At a Glance
- Tasks: Lead security strategy, assess risks, and optimise processes at iwoca.
- Company: Join iwoca, a fast-growing fintech supporting SMEs with flexible finance solutions.
- Benefits: Enjoy flexible hours, medical insurance, generous holiday, and a learning budget.
- Why this job: Shape the future of security in a dynamic environment and make a real impact.
- Qualifications: Proven experience in security risk analysis and implementing effective protections.
- Other info: Collaborative culture with fun events and opportunities for professional growth.
The predicted salary is between 100000 - 150000 £ per year.
The Company: Small businesses move fast. Opportunities often don’t wait, and cash flow pressures can appear overnight. To keep going, and growing, SMEs need finance that’s as flexible and responsive as they are.
Hybrid in London, United Kingdom
The role: As Security Strategy Lead, you’ll define how security works at iwoca and own the decisions that shape it. You’ll assess security risks, influence priorities across teams, and embed security into how products are built and operated. This is iwoca’s first dedicated security role, reporting to the Engineering Director, with visibility at company level and scope to shape standards, ways of working, and long-term security strategy.
You’ll be accountable for the following areas, deciding priorities and how work is delivered in iwoca’s context. We expect this to involve judgement, trade-offs, and discussion rather than following a fixed playbook.
- Security strategy and leadership: Own iwoca’s security strategy, minimising security risk while avoiding unnecessary friction for customers and developers. Act as the key decision maker for security checks and processes, and decide how the security function evolves over time, including when to use internal capability, third-party expertise, or new tooling.
- Tooling and process optimisation: Decide how security tooling and processes should be designed and applied across iwoca’s systems. Maintain a consolidated view of our security posture, including identity risks, third-party exposure, and supply-chain vulnerabilities, and oversee the development or adoption of automated detection where it adds value.
- Monitoring, reporting, and continuous improvement: Establish monitoring and reporting that provides visibility into the effectiveness of security controls. Use this to generate insights, recommend improvements, and guide prioritisation as risks and the business evolve.
- Collaboration and incident response: Work closely with product, engineering, and infrastructure teams to align on security priorities and trade-offs. Act as the primary point of contact for security matters and lead coordinated incident response and triage of emerging threats.
Essential:
- Proven ability to analyse security risks across application and infrastructure systems, and implement effective protections and monitoring solutions.
- Understanding of security techniques such as static analysis, network scanning, and penetration testing, and how to apply them in practice.
- Experience turning security plans into action, prioritising work, and delivering meaningful improvements with engineering teams.
- Experience leading or influencing change across teams, making trade-offs explicit and aligning security decisions with business context.
Bonus:
- Experience contributing to security certifications such as ISO 27001.
- Experience building security practices in a fast-growing company.
- Exposure to identity-based attacks, supply chain vulnerabilities, or other advanced threat classes.
The salary: We expect to pay from £100,000 - £150,000 for this role. But, we’re open-minded, so definitely include your salary goals with your application. We routinely benchmark salaries against market rates, and run quarterly performance and salary reviews.
The culture: At iwoca, we prioritise a culture of learning, growth, and support, and invest in the professional development of our team members. We value thought and skill diversity, and encourage you to explore new areas of interest to help us innovate and improve our products and services.
The offices: Offices in London, Leeds, Berlin, and Frankfurt with plenty of drinks and snacks. Events and clubs, like bingo, comedy nights, football, etc.
The Benefits:
- Flexible working hours.
- Medical insurance from Vitality, including discounted gym membership.
- A private GP service (separate from Vitality) for you, your partner, and your dependents.
- 25 days’ holiday per year, an extra day off for your birthday, the option to buy or sell an additional five days of annual leave, and unlimited unpaid leave.
- A one-month, fully paid sabbatical after four years.
- Instant access to external counselling and therapy sessions for team members that need emotional or mental health support.
- 3% Pension contributions on total earnings.
- An employee equity incentive scheme.
- Generous parental leave and a nursery tax benefit scheme to help you save money.
- Electric car scheme and cycle to work scheme.
- Two company retreats a year: we’ve been to France, Italy, Spain, and further afield.
And to make sure we all keep learning, we offer:
- A learning and development budget for everyone.
- Company-wide talks with internal and external speakers.
- Access to learning platforms like Treehouse.
Useful Links: iwoca benefits & policies, Interview welcome pack
Security Strategy Lead in Harrow employer: iwoca Deutschland
Contact Detail:
iwoca Deutschland Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Security Strategy Lead in Harrow
✨Tip Number 1
Network like a pro! Reach out to people in the industry, attend events, and connect with potential colleagues on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for those interviews! Research iwoca’s security practices and think about how your experience aligns with their needs. Be ready to discuss your past projects and how you’ve tackled security challenges.
✨Tip Number 3
Showcase your passion for security! During interviews, share your thoughts on current security trends and how they could impact iwoca. This will demonstrate your commitment and knowledge in the field.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in being part of the iwoca team.
We think you need these skills to ace Security Strategy Lead in Harrow
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter for the Security Strategy Lead role. Highlight your relevant experience and skills that align with iwoca's needs, especially in security risk analysis and strategy.
Showcase Your Achievements: Don’t just list your responsibilities; share specific examples of how you've successfully implemented security measures or led teams in previous roles. This will help us see the impact you've made in your past positions.
Be Clear and Concise: When writing your application, keep it straightforward and to the point. Use clear language and avoid jargon unless it's relevant to the role. We appreciate clarity as much as you do!
Apply Through Our Website: We encourage you to submit your application directly through our website. It’s the best way for us to receive your details and ensures you’re considered for the role without any hiccups.
How to prepare for a job interview at iwoca Deutschland
✨Know Your Security Fundamentals
Before the interview, brush up on key security concepts like static analysis, network scanning, and penetration testing. Be ready to discuss how you’ve applied these techniques in real-world scenarios, as iwoca is looking for someone who can turn security plans into actionable strategies.
✨Showcase Your Leadership Skills
As this role involves influencing change across teams, prepare examples of how you've led security initiatives or made trade-offs in previous positions. Highlight your ability to align security decisions with business context, as this will demonstrate your strategic thinking.
✨Understand iwoca's Business Context
Familiarise yourself with iwoca’s mission and the challenges faced by SMEs. This knowledge will help you articulate how your security strategy can minimise risks while supporting their fast-paced environment, showing that you’re not just a security expert but also a business partner.
✨Prepare for Collaboration Questions
Expect questions about how you would work with product, engineering, and infrastructure teams. Think of specific instances where you’ve successfully collaborated on security priorities and how you handled any conflicts. This will showcase your ability to be the primary point of contact for security matters.