. You own the actual security posture, the tooling, and the response. The two roles need each other to succeed, and we expect you to work closely together rather than carve out territory.

We're a payments business operating in a regulated space, with HIPAA and ISO 27001 behind us and PCI DSS, GDPR, and SOC 2 Type II ahead of us this year. The security bar is not theoretical. To foster a collaborative environment that thrives on face-to-face interactions and teamwork, this role will be based in our dog-friendly office 5 days per week in London: The Bower, 207-122, Old Street, London EC1V 9NR.

What you'll own:

  • Security strategy and roadmap: Shape the security strategy together with the VP β€” the VP sets direction at the exec level, you bring the ground truth, the technical depth, and the detailed plan that turns that direction into something real. Own the security roadmap that falls out of it: what we're building, what we're retiring, what we're deferring, and why. Make the call on where to invest day-to-day: tooling, headcount, external services, automation β€” within the strategic envelope agreed with the VP. Translate that roadmap into something the exec team can actually read and fund.
  • Controls and protections: Deploy and run the security controls across the estate β€” endpoint, network, cloud, identity, application. Make sure controls are actually working, not just deployed β€” continuous validation, not annual tick-boxing. Partner with Engineering and IT to get controls in early, rather than bolted on after the fact.
  • Penetration testing and vulnerability management: Run the regular external pentest cadence β€” application, infrastructure β€” and make sure findings are triaged and closed. Own the vulnerability management programme: scanning, prioritisation, SLAs, and closure. Work with the Head of Compliance on the evidence side β€” they need clean data for audits, you need clean closure on the underlying issues.
  • Incident response: Own the IR process end-to-end: detection, triage, containment, eradication, recovery, and post-incident review. Run the on-call model, the playbooks, the tabletop exercises, and the tooling behind them. Be the person in the room when something real happens, and the person writing the honest post-mortem afterwards.
  • Threat intelligence and threat modelling: Stand up a threat intelligence capability β€” somewhere past incidents, near-misses, industry reports, and internal telemetry get captured, tagged, and made useful. Build this into a threat intel data warehouse that actually informs decisions: future threat modelling, control design, roadmap prioritisation, and tabletop scenarios. Run threat modelling as a routine practice, not a one-off β€” including automated threat modelling using AI against designs, code, and infrastructure changes.
  • Emerging threats: Keep a forward view on where the threat landscape is heading, especially around LLMs: prompt injection, model abuse, AI-augmented vulnerability scanning by attackers, and exposure of sensitive data through AI tooling. Don't just react to what's hitting us today β€” make sure we're not blindsided by what's hitting everyone in 12 months. Feed that view into the strategy conversation with the VP, and turn it into concrete roadmap items.
  • Security training and awareness: Own the security-specific training content: phishing simulations, secure coding for engineers, threat modelling training, IR tabletop participation, and role-based training for anyone handling cardholder data, PHI, or other sensitive material. Partner with the Head of Compliance β€” they run the overall training programme, cadence, and evidence; you bring the security substance and keep it current with the threat landscape.
  • Automation and AI: Look at every recurring task in this function and ask "why is a human still doing this?" β€” triage, alert enrichment, vulnerability prioritisation, evidence gathering, threat modelling, IR runbooks. Push existing tooling as far as it'll go, and fill the gaps with scripts, workflows, or AI where it makes sense.
  • Security advisory: Be the go-to person for security questions across the business β€” architecture reviews, vendor assessments, new products, acquisitions, anything risky. Give engineers a straight answer and a path forward, not a ticket queue and a policy link.

What we're looking for:

  • You've led security at a company operating under real regulatory pressure β€” payments, healthcare, financial services, or similar.
  • You've run incident response for real incidents, not just exercises, and you've written the post-mortems.
  • You understand modern attack surfaces: cloud, SaaS, identity, supply chain, application β€” and you don't reduce security to any one of them.
  • You've built or meaningfully improved a threat intel or threat modelling capability, not just consumed vendor feeds.
  • You're fluent with AI tools and comfortable building automation.
  • You're comfortable co-owning strategy with a VP β€” bringing strong opinions, challenging when it matters, and aligning once a direction is set.
  • You can hold your own with engineers on technical depth and with execs on business framing.

How you'll work:

You'll have a team to lead from day one, with scope to grow it as the roadmap demands. You'll work closely with the VP on strategy, and with the Head of Compliance, IT, Engineering, Infrastructure, and Product on execution. You'll be in front of customers and auditors often enough that polish matters. Expect to spend real time hands-on β€” in tooling, in incidents, in design reviews β€” not just managing.

Interview Process:

  • Screen Stage - Video-call with a member from the Talent Team (45-60min)
  • 1st Stage - Interview with the VP of Security, IT & Compliance (60min)
  • Final Stage - Video interview with CTO (60min) and Head of Talent (30min)

Inclusive workforce:

At Fresha, we are creating a culture where individuals of all backgrounds feel comfortable. We want all Fresha people to feel included and truly empowered to contribute fully to our vision and goals. Everyone who applies will receive fair consideration for employment. We do not discriminate based on race, colour, religion, sex, sexual orientation, age, marital status, gender identity, national origin, disability, or any other applicable legally protected characteristics in the location in which the candidate is applying.

Head of Security in London employer: Fresha

Fresha is an exceptional employer, offering a dynamic work environment in the heart of London where innovation meets collaboration. With a strong focus on employee growth and a commitment to inclusivity, Fresha empowers its team members to take ownership of their roles while providing opportunities for professional development in a rapidly evolving industry. The company's dog-friendly office culture and emphasis on teamwork make it a unique and rewarding place to work for those passionate about security in the beauty and wellness sector.
Fresha

Contact Detail:

Fresha Recruiting Team

StudySmarter Expert Advice 🀫

We think this is how you could land Head of Security in London

✨Tip Number 1

Network like a pro! Get out there and connect with folks in the security industry. Attend meetups, webinars, or even local events. You never know who might have the inside scoop on job openings or can put in a good word for you.

✨Tip Number 2

Show off your skills! Create a portfolio or a personal project that highlights your security expertise. Whether it's a blog about the latest threats or a GitHub repo showcasing your automation scripts, let your work speak for itself.

✨Tip Number 3

Prepare for those interviews! Research Fresha and understand their security needs. Be ready to discuss how your experience aligns with their goals, especially around compliance and incident response. Confidence is key!

✨Tip Number 4

Apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you're genuinely interested in joining the Fresha team. Don’t miss out!

We think you need these skills to ace Head of Security in London

Security Strategy Development
Regulatory Compliance (HIPAA, ISO 27001, PCI DSS, GDPR, SOC 2 Type II)
Incident Response Management
Vulnerability Management
Threat Intelligence and Modelling
Penetration Testing
Automation and AI Integration
Technical Depth in Security Architecture
Collaboration with Engineering and IT
Security Training and Awareness
Data Analysis for Security Audits
Communication Skills
Leadership and Team Management
Adaptability to Emerging Threats

Some tips for your application 🫑

Tailor Your Application: Make sure to customise your CV and cover letter for the Head of Security role. Highlight your experience in security strategy, incident response, and regulatory compliance, as these are key areas we're looking for.

Show Your Technical Depth: We want to see your understanding of modern attack surfaces and security controls. Don't just list your skills; provide examples of how you've applied them in real-world situations to protect a business.

Be Clear and Concise: When writing your application, keep it straightforward. Use clear language and avoid jargon where possible. We appreciate directness and clarity, especially when discussing complex security topics.

Apply Through Our Website: We encourage you to submit your application through our website. This way, we can ensure your application is reviewed promptly and you get the best chance to showcase your fit for the role!

How to prepare for a job interview at Fresha

✨Know Your Security Stuff

Make sure you’re up to speed on the latest security trends, especially in the beauty and wellness industry. Familiarise yourself with regulations like PCI DSS and GDPR, and be ready to discuss how they impact security strategy.

✨Show Your Incident Response Skills

Prepare to share specific examples of how you've handled real incidents in the past. Be ready to walk through your thought process during an incident response, including how you triaged issues and wrote post-mortems.

✨Collaborate Like a Pro

This role requires working closely with the VP and Head of Compliance. Think about how you can demonstrate your ability to collaborate effectively. Have examples ready that show how you’ve successfully partnered with other teams in the past.

✨Bring Your Automation Ideas

Fresha is looking for someone who can leverage automation and AI in security processes. Come prepared with ideas on how you would automate recurring tasks and improve efficiency within the security function.

Head of Security in London
Fresha
Location: London

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>