At a Glance
- Tasks: Lead cyber security and data protection for a fast-growing safety specialist.
- Company: Join Harmony, rated an ‘Outstanding Employer’ in 2025.
- Benefits: Enjoy competitive salary, unlimited holiday, and ongoing training.
- Other info: Collaborative, high-energy environment with excellent career growth opportunities.
- Why this job: Make a real impact on safety while shaping the group's security posture.
- Qualifications: Proven experience in cyber security and data protection compliance.
The predicted salary is between 70000 - 90000 £ per year.
Harmony is on a mission to be the best life safety partner to work with and for. Rated an ‘Outstanding Employer’ by Best Companies in 2025, we are only getting bigger and stronger — and we’re looking for A-players to help us get there. We are passionate about making a difference and obsessed with quality. Our goal is to build a world where every resident can sleep safely at night, knowing their home is 100% safe.
This is a security-first leadership role. You will own cyber security and data protection across the Harmony group (Harmony Fire, Solidcor, Auro Technology) end-to-end — strategy, delivery and BAU — acting as the most senior security voice in the business below the Group IT Director. Cyber Essentials Plus, IASME Cyber Assurance and ISO 27001 sit with you. UK GDPR compliance sits with you as the group’s Data Protection Lead (a non-statutory role distinct from a formal DPO appointment). The group’s security posture, risk register, incident response and audit defensibility all sit with you. If something has a security or data protection dimension, it lands on your desk first.
Security cannot exist in isolation, so you will also run the day-to-day IT function — line-managing the IT Technician, overseeing the helpdesk, vendor stack and infrastructure resilience for around 250 users across three trading entities. Operations exist to deliver a secure platform, not the other way around. IT Project Managers will deliver new systems into the group; you will accept those handovers and operationalise them into BAU only once they meet your security bar. Reporting to the Group IT Director, you will be the security leader the group trusts to keep its people productive, its data protected and its certifications intact through ~30% year-on-year growth. This is more than an IT role. It is about bringing the right energy, accountability and resilience to our mission of saving lives through fire and height safety.
Key Responsibilities
- Own the group’s cyber security strategy, posture and risk register — the most senior security accountability in the business below the Group IT Director.
- Lead all formal security certifications end-to-end: Cyber Essentials Plus annual recertification, IASME Cyber Assurance alignment and ISO 27001 ISMS — scoping, risk treatment, Statement of Applicability, internal audits, management review and external audit defence.
- Apply additional frameworks where they strengthen the group’s posture — NIST CSF, CIS Controls, NCSC Cyber Assessment Framework — and embed them into operational practice.
- Act as the group’s Data Protection Lead (not a statutory DPO under UK GDPR Article 37) — own UK GDPR and DPA 2018 compliance, ROPA, DPIAs, retention schedules, DSARs, breach notification, processor agreements and supplier due diligence.
- Run security operations day-to-day — endpoint protection (Bitdefender GravityZone), conditional access, MFA, identity governance, vulnerability management, and security awareness and phishing simulation programmes via KnowBe4.
- Lead incident response — triage, containment, recovery, post-incident review and reporting, with playbooks kept current and tested.
- Oversee security across Auro Technology’s software stack — IoT device firmware, cloud platforms, mobile and web applications — partnering with the Auro engineering team on secure SDLC, code review, dependency management, secrets handling and product security posture.
- Act as the security gatekeeper for IT project handovers — accept newly delivered systems from IT Project Managers into BAU only once documentation, monitoring, support runbooks and security controls meet the group’s bar.
- Run vendor and licensing relationships across the IT and security stack — renewals, commercial negotiation and security due diligence on every new supplier before they are onboarded.
- Run the day-to-day IT function in service of the security mission — line-manage the IT Technician, oversee the Atera helpdesk, own SLAs and personally take the hardest tickets when they have a security dimension.
- Maintain infrastructure resilience — backups, disaster recovery, business continuity, identity, network and connectivity — owned, documented and tested.
- Run secure onboarding and offboarding at scale, keeping identity hygiene and asset control airtight as the group grows.
Skills, Knowledge and Expertise
- An A-player mindset — high standards, extreme ownership and the drive to do things properly, the first time.
- A security professional first and foremost — your career identity is cyber security and information assurance, not IT generalism that happens to include security.
- Proven track record leading Cyber Essentials Plus and ISO 27001 (or actively driving towards certification) in a real organisation — not a tabletop exercise.
- Strong working knowledge of UK GDPR and the Data Protection Act 2018, with hands‑on experience of DSARs, DPIAs, breach response and supplier DPAs.
- Deep, hands‑on Microsoft 365 and Entra ID security experience — conditional access, Intune, identity governance, the Defender stack and security baselines.
- Demonstrable security operations experience — EDR/XDR, vulnerability management, incident response and security awareness programmes.
- Pragmatic, hands‑on operator — comfortable running a helpdesk and line‑managing an IT Technician alongside the security and compliance remit.
- Confident commercial mindset — budget ownership, vendor negotiation and the ability to challenge supplier security claims with evidence.
- Excellent written and verbal communication, able to translate technical risk plainly for non‑technical leadership and field staff.
- Right to work in the UK and able to travel between London, Yeovil, Chesterfield, Edinburgh and other group sites as required.
- Recognised certification — CISSP, CISM, ISO 27001 Lead Implementer or Lead Auditor, Microsoft SC‑100 / SC‑200 / SC‑300.
- IASME Cyber Assurance experience.
- Formal Data Protection Officer training or qualification (e.g. PC.dp, BCS Practitioner Certificate in Data Protection).
- Experience in fire safety, construction, manufacturing or field‑engineering environments.
- Familiarity with our wider stack — Salesforce, SimPRO, Unleashed, Supabase, Cloudflare, Microsoft Fabric.
- Hands‑on experience with KnowBe4 (or equivalent security awareness and phishing simulation platforms).
- NIST CSF, CIS Controls or NCSC CAF practical experience.
Benefits
This is a chance to own cyber security and data protection end-to-end for a three‑entity group at one of the UK’s fastest‑growing safety specialists — with the autonomy to set the security bar, hold certifications and shape the group’s posture as we grow ~30% year-on-year. At Harmony, we ask a lot — and we give a lot back. The hours are real, the standards are high and the work is demanding, but for those who show up, deliver and go the extra mile, the rewards follow. A-players here enjoy a competitive salary, a performance bonus tied to successful, on‑time delivery against roadmap milestones and delivery KPIs, a Personal Development Plan with ongoing training and leadership mentoring, unlimited holiday, private medical insurance, enhanced maternity and paternity, lunch, snacks and refreshments on us every day (fresh fruit and Takeaway Fridays included), a team social budget, cycle to work, an auto‑enrolment pension, two major company events a year and our Reward and Recognition scheme — including European mini‑breaks for those who go above and beyond. It is a collaborative, high‑energy environment focused on doing things the right way — technically, ethically and practically — and none of it is a perk for showing up; it’s what we share with the people pulling the business forward. Harmony is an equal opportunity employer. We consider all applicants for employment regardless of age, disability, sexual orientation, gender identity, family or parental status, race, colour, nationality, ethnic or national origin, religion or belief. We want everyone who works with us to feel valued and to make a difference.
Group IT Security & Data Protection Lead employer: Harmony Fire
At Harmony, we pride ourselves on being an outstanding employer, recognised for our commitment to employee growth and a collaborative work culture. Located in London, we offer A-players the opportunity to lead cyber security and data protection for a rapidly growing group, with benefits including unlimited holiday, private medical insurance, and a performance bonus tied to successful delivery. Our high-energy environment is focused on doing things the right way, ensuring that every team member feels valued and empowered to make a meaningful impact.
StudySmarter Expert Advice🤫
We think this is how you could land Group IT Security & Data Protection Lead
✨Tip Number 1
Network like a pro! Get out there and connect with people in the industry. Attend events, join online forums, and don’t be shy about reaching out on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by researching the company and its culture. Harmony is all about quality and making a difference, so think about how your values align with theirs. Be ready to share examples of how you've demonstrated high standards and accountability in your previous roles.
✨Tip Number 3
Showcase your expertise! When you get the chance to chat with potential employers, highlight your hands-on experience with cyber security and data protection. Talk about specific projects or certifications that make you an A-player in this field.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in being part of the Harmony team and contributing to our mission.
We think you need these skills to ace Group IT Security & Data Protection Lead
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Group IT Security & Data Protection Lead role. Highlight your experience with cyber security, data protection, and any relevant certifications. We want to see how your skills align with our mission!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you’re passionate about security and how you can contribute to our goal of keeping residents safe. Be genuine and let your personality come through.
Showcase Your Achievements:Don’t just list your responsibilities; showcase your achievements in previous roles. Did you lead a successful certification process or improve security protocols? We love to see results that demonstrate your impact!
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for this exciting opportunity. Plus, it shows you’re keen on joining our team!
How to prepare for a job interview at Harmony Fire
✨Know Your Cyber Security Stuff
Make sure you brush up on your knowledge of Cyber Essentials Plus, ISO 27001, and UK GDPR compliance. Be ready to discuss how you've applied these frameworks in real-world scenarios, as this role is all about owning the security strategy and posture.
✨Show Your Leadership Skills
This position requires a strong leader who can manage both security operations and the IT function. Prepare examples of how you've successfully led teams, managed projects, or improved processes in previous roles. Highlight your ability to communicate technical risks to non-technical stakeholders.
✨Demonstrate Your Hands-On Experience
Be ready to talk about your practical experience with security operations, incident response, and vulnerability management. Share specific instances where you've tackled security challenges or implemented new systems, especially in environments similar to fire safety or construction.
✨Ask Insightful Questions
Prepare thoughtful questions that show your interest in Harmony's mission and values. Inquire about their current security challenges, how they measure success in this role, or what the team culture is like. This not only demonstrates your enthusiasm but also helps you gauge if it's the right fit for you.