Head of IT Security in London

Head of IT Security in London

London Full-Time 80000 - 100000 € / year (est.) No home office possible
O

At a Glance

  • Tasks: Lead and build Omaze's security strategy from the ground up, ensuring robust protection across all platforms.
  • Company: Join a fast-growing tech company focused on innovation and security.
  • Benefits: Generous stock options, 25 days leave, private health insurance, and a personal development budget.
  • Other info: Collaborative culture with opportunities for personal and professional growth.
  • Why this job: Make a real impact by shaping security at a pivotal moment in our growth journey.
  • Qualifications: Senior security leadership experience, ISO 27001 knowledge, and strong communication skills.

The predicted salary is between 80000 - 100000 € per year.

About The Job

We're looking for a Head of Security to take ownership of Omaze's end-to-end security posture at a pivotal moment in our growth. As we scale, expand into new territories, and mature our operational foundations, security is moving from a shared responsibility to a critical, business-wide priority. Right now, it sits across Engineering and IT — but we need a dedicated leader to bring it together into a clear, structured, and scalable programme. This is a rare opportunity to build a security function from the ground up. You'll define our strategy, implement the right controls, and establish the frameworks we need to support our next stage — from ISO 27001 certification to investor scrutiny. You'll be just as comfortable operating at board level as you are rolling up your sleeves to get things done. At Omaze, everyone is hands-on — including our exec team — and this role is no exception.

What You'll Be Doing

  • Owning Omaze's security posture end-to-end across AWS, SaaS platforms, and employee devices
  • Building and delivering a company-wide security strategy aligned to our growth, IPO readiness, and regulatory landscape
  • Leading our ISO 27001 certification journey, including gap analysis, roadmap creation, and delivery
  • Establishing and embedding a robust Information Security Management System (ISMS)
  • Designing and implementing a formal GDPR and data protection programme
  • Defining and owning our incident response plan — and leading response during security events
  • Working with IT in MDM processes and strengthening endpoint security across the business
  • Conducting security reviews across our infrastructure and tooling (AWS, Google Workspace, Slack, Shopify, Stripe, etc.)
  • Owning relationships with external partners (e.g. auditors, pen testers, security vendors)
  • Bringing clarity and visibility to risk through regular board-level reporting
  • Building a strong security culture through awareness, education, and practical guidance
  • Laying the foundations for a future security team

About You

  • You've operated in a senior security leadership role (Head of, Director, or similar), ideally in a high-growth or scaling tech environment
  • You're experienced in building security programmes from scratch — not just maintaining them
  • You've successfully led or been deeply involved in ISO 27001 certification
  • You're comfortable balancing strategic thinking with hands‐on execution
  • You understand the realities of GDPR and data protection in a consumer-focused business
  • You've worked in environments preparing for major milestones like IPO, enterprise expansion, or regulatory scrutiny
  • You can confidently communicate with senior stakeholders, including execs, investors, and auditors
  • You're pragmatic — you know how to prioritise and deliver impact without overcomplicating things
  • You're naturally collaborative and can influence across Engineering, Product, Legal, and beyond
  • You care about building something meaningful and want to have a real impact on how we scale

What's In It For You

  • Generous stock options scheme
  • 25 days annual leave PLUS Bank Holidays
  • Private medical and dental insurance
  • 9% employer pension contributions, when you contribute at least 2%
  • A generous personal learning and development budget each year to use on training courses, conferences and professional memberships
  • Personal equipment budget to work from home
  • Enhanced family leave policies
  • Life assurance of 4x your salary

DEI Statement

We actively seek out diversity of thought and experience to drive innovation. We welcome all backgrounds, identities, and perspectives and work hard to ensure that every Omaze employee can bring their authentic self to work at all times.

Head of IT Security in London employer: Omaze, Inc.

Omaze is an exceptional employer that offers a unique opportunity for the Head of IT Security to shape and lead a critical security function during a transformative phase of growth. With a strong emphasis on hands-on leadership, a collaborative work culture, and generous benefits including stock options, private medical insurance, and a personal development budget, employees are empowered to make a meaningful impact while enjoying a supportive environment that values diversity and innovation.

O

Contact Detail:

Omaze, Inc. Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Head of IT Security in London

Tip Number 1

Network like a pro! Reach out to folks in the industry, attend meetups, and connect with potential colleagues on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Prepare for interviews by researching the company and its security posture. Understand their tech stack and be ready to discuss how your experience aligns with their needs. We want to see you shine and show us why you're the perfect fit!

Tip Number 3

Don’t just wait for job postings; be proactive! Reach out directly to companies you admire, like Omaze, and express your interest in contributing to their security efforts. A little initiative can go a long way!

Tip Number 4

Follow up after interviews with a thank-you note. It’s a simple gesture that shows your appreciation and keeps you top of mind. Plus, it gives you another chance to reiterate your enthusiasm for the role!

We think you need these skills to ace Head of IT Security in London

Security Strategy Development
ISO 27001 Certification
Information Security Management System (ISMS)
GDPR Compliance
Incident Response Planning
Endpoint Security Management
Risk Assessment and Reporting

Some tips for your application 🫡

Tailor Your CV:Make sure your CV speaks directly to the job description. Highlight your experience in building security programmes and leading ISO 27001 certification, as these are key for us at Omaze.

Craft a Compelling Cover Letter:Use your cover letter to tell us why you're the perfect fit for the Head of IT Security role. Share specific examples of how you've successfully managed security in high-growth environments.

Show Your Hands-On Approach:We love candidates who can roll up their sleeves! In your application, mention times when you’ve been hands-on in implementing security strategies or responding to incidents.

Apply Through Our Website:Don’t forget to apply through our website! It’s the best way for us to receive your application and ensures you’re considered for this exciting opportunity.

How to prepare for a job interview at Omaze, Inc.

Know Your Security Fundamentals

Make sure you brush up on the key principles of IT security, especially around ISO 27001 and GDPR. Be ready to discuss how you've implemented these frameworks in previous roles, as this will show your depth of knowledge and hands-on experience.

Showcase Your Strategic Vision

Prepare to articulate a clear vision for building a security function from the ground up. Think about how you would align security strategies with business growth and IPO readiness, and be ready to share specific examples of how you've done this before.

Demonstrate Hands-On Leadership

Omaze values leaders who are not afraid to roll up their sleeves. Be prepared to discuss times when you've taken a hands-on approach to security challenges, whether it’s leading incident response or conducting security reviews across various platforms.

Engage with Stakeholders

Since you'll be communicating with senior stakeholders, practice how you would present complex security concepts in a straightforward manner. Think about how you can build relationships with different teams and external partners, and be ready to share your collaborative experiences.