Overview
Business Purpose & Value Contribution
This role owns information security, risk and compliance for Graitec: the certifications, the controls and the assurance that keep Graitec and our customers safe.
It is commercially consequential: information security managed as a product and turned into business won and retained. The role is hands-on, writing the policy, running the audit and answering the difficult customer questions, and it is designed to grow into a broader leadership remit as the capability matures.
Key Outcomes Expected
What success looks like in the first 12 months
- ISO 27001 certification and SOC 2 Type II attestation achieved through one efficient control programme
- An external trust centre live, with customer security questionnaires answered to an agreed SLA from a maintained and increasingly automated knowledge base
- Security visibly enabling revenue, with named regulated and public sector opportunities won or retained on the strength of our security position
- A prioritised information security risk register, owned by the business and reviewed at executive level
- Detection and response matured: consolidated tooling, tested playbooks, and time to detect and respond trending down
- External security ratings improved further
- A published position on AI security and acceptable use, with the AI estate inventoried and a clear approval route to be an enabler for innovation
Responsibilities
Certification & Compliance
- Own delivery of SOC 2 Type II and ISO 27001 as a single efficient control programme
- Build and run the information security management system: policies, controls, evidence, internal audit and management review, and own the relationship with auditors and certification bodies
Customer Assurance & Commercial Enablement
- Run customer assurance: an external trust centre, a maintained questionnaire knowledge base, clear service levels back to Sales, and reporting on the commercial contribution of security
- Represent Graitec on security with customers and prospects, including regulated and public sector accounts, and support contract negotiation with the Group Legal Director
Security Operations & Engineering
- Own detection and response, and run vulnerability, exposure and patch management to agreed targets, with the external attack surface actively managed
- Own identity and access security with IT Operations & Platforms: privileged access, service accounts, conditional access, and joiner, mover and leaver controls
- Own the security tooling roadmap and budget, consolidating the estate as required
Cloud, Product & Web Security
- Secure Graitec's public estate, platforms and hosted services, setting secure-by-design standards for cloud landing zones, integrations and customer-facing services
- Extend remit to our intellectual property and product security, with a strong working interface into R&D
- Embed secure development practice with R&D: secure SDLC, code and dependency scanning, secrets management, and penetration testing with tracked remediation
Risk, Resilience & Governance
- Build and maintain the information security risk register, with business ownership, an agreed risk appetite and executive-level reporting
- Own third party and vendor security assessment, including periodic reassessment and secure offboarding, and provide security due diligence for acquisitions
- Drive security governance for corporate AI: inventory and approval of tools and agents, AI access to corporate data, AI vendor risk, and responsible use
- Own incident response and business continuity: run exercises, lead responses, and work with other functions on disaster recovery design and testing
- Build security awareness that changes behaviour, with targeted training, phishing simulation and a strong culture of prevention
Responsibilities
- Hands-on ownership of an information security programme in a software or SaaS business, with SOC 2 Type II and ISO 27001 carried end-to-end, and national schemes e.g., Cyber Essentials Plus or NIST CSF
- Strong working knowledge of the Microsoft security stack (Defender, Entra ID, Purview, Sentinel) and of managing an outsourced or co-managed SOC
- Cloud security, including landing zones, identity, securing internet-facing services, and penetration testing and vulnerability remediation with R&D teams
- Security risk management, third party assurance and GDPR obligations, working alongside a Data Protection Officer
- AI security and governance: securing AI agents that access corporate data, and setting the inventory, approval and acceptable use framework
- Comfortable as the only dedicated security professional, pragmatic and proportionate in a mid-sized, fast-moving business
- Commercially astute, credible in front of customers, and able to translate risk into business language
- Self-directed and evidence-driven, taking work to completion, and able to develop junior talent and mature a small team
Also valued
- CISSP, CISM, CISA, CRISC, CCSP, or ISO 27001 Lead Implementer or Lead Auditor
- Experience in M&A due diligence and integration, in an acquisitive or private equity-backed group
- Exposure to NIS2, DORA or the EU AI Act
Qualifications
- Executive-level communication, with a track record of leading adoption and change across multinational, multidisciplinary teams
- Results-oriented mindset with a high degree of ownership and accountability.
- Ability to operate effectively in a global and multicultural environment.
Information Security Leader employer: Graitec
StrucSoft is an exceptional employer that fosters a collaborative and innovative work culture, empowering employees to excel in their roles as Solution Sales Specialists. With a strong focus on professional development and customer satisfaction, team members benefit from comprehensive training, mentorship opportunities, and the chance to work closely with industry experts. Located in a vibrant area, StrucSoft offers a dynamic environment where creativity and teamwork thrive, making it an ideal place for those seeking meaningful and rewarding careers in the software solutions sector.