At a Glance
- Tasks: Lead information security and risk management for a cutting-edge AI SaaS product.
- Company: Join Natter, a dynamic team of ex-Uber, WeWork, and Amazon innovators.
- Benefits: Enjoy quarterly international offsites, free meals, and a supportive work environment.
- Why this job: Be the first dedicated hire in a role that shapes security for major enterprises globally.
- Qualifications: 5+ years in info security or risk management; strong communication skills required.
- Other info: Flexible interview process tailored to your schedule and needs.
The predicted salary is between 48000 - 84000 ÂŁ per year.
Information Security & Risk Management Lead
A rare chance to join as the first full-time, dedicated Information Security and Risk Management related hire at a venture capital funded, ex-Uber, WeWork and Amazon team providing an AI-powered and data-driven SaaS product to employees at large enterprises globally.
You will have a high level of autonomy to operationalise and further develop our posture, with the chance to build relationships with relevant teams at enterprise customers worldwide (e.g. Deloitte, Legal & General, Miro).
A varied role with the chance to build on the fundamentals of our ISO 27001 compliance and across IT, information security, data protection and wider risk management.
ABOUT NATTER
Natter exists to give everyone a voice at work by leveraging the power of AI & video.
Built by a team of ex-Uber, WeWork and Amazon builders, Natter has selectively hired a team of exited founders, specialist domain experts and SaaS unicorn founding team members. They are now looking for their first Information Security & Risk Management Lead.
Natter is already being used by some of the world’s largest companies, ranging from big four consultancies like Deloitte, institutional financial services providers like Legal and General, to technology innovators like Miro.
Natter’s conversational AI platform allows tens of thousands of users to simultaneously share ideas and feedback through real-time video conversations. Its uniquely scalable tech allows anyone with a smartphone to, literally, have a say on the most important decisions – ranging from workplace strategy to new product offerings.
Information Security & Risk Management Lead Responsibilities
As our Information Security & Risk Management Lead at Natter you will…
- Have ownership of our information security and risk management policies and procedures, working to ensure these meet the risk-related expectations of enterprise customers (including, e.g. incident response, vulnerability management, vendor and asset management, system access and backup, business continuity and disaster recovery).
- Lead efforts to build credibility with our customers’ information security, IT, legal, risk and data teams, including acting as the working level contact to complete their vendor assessment exercises, negotiate and enact data processing or related agreements and address ongoing compliance check-ins.
- Maintain and report on our compliance with our ISO 27001 certification, GDPR and any future AI-related legal or risk-related requirements, working cross-functionally and proactively to avoid policy and procedure-related non-conformities.
- Manage our IT and other risk management policies (including e.g. physical security, data classification, retention and backup), adopting a pragmatic mindset that balances the need to identify, manage and escalate risk with our ambitious commercial objectives.
- Collaborate with our Engineering and Product teams to put security and data protection at the forefront of how we design, build and maintain our products to stay in line with industry best practices and evolving customer expectations.
- Lead efforts to upskill commercial-facing teams on specialist subject matter to ensure all our people understand and can communicate our posture to external parties effectively.
- Work closely with senior leaders to further embed security and the appropriate evaluation of risk as part of Natter’s DNA.
We’d love to hear from you if you have…
- 5+ years’ varied experience in information security, data protection, risk management, enterprise IT, legal or (relevant) compliance roles.
- Hands-on experience building credibility with external stakeholders, including enterprise clients, critical system vendors, certification auditors and regulatory bodies.
- Proven experience shepherding a B2B SaaS product with the potential to capture special category data through enterprise-grade vendor assessment exercises and data processing-related legal negotiations.
- A high level of understanding and experience in how to maintain IT, security, monitoring and logging tools and continuous compliance platforms.
- Excellent verbal and written communication skills, with the ability to explain sometimes complex concepts to non-specialist stakeholders.
- A proactive and solution-oriented mindset, with a strong attention to detail.
- Given the variety of this role (spanning both operational policy and more technical procedure), those with an intellectually curious mindset who can adapt under pressure and use limited resources effectively are likely to succeed. Whilst experience working at an early stage start-up is not necessarily required, tangible experience operating in fast-paced, sometimes fluid working environment requiring proactivity, accountability and pragmatism is highly desirable.
️ Quarterly international team offsite
Company laptop and supporting tech as necessary
Mindfulness/meditation sessions for all employees
Complimentary daily breakfast and weekly lunch provided In office
Dedicated, private office space in Soho, London
HOW TO APPLY
The application journey has 4 key steps. Our interview process involves four main stages after an informal recruiter call:
- 30 min screening interview
- Interview with James Stevens (COO)
- Interview with Chief of Staff and Operations Lead
- Final stage in-person meet with founding team
This process should take around 3-4 weeks – your schedule is really important to us, so we promise to be as flexible as possible!
You will have the chance to speak to our recruitment team at various points during your process but if you do have any specific questions or want to talk through reasonable adjustments ahead of or during application please us at any point on
Please also use that email to let us know if there’s anything we can do to make your application process easier for you, because of disability, neurodiversity or any other personal reason.
#J-18808-Ljbffr
Information Security & Risk Management Lead employer: Natter
Contact Detail:
Natter Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Information Security & Risk Management Lead
✨Tip Number 1
Familiarize yourself with ISO 27001 compliance and GDPR regulations, as these are crucial for the role. Understanding these frameworks will not only help you in discussions but also demonstrate your commitment to information security.
✨Tip Number 2
Build a strong understanding of the SaaS landscape, especially how data protection and risk management apply to B2B products. This knowledge will be invaluable when engaging with enterprise clients and addressing their specific concerns.
✨Tip Number 3
Network with professionals in the information security and risk management fields. Attend relevant industry events or webinars to connect with potential colleagues and gain insights into best practices that you can bring to Natter.
✨Tip Number 4
Prepare to discuss your experience in building credibility with external stakeholders. Be ready to share specific examples of how you've successfully navigated vendor assessments or legal negotiations in previous roles.
We think you need these skills to ace Information Security & Risk Management Lead
Some tips for your application 🫡
Understand the Role: Before applying, make sure you fully understand the responsibilities and requirements of the Information Security & Risk Management Lead position. Tailor your application to highlight relevant experiences that align with the job description.
Highlight Relevant Experience: In your CV and cover letter, emphasize your 5+ years of experience in information security, data protection, and risk management. Provide specific examples of how you've built credibility with external stakeholders and managed compliance in previous roles.
Showcase Communication Skills: Since excellent verbal and written communication skills are crucial for this role, ensure your application reflects your ability to explain complex concepts clearly. Use concise language and structure your documents well to demonstrate your communication prowess.
Tailor Your Application: Customize your cover letter to reflect your proactive and solution-oriented mindset. Mention how your experience aligns with Natter's mission and values, and express your enthusiasm for contributing to their information security and risk management efforts.
How to prepare for a job interview at Natter
✨Understand the Company and Its Product
Before your interview, take the time to research Natter and its AI-powered SaaS product. Understand how it works, who its customers are, and what makes it unique in the market. This knowledge will help you demonstrate your genuine interest in the company and its mission.
✨Showcase Your Experience with Compliance
Given the emphasis on ISO 27001 compliance and GDPR in the job description, be prepared to discuss your past experiences related to these areas. Highlight specific examples where you successfully managed compliance or risk management processes, and how you navigated challenges.
✨Prepare for Technical Questions
Since this role involves both operational policy and technical procedures, expect questions that assess your technical knowledge in information security tools and practices. Brush up on relevant technologies and be ready to explain how you've implemented them in previous roles.
✨Demonstrate Your Communication Skills
The ability to communicate complex concepts to non-specialists is crucial for this position. Prepare examples of how you've effectively communicated technical information to diverse stakeholders in the past. This will showcase your ability to bridge the gap between technical and non-technical teams.