Head of Security and IT
Summary
Leads global security and IT across seven countries, managing SOC 2 compliance, policy, and 24/7 operations. Oversees identity management, budgeting, and a distributed team using Google Workspace and Jira.
- Lead
security and IT for the whole company. You are the single owner of
both, for every entity in seven countries (US, UK, Singapore, Kenya,
Philippines, India, South Africa), reporting to the COO and leading
a team of five in India, the Philippines, and Kenya.
- Set
the security strategy and stand behind it with clients. You own SOC
2 Type II, the annual audit and penetration test, incident response
with the General Counsel, and the security answers in every RFP and
client audit we face.
- Own
every policy and process document across security and IT. Write
them, keep them current and version controlled; run the training and
phishing simulations that make people follow them, with completion
reported by country.
- Set
the global standard for identity and access and enforce it
everywhere. Google Workspace, Microsoft 365, zero trust in Chrome
Enterprise Premium, and best-practice for Administrator management.
- Own
the company's position on AI. Which models are approved for which
data, enforced through access controls, including the AI features
that switch on inside software we already own.
- Run
IT as a 24/7 service across seven countries. The Jira queue and its
service levels, HR to IT automation so leavers lose access on their
last day, and assets from purchase to disposal.
- Own
the cost of every subscription we hold. Build and run the cost model
with Finance: what we pay, which entity and team it belongs to, what
each renewal should cost, and where we are paying for seats nobody
uses. You bring the savings, not just the invoices.
- Lead
and develop the team. Shift rota covering US, European, and Asian
hours, a deputy who can hold the queue, continuity and disaster
recovery plans tested per entity, and monthly reporting to the COO
on service, risk, compliance, and spend.
Requirements
- Has
been the accountable owner of security and IT for a company or a
large division, with eight or more years in the field, three of them
leading a team across more than one country.
- Deep
Google Workspace administration at organisation level, plus
Microsoft 365 and Entra ID, and hands on zero trust (Chrome
Enterprise Premium, BeyondCorp, Zscaler, or Cloudflare Access).
- Has
taken a company through SOC 2 Type II in Vanta, Drata, or Sprinto,
and wrote the policies and procedures rather than inheriting them.
- Has
scoped penetration tests, run phishing programmes, and written and
tested continuity plans.
- Has
owned a software subscription budget alongside Finance: tracking
spend, allocating cost to entities and teams, negotiating renewals,
and removing seats. Be ready to quote what you saved and how.
- Has
represented a company to client security teams: questionnaires,
audits, and RFPs.
- Has
run a service desk to service levels across time zones, ideally
Jira, building automation across functions to provide a seamless
user experience.
- Desirable:
ISO 27001; GDPR, PDPA, DPDP, POPIA; CISSP, CISM, or CCSP; scripting
in Apps Script, Python, or PowerShell.