Security Lead in London

Security Lead in London

London Full-Time 63000 - 77000 £ / year (est.) Home office (partial)
T

At a Glance

  • Tasks: Lead security initiatives and enhance controls across product and cloud infrastructure.
  • Company: Join a forward-thinking benefits platform dedicated to uplifting lives.
  • Benefits: Competitive salary, equity, flexible holidays, and comprehensive health support.
  • Other info: Be part of a diverse team committed to inclusivity and respect.
  • Why this job: Own the security function and influence key decisions in a growing company.
  • Qualifications: 4-6 years of hands-on security experience in SaaS or cloud environments.

The predicted salary is between 63000 - 77000 £ per year.

Our Mission
We're not your average benefits platform; we're the unordinary force that uplifts people's lives. Our technology is the link that connects the entire benefits ecosystem, creating better outcomes for employers, employees, brokers, and providers. Our mission is clear: we're here to create a world where everything operates at its very best, ensuring that every employee receives the support they need to live life to the fullest, both at work and beyond.

Your Mission
You'll be Ben's Security Lead - owning security end-to-end across product, cloud infrastructure, internal systems, and trust/compliance. In the same week you might review a pull request, harden AWS IAM controls, and sit opposite a prospect's CISO explaining how Ben handles their data. You'll work closely with the CTO on priorities and direction, but day-to-day you're the one making the calls.

You won’t be starting from scratch. Ben is ISO 27001:2022 certified with established controls across product, AWS, and corporate IT. There's a solid foundation in place - this role is about strengthening it, making it scale, and making sure security’s part of the reason enterprise customers choose Ben.

If you like combining hands-on engineering with practical risk judgement and cross-functional influence - and you're comfortable being the person who owns the answer, this is the role for you.

Things you will be working on…

  • Act as Ben’s security lead in enterprise customer and prospect conversations, questionnaires, due diligence calls, and trust centre content. Security is a reason customers choose Ben - you'll help keep it that way.
  • Own and improve Ben’s security controls across identity, endpoint, cloud infrastructure, product security, and corporate IT.
  • Lead monitoring, detection, incident response, and continuous improvement across the environment.
  • Maintain and mature our ISO 27001-certified ISMS, conducting risk assessments, vendor reviews, and policy/control maintenance to keep our control environment effective and audit-ready.
  • Embed secure-by-design into the development lifecycle - threat modelling, architecture reviews, secure code review, and CI/CD hardening.
  • Over time, lead a pragmatic SOC 2 implementation alongside the existing ISMS, and provide input on GenAI governance as Ben ships AI features in production.

What you'll bring…

  • Hands-on security experience in a SaaS, cloud-first, or product-led environment - you've probably been doing this for 4-6 years and are looking to own a security function for the first time.
  • Strong working knowledge of identity and access management in both corporate and product contexts. We work with Microsoft's security ecosystem a lot (Entra, Intune, Defender) - you'll need to be comfortable there or confident you can get up to speed quickly.
  • Experience securing AWS environments and embedding security into product development, through threat modelling, code review, and CI/CD controls.
  • Experience with endpoint and corporate security - you've worked with EDR, MDM, ZTNA, or similar tooling, even if not the specific stack we use.
  • Familiarity with compliance frameworks (ISO 27001 or SOC 2), and the ability to translate technical controls into audit-ready evidence.
  • Confidence in enterprise customer conversations - you can explain security clearly to technical and non-technical audiences.
  • Comfort with ambiguity and context-switching - you're happy owning the answer across a wide remit rather than specialising in one domain.

Why join us?
You’ll own the security function. Priorities, architecture, tooling, controls, and how it's communicated to customers. That level of ownership at a company with real enterprise customers and a live compliance programme is rare without ten years of politics to get there.

Security at Ben is an enabling function, and directly tied to revenue. Enterprise customers choose us partly because of how we handle their data, and you'll be the person in those conversations. You'll have a direct line to the CTO and genuine influence over product and infrastructure decisions.

The foundation is already built - ISO 27001:2022 certified, established AWS controls and a functioning ISMS. You're not here to put out fires but to take something that works and make it stronger as the company grows into more demanding customers and regulated environments.

Our Compensation & Benefits
It’s important to us to practise what we preach when it comes to our benefits. We know what good looks like and we want to provide the best for our team, with a comprehensive and inclusive benefits package. This means you have a choice over the things that are most important to you.

  • Competitive base salary + equity, so you own what you build.
  • £100 monthly personal Ben Balance: for whatever works for you, whether that's Netflix, Spotify, or a really expensive cup of coffee! This allowance will increase by £50 for each year of service until you reach £250.
  • Weekly lunch provided in office so you can spend quality time with the team over some tasty food!
  • 28 days of holidays a year plus bank holidays, and an option to buy or sell 2 days per year. Also, your annual holiday entitlement will increase to 30 days after your 3rd year of service! Day off for your birthday.
  • Work-from-abroad scheme, so you can support your travels, enjoy an extended holiday, or visit loved ones.
  • Enhanced parental leave and workplace nursery scheme to support with the cost of childcare in a nursery setting.
  • Comprehensive Private Medical Insurance.
  • Funded Life Assurance cover with the option to voluntarily increase - this also includes an annual health check.
  • Comprehensive and tailored mental health support and professional coaching through a leading provider.

Diversity and Culture at Ben
We are organically growing a brilliantly diverse, inclusive and respectful bunch of people we are extremely proud of. This should go without saying but all applications are very much welcome. If you need any adjustments to support you with your application, just let us know by emailing.

Security Lead in London employer: Thanks Ben

Thanks Ben is an exceptional employer that prioritises a culture of trust, collaboration, and continuous improvement. As a Security Lead, you will have the opportunity to work closely with senior leadership, driving impactful security initiatives while benefiting from professional development opportunities in a dynamic environment. Located in a vibrant tech hub, the company offers a supportive atmosphere that encourages innovation and values your contributions to safeguarding enterprise SaaS security.

T

Contact Details:

Thanks Ben Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Security Lead in London

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Thanks Ben, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Thanks Ben

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Thanks Ben. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Security Lead in London

Security Leadership
AWS Security
Identity and Access Management
Incident Response
ISO 27001
SOC 2 Implementation
Threat Modelling

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Thanks Ben insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Thanks Ben that you’re committed to staying ahead in the game.

How to prepare for a job interview at Thanks Ben

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Thanks Ben to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Thanks Ben.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.