At a Glance
- Tasks: Lead and build Omaze's security strategy from the ground up.
- Company: Join a fast-growing company making a real social impact.
- Benefits: Generous stock options, private medical insurance, and a personal development budget.
- Other info: Collaborative culture focused on diversity and meaningful impact.
- Why this job: Shape the future of security in a dynamic, hands-on environment.
- Qualifications: Senior security leadership experience and ISO 27001 certification knowledge.
The predicted salary is between 80000 - 100000 € per year.
Location: London
Employment Type: Full time
Location Type: Hybrid
Department: Technology
Who We Are: At Omaze, we give our community in the UK and Germany the chance to win luxury homes and other life-changing prizes — all while raising money for the causes they love. Thanks to our Omaze Community, we’ve raised over £100 million for UK charities in just five years. That’s millions helping organisations like Age UK, the RSPCA, British Heart Foundation and Great Ormond Street Hospital Charity deliver life‑saving work. And the best part? We’re only just getting started. Omaze is building a business and culture committed to growth and creating significant social impact on a global scale.
About The Job: We’re looking for a Head of Security to take ownership of Omaze’s end‑to‑end security posture at a pivotal moment in our growth. As we scale, expand into new territories, and mature our operational foundations, security is moving from a shared responsibility to a critical, business‑wide priority. Right now, it sits across Engineering and IT — but we need a dedicated leader to bring it together into a clear, structured, and scalable programme. This is a rare opportunity to build a security function from the ground up. You’ll define our strategy, implement the right controls, and establish the frameworks we need to support our next stage — from ISO 27001 certification to investor scrutiny. You’ll be just as comfortable operating at board level as you are rolling up your sleeves to get things done. At Omaze, everyone is hands‑on — including our exec team — and this role is no exception.
What You’ll Be Doing:
- Owning Omaze’s security posture end‑to‑end across AWS, SaaS platforms, and employee devices
- Building and delivering a company‑wide security strategy aligned to our growth, IPO readiness, and regulatory landscape
- Leading our ISO 27001 certification journey, including gap analysis, roadmap creation, and delivery
- Establishing and embedding a robust Information Security Management System (ISMS)
- Designing and implementing a formal GDPR and data protection programme
- Defining and owning our incident response plan — and leading response during security events
- Working with IT in MDM processes and strengthening endpoint security across the business
- Conducting security reviews across our infrastructure and tooling (AWS, Google Workspace, Slack, Shopify, Stripe, etc.)
- Owning relationships with external partners (e.g., auditors, pen testers, security vendors)
- Bringing clarity and visibility to risk through regular board‑level reporting
- Building a strong security culture through awareness, education, and practical guidance
- Laying the foundations for a future security team
About You:
- You’ve operated in a senior security leadership role (Head of, Director, or similar), ideally in a high‑growth or scaling tech environment
- You’re experienced in building security programmes from scratch — not just maintaining them
- You’ve successfully led or been deeply involved in ISO 27001 certification
- You’re comfortable balancing strategic thinking with hands‑on execution
- You understand the realities of GDPR and data protection in a consumer‑focused business
- You’ve worked in environments preparing for major milestones like IPO, enterprise expansion, or regulatory scrutiny
- You can confidently communicate with senior stakeholders, including execs, investors, and auditors
- You’re pragmatic — you know how to prioritise and deliver impact without overcomplicating things
- You’re naturally collaborative and can influence across Engineering, Product, Legal, and beyond
- You care about building something meaningful and want to have a real impact on how we scale
What’s In It For You:
- Generous stock options scheme
- 25 days annual leave PLUS Bank Holidays
- Private medical and dental insurance
- 9% employer pension contributions, when you contribute at least 2%
- A generous personal learning and development budget each year to use on training courses, conferences and professional memberships
- Personal equipment budget to work from home
- Enhanced family leave policies
- Life assurance of 4x your salary
DEI Statement: We actively seek out diversity of thought and experience to drive innovation. We welcome all backgrounds, identities, and perspectives and work hard to ensure that every Omaze employee can bring their authentic self to work at all times.
Head of IT Security employer: Omaze
Omaze is an exceptional employer that fosters a dynamic and inclusive work culture, where employees are empowered to make a meaningful impact while contributing to charitable causes. With generous benefits such as stock options, extensive learning budgets, and a commitment to personal growth, the Head of IT Security will thrive in a collaborative environment that values innovation and hands-on leadership. Located in London, this hybrid role offers the unique opportunity to build a security function from the ground up, ensuring a pivotal role in the company's ambitious growth journey.
StudySmarter Expert Advice🤫
We think this is how you could land Head of IT Security
✨Tip Number 1
Network like a pro! Reach out to folks in your industry on LinkedIn or at events. A personal connection can often get you noticed faster than a CV.
✨Tip Number 2
Prepare for interviews by researching the company and its culture. Show them you’re not just another candidate, but someone who genuinely cares about their mission and values.
✨Tip Number 3
Practice your pitch! Be ready to explain how your skills align with their needs. Tailor your experience to highlight what makes you the perfect fit for the Head of IT Security role.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re serious about joining the team!
We think you need these skills to ace Head of IT Security
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Head of IT Security role. Highlight your experience in building security programmes and leading ISO 27001 certification. We want to see how your skills align with our mission at Omaze!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Share your passion for security and how you can contribute to our growth. Let us know why you’re excited about the opportunity to build something meaningful with us.
Showcase Your Hands-On Experience:We love candidates who are hands-on! In your application, mention specific examples where you've rolled up your sleeves to tackle security challenges. This will show us that you're ready to dive into the role.
Apply Through Our Website:Don’t forget to apply through our website! It’s the best way for us to receive your application and ensures you’re considered for this exciting opportunity. We can’t wait to hear from you!
How to prepare for a job interview at Omaze
✨Know Your Security Fundamentals
Make sure you brush up on the key principles of IT security, especially around ISO 27001 and GDPR. Be ready to discuss how you've implemented these in previous roles, as this will show your depth of knowledge and experience.
✨Showcase Your Leadership Skills
Since this role is about building a security function from scratch, be prepared to share examples of how you've led teams or projects in the past. Highlight your ability to balance strategic thinking with hands-on execution, as this is crucial for the position.
✨Understand Omaze's Mission
Familiarise yourself with Omaze’s community impact and how security plays a role in their operations. Being able to connect your security strategies to their mission will demonstrate your alignment with their values and goals.
✨Prepare for Board-Level Discussions
Since you'll need to communicate with senior stakeholders, practice articulating complex security concepts in simple terms. Think about how you would report on risk and security posture to the board, as this will be a key part of your role.