IT Security & Compliance Lead

IT Security & Compliance Lead

Full-Time No working from home possible
Wordsmith

At a Glance

  • Tasks: Lead IT security and compliance initiatives while shaping security strategy at a fast-growing AI company.
  • Company: Join Wordsmith, a cutting-edge firm revolutionising legal tech with AI solutions.
  • Benefits: Enjoy a hybrid work model, competitive salary, and opportunities for professional growth.
  • Other info: Collaborate with diverse teams and gain visibility with leadership in a dynamic environment.
  • Why this job: Make a real impact in security and compliance while working with innovative technology.
  • Qualifications: Experience in IT security operations and familiarity with compliance frameworks required.

IT Security & Compliance Lead at wordsmith. About the role Wordsmith develops artificial intelligence-driven command center solutions designed specifically for legal departments seeking to modernize their operations. The company is actively looking for a skilled professional to build out and lead the IT security function from the ground up while simultaneously managing compliance initiatives during a period of significant infrastructure growth. This position offers a unique opportunity to shape security strategy and governance practices at a rapidly scaling organization operating at the intersection of legal technology and artificial intelligence. You will serve as the primary owner of security operations and compliance frameworks, working cross‑functionally to protect company assets and maintain customer trust.

Key facts

Location: Edinburgh Engagement: Full-time Team: General and Administrative

What you'll do

  • Administer and maintain device compliance programs across the organization, implementing and managing mobile device management solutions through platforms such as Jamf or Microsoft Intune to ensure all endpoints meet security standards and corporate policies.
  • Take ownership of identity and access management processes, including user provisioning, deprovisioning, and enforcement of least‑privilege access principles using Okta as the primary identity platform to control authentication and authorization across all systems.
  • Strengthen and secure cloud infrastructure by implementing robust security controls within Amazon Web Services environments, including network segmentation, encryption standards, logging configurations, and vulnerability management practices.
  • Lead security incident response activities from initial detection through resolution, coordinating investigations with external Security Operations Center as a Service providers, managing communication with stakeholders, and conducting thorough post‑incident reviews to identify lessons learned and preventive measures.
  • Deploy, configure, and maintain a comprehensive suite of security monitoring tools including endpoint detection and response solutions, data loss prevention systems, and security information and event management platforms to provide visibility into potential threats.
  • Oversee the maintenance and continuous improvement of SOC 2 Type II certification along with ISO 27001, ISO 27017, and ISO 27018 certifications, implementing audit evidence automation to streamline compliance workflows and reduce manual documentation burdens.
  • Conduct thorough security and privacy risk assessments for third‑party vendors, software tools, and artificial intelligence solutions before integration into the company technology stack, ensuring alignment with organizational risk tolerance and regulatory requirements.
  • Contribute to the development and execution of the AI governance program, participating in internal risk reviews to evaluate potential security implications of machine learning models and automated decision‑making systems.
  • Partner with Sales, Legal, and Customer Success teams to complete security questionnaires from prospective and existing customers, negotiate security‑related contract terms, and manage the external Trust Center to communicate the company security posture effectively.
  • Develop and maintain security policies, procedures, and documentation that align with industry best practices and regulatory requirements while remaining practical for implementation across the organization.
  • Create and deliver security awareness training programs to educate employees on emerging threats, phishing prevention, data handling practices, and their individual responsibilities in maintaining organizational security.
  • Monitor the evolving threat landscape and regulatory environment to proactively identify risks and recommend appropriate countermeasures before they impact business operations.

Requirements

  • Demonstrated experience managing IT security operations within a high‑growth software as a service company, with understanding of the unique challenges and pace associated with rapidly scaling technology organizations.
  • Strong proficiency with mobile device management platforms, particularly Jamf for Apple ecosystem management or Microsoft Intune for cross‑platform device administration and compliance enforcement.
  • Hands‑on technical background working with Okta for identity and access management, including single sign‑on configuration, multi‑factor authentication implementation, and lifecycle management automation.
  • Practical experience securing Amazon Web Services environments, including familiarity with IAM policies, security groups, CloudTrail logging, GuardDuty threat detection, and other native AWS security services.
  • Proven track record leading security incident response from detection through remediation, with ability to remain calm under pressure and coordinate effectively with internal and external stakeholders during active incidents.
  • Working knowledge of SOC 2 Type II audit requirements and ISO 27000 series standards, with experience preparing evidence, managing auditor relationships, and addressing findings.
  • Experience deploying and operating endpoint detection and response, data loss prevention, or security information and event management platforms in production environments.
  • Strong collaboration skills with demonstrated ability to work effectively across IT, Engineering, and Go‑To‑Market functions to achieve security objectives without impeding business velocity.

Nice to have

  • Familiarity with General Data Protection Regulation requirements and emerging AI governance frameworks such as ISO 42001 for artificial intelligence management systems.
  • Professional certifications demonstrating security and privacy expertise, such as Certified Information Systems Security Professional, Certificate of Cloud Security Knowledge, Certified Information Privacy Professional for Europe, or AI Governance Professional credentials.
  • Previous experience working within legal technology, artificial intelligence, or other regulated software as a service sectors where security and compliance requirements are particularly stringent.
  • Hands‑on experience with specific security and compliance tools including Vanta for compliance automation, Crowdstrike for endpoint protection, Zscaler for secure access, Datadog for monitoring, or Whistic for security questionnaire management.
  • Background in building security programs from early stages rather than inheriting mature existing frameworks.
  • Experience with secure software development lifecycle practices and ability to partner with engineering teams on application security initiatives.

Skills & tools

  • Mobile Device Management platforms including Jamf and Microsoft Intune
  • Identity and Access Management using Okta
  • Cloud Security within Amazon Web Services environments
  • Security Operations tooling including Endpoint Detection and Response, Data Loss Prevention, and Security Information and Event Management solutions
  • Compliance frameworks including SOC 2 Type II, ISO 27001, ISO 27017, and ISO 27018
  • Vendor risk assessment and third‑party security evaluation
  • Security awareness training and policy development
  • Incident response and forensic investigation coordination

Practical notes

This position follows a hybrid working arrangement based out of the Edinburgh office location. Regular in‑office presence is expected to enable effective collaboration with product, engineering, and legal teams who work closely with security and compliance functions. The role reports into the General and Administrative organization and will have significant visibility with leadership given the critical nature of security and compliance in building customer trust and enabling enterprise sales. Candidates should be prepared to balance strategic planning with hands‑on technical work, particularly during the initial phase of building

#J-18808-Ljbffr

IT Security & Compliance Lead employer: Wordsmith

Wordsmith is an exceptional employer for Product Engineers, offering a dynamic work environment in Edinburgh where innovation thrives. With a strong focus on AI integration, employees enjoy real ownership of their projects and the opportunity to collaborate closely with a talented team, ensuring rapid personal and professional growth. The company's commitment to a high-trust culture and competitive compensation makes it an attractive place for those looking to make a meaningful impact in the legal tech space.

Wordsmith

Contact Details:

Wordsmith Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land IT Security & Compliance Lead

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Wordsmith, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Wordsmith

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Wordsmith. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace IT Security & Compliance Lead

IT Security Operations Management
Compliance Frameworks (SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018)
Mobile Device Management (Jamf, Microsoft Intune)
Identity and Access Management (Okta)
Cloud Security (Amazon Web Services)
Security Incident Response
Security Monitoring Tools (Endpoint Detection and Response, Data Loss Prevention, Security Information and Event Management)

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Wordsmith insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Wordsmith that you’re committed to staying ahead in the game.

How to prepare for a job interview at Wordsmith

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Wordsmith to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Wordsmith.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.