Head of IT & Security
Summary
Lead IT operations and cybersecurity for a fast-growing SaaS company, overseeing global infrastructure, compliance audits, and AI security governance.
How you'll make an impact:
Here's what you'll do:
Core IT Operations Management (Day-to-Day)
-
Lifecycle Management: Oversee the end-to-end onboarding and offboarding processes for all global staff, contractors, consultants ensuring seamless provisioning and de-provisioning of equipment and access.
-
Hardware & Asset Management: Manage procurement, inventory lifecycle, distribution, and maintenance of all corporate hardware.
-
Network Operations: Design, manage, and maintain networking, Wi-Fi, and connectivity infrastructure across office locations.
-
Identity & Access Management: Own the corporate identity architecture, access control lists, single sign-on and multi-factor authentication protocols.
-
Vendor Management: Manage vendor relationships, including, billing, renewals, new vendor onboarding, selection and optimisation.
-
Endpoint Management: Architect, deploy, and maintain Microsoft Intune device policies, compliance baselines, and application deployment for a fully cloud-first environment.
-
Working with RevOps, Data and Platform teams: Understanding the technical requirements for all integrations for corporate systems, owning the architecture of said integrations.
Strategic Security Governance & Compliance (CISO-Style Functionality)
-
Audit Ownership: Lead, coordinate, and successfully execute continuous SOC 2 compliance audits, finance-related security audits, and third-party partner reviews.
-
High-Stakes Partner Audits: Act as the primary technical point of contact for highly rigorous partner audits (e.g., Amazon) as well as integration compliance programs (QuickBooks, Google, Xero).
-
Policy Architecture: Draft, implement, and maintain the lifecycle of all corporate information security policies, standards, and procedures in close collaboration with People & Culture and the SLT.
-
AI Security & Governance: Establish frameworks, acceptable use policies, and technical controls governing the secure implementation and use of AI.
Security Operations, Threat Management & Response
-
Tooling & Architecture: Own and optimize the enterprise security stack, directly managing relationships and configurations with core vendors such as Wiz (cloud security) and CrowdStrike (endpoint protection).
-
Vulnerability & Penetration Testing: Scope, organize, and manage annual third-party penetration testing initiatives, ensuring rapid remediation of identified vulnerabilities.
-
Cross-Functional Advisory: Serve as the definitive escalation point for security tickets and questionnaires originating from customers, prospects, sales teams, engineering, and customer support regarding product security and platform integrity.
-
Legal Liaison: Coordinate with external legal counsel regarding data privacy laws, security incident response readiness, and compliance liabilities.
-
Security Culture: Build, deploy, and monitor an upgraded internal security awareness training and education program to elevate the company's baseline security posture.
Here's what you'll bring:
-
5+ years leading IT operations or a Security function, including meaningful experience directing information security work through a team rather than executing it solo, ideally in a scaling SaaS or tech organization operating across multiple jurisdictions.
-
People leadership experience and a growth mindset, with the ability to manage and develop technical specialists
-
Accountable ownership of a SOC 2 (or equivalent) compliance program and the ability to direct a team through audit prep, control design, and remediation, and to represent the program credibly to auditors, partners, and executives
-
Working knowledge of AI governance and security controls sufficient to set policy direction and evaluate technical recommendations from the security team
-
Ability to direct a security tooling strategy (e.g., cloud security posture management, EDR)
-
Experience overseeing (not necessarily personally running) third-party penetration testing programs, with the judgment to prioritize findings and hold engineering accountable for remediation timelines
-
Comfort acting as the escalation point for external-facing security situations
-
Proven stakeholder management at senior leadership level, with the ability to translate technical risk into business terms
-
Strong vendor and budget management.
In return, we offer:
- Hybrid Working Environment - 3 days work from home per week
- Option to work 30 days every six months fully remote from anywhere in the world
- Celebrate your birthday with a paid day off
- A Global Wellness Day celebrated companywide, providing you a dedicated holiday to focus on your own wellbeing.
- Fully paid health insurance
- Monthly Social Fridays drinks and food on us
- Discounted gym membership as well as discounts at some local eateries etc
- Recruitment referral bonus
- Relaxed dress code
- Modern office in Grafton complete with pool table, table tennis, PS5, Coffee machines etc