Senior IT Security & Compliance Lead

Senior IT Security & Compliance Lead

Full-Time 63000 - 77000 £ / year (est.) No working from home possible
Wordsmith AI

At a Glance

  • Tasks: Lead security and compliance strategy for a cutting-edge AI legal tech company.
  • Company: Join Wordsmith, a fast-growing AI-enabled command centre for legal teams.
  • Benefits: Competitive salary, equity, and a collaborative office environment in Edinburgh.
  • Other info: Build and lead a team while making a real difference in enterprise trust.
  • Why this job: Shape the future of security and compliance in a dynamic, impactful role.
  • Qualifications: 8-10+ years in security/compliance with hands-on expertise in SOC 2 and ISO standards.

The predicted salary is between 63000 - 77000 £ per year.

Wordsmith is building the AI-enabled command centre for in-house legal teams. Our customers are some of the most demanding enterprise legal departments in the world, and they hold us to a high bar on security, privacy, and responsible AI. We're looking for a senior leader to take ownership of security and compliance as we scale.

The Role

  • Own security and compliance at Wordsmith end-to-end — setting the strategy for IT and infrastructure security, running our certification program across SOC 2, ISO 27001, and ISO 42001, embedding responsible-AI practices into how we build and ship product, and making sure privacy and regulatory obligations (GDPR and beyond) are handled properly as we grow.
  • This is a senior role that blends strategy and hands-on execution. You'll set multi-year direction, represent Wordsmith's security posture to executives, customers, and — as we grow — the board, and build the team, tooling, and controls the company needs at the next stage, not just maintain what exists today.

What You'll Do

  • Security Strategy & Leadership: Own Wordsmith's multi-year IT security and compliance roadmap — setting priorities, budget, and tooling decisions in partnership with Engineering and company leadership.
  • IT & Infrastructure Security: Own security architecture across corporate IT and infrastructure — identity & access management, endpoint protection, and cloud/network security — and lead incident response when issues arise.
  • Compliance & Certification: Own SOC 2 Type II, ISO 27001/27017/27018, and ISO 42001 end-to-end — policies, controls, audit evidence, and the audits themselves.
  • AI Governance: Run our AI governance program, including AI Impact Assessments and model/AI-vendor risk reviews, ensuring responsible, compliant AI use across the product.
  • Privacy Operations: Own privacy operations end-to-end — GDPR and other regulatory obligations, DPIAs, RoPA maintenance, sub-processor management, and Data Subject Request fulfilment.
  • Third-Party & Vendor Risk: Assess vendors and AI tools for security, privacy, and AI risk before they're adopted, and put the right contractual safeguards in place at a program level.
  • Team & Function Building: Build the people, process, and tooling the function needs as it scales — starting as the senior owner of the program today, with a mandate to build out a team as Wordsmith grows.
  • Executive & Board Reporting: Own risk and compliance reporting to leadership and, as we scale, the board — translating technical risk into business terms.
  • Customer & Deal Support: Act as the senior voice on security for enterprise deals — security questionnaires, DPAs, and our Trust Center — partnering with Sales, Customer Success, and Legal to unblock deals without cutting corners.
  • Automation & Tooling: Build lean, automation-first tooling (e.g. Vanta) for evidence collection and ongoing compliance monitoring, so the program scales without scaling headcount unnecessarily.

What we're looking for

  • Essential: 8-10+ years in security, IT, or compliance roles, including a track record of owning a security or compliance function end-to-end at a fast-growing SaaS or tech company.
  • Proven experience building or scaling a security/compliance program from an early stage — ideally including time as the sole or founding owner of the function.
  • Deep, hands-on expertise across SOC 2, the ISO 27000 series, and ideally ISO 42001.
  • Strong grounding in core IT security fundamentals — identity & access management, endpoint/device security, and cloud or network infrastructure security.
  • Practical, working knowledge of GDPR and related privacy regulation (ePrivacy, HIPAA, or similar).
  • Experience presenting security posture, risk, and roadmap to executives, boards, or investors.
  • Experience building and/or managing a team — or a clear point of view on how you'd grow one as the function scales.
  • Comfortable owning budget and vendor decisions at a strategic level, not just executing against someone else's plan.
  • A strong cross-functional operator and executive communicator, bridging Security, IT, Legal/Privacy, Engineering, and GTM.

Valued

  • Prior experience as a Head of Security, Director of Security/IT, or similar senior/leadership title.
  • Relevant certifications — e.g. CISSP/ISC2, CISM, AIGP, CIPP/E, CIPT, CCSK, or FIP.
  • Experience in legal tech, AI, or another highly regulated SaaS environment.
  • Experience designing AI risk or impact-assessment processes from scratch.
  • Familiarity with tools such as Datagrail, MineOS, Whistic, or SafeBase.

Why this role matters

  • You'll take a senior leadership seat over security and compliance, with real ownership over how the function is shaped and grown.
  • You'll sit at the centre of trust for a fast-growing legal AI platform, directly enabling enterprise sales and customer confidence.
  • You'll have a clear path to building and leading a team as the function scales with the company.

What you can expect

  • A small, focused leadership group where your work has visible, immediate impact.
  • Competitive compensation, benefits, and meaningful equity.

How we work

  • We're an in-office team in Edinburgh. We work together because it helps us collaborate closely across product, engineering, and legal teams. You should expect to be in the office as your default.
  • This is a high ownership role. You'll be trusted to set strategy, represent security to executives and customers, and drive outcomes without heavy oversight.

Senior IT Security & Compliance Lead employer: Wordsmith AI

Wordsmith is an exceptional employer, offering a dynamic work environment in London where innovation meets collaboration. As a Partner Manager, you'll enjoy competitive compensation and benefits while playing a crucial role in shaping the future of legal technology. With a strong focus on employee growth and a culture that values autonomy and teamwork, Wordsmith empowers you to make a meaningful impact in the industry.

Wordsmith AI

Contact Details:

Wordsmith AI Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior IT Security & Compliance Lead

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Wordsmith AI, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Wordsmith AI

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Wordsmith AI. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Senior IT Security & Compliance Lead

IT Security Strategy
Compliance Management
SOC 2
ISO 27001
ISO 42001
Identity & Access Management
Endpoint Protection

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Wordsmith AI insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Wordsmith AI that you’re committed to staying ahead in the game.

How to prepare for a job interview at Wordsmith AI

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Wordsmith AI to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Wordsmith AI.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.