Senior IT Security & Compliance Lead

Wordsmith AI
Edinburgh, UK
12 days ago
Apply on www.collegerecruiter.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours

Tech stack

Artificial Intelligence Software as a Service Cyber Security Information Security Management Network Security Network Architecture EndPointSecurity

Job description

Senior IT Security & Compliance Leads own security and compliance at Wordsmith end-to-end - setting the strategy for IT and infrastructure security, running our certification program across SOC 2, ISO 27001, and ISO 42001, embedding responsible-AI practices into how we build and ship product, and making sure privacy and regulatory obligations (GDPR and beyond) are handled properly as we grow.

This is a senior role that blends strategy and hands-on execution. You’ll set multi-year direction, represent Wordsmith’s security posture to executives, customers, and - as we grow - the board, and build the team, tooling, and controls the company needs at the next stage, not just maintain what exists today., * Own SOC 2 Type II, ISO 27001/27017/27018, and ISO 42001 end-to-end - policies, controls, audit evidence, and the audits themselves., * Run our AI governance program, including AI Impact Assessments and model/AI-vendor risk reviews, ensuring responsible, compliant AI use across the product., * Act as the senior voice on security for enterprise deals - security questionnaires, DPAs, and our Trust Center - partnering with Sales, Customer Success, and Legal to unblock deals without cutting corners.

Requirements

  • 8-10+ years in security, IT, or compliance roles, including a track record of owning a security or compliance function end-to-end at a fast-growing SaaS or tech company.
  • Proven experience building or scaling a security/compliance program from an early stage - ideally including time as the sole or founding owner of the function.
  • Deep, hands-on expertise across SOC 2, the ISO 27000 series, and ideally ISO 42001.
  • Strong grounding in core IT security fundamentals - identity & access management, endpoint/device security, and cloud or network infrastructure security.
  • Practical, working knowledge of GDPR and related privacy regulation (ePrivacy, HIPAA, or similar).
  • Experience presenting security posture, risk, and roadmap to executives, boards, or investors.
  • Experience building and/or managing a team - or a clear point of view on how you’d grow one as the function scales.
  • Comfortable owning budget and vendor decisions at a strategic level, not just executing against someone else’s plan.
  • A strong cross-functional operator and executive communicator, bridging Security, IT, Legal/Privacy, Engineering, and GTM., * Prior experience as a Head of Security, Director of Security/IT, or similar senior/leadership title.
  • Relevant certifications - e.g. CISSP/ISC2, CISM, AIGP, CIPP/E, CIPT, CCSK, or FIP.
  • Experience in legal tech, AI, or another highly regulated SaaS environment.
  • Experience designing AI risk or impact-assessment processes from scratch.
  • Familiarity with tools such as Datagrail, MineOS, Whistic, or SafeBase.

Benefits & conditions

You’ll take a senior leadership seat over security and compliance, with real ownership over how the function is shaped and grown.

You’ll sit at the centre of trust for a fast-growing legal AI platform, directly enabling enterprise sales and customer confidence.

You’ll have a clear path to building and leading a team as the function scales with the company.

What you can expect

A small, focused leadership group where your work has visible, immediate impact.

  • Competitive compensation, benefits, and meaningful equity.

How we work

We’re an in-office team in Edinburgh. We work together because it helps us collaborate closely across product, engineering, and legal teams. You should expect to be in the office as your default.

This is a high ownership role. You’ll be trusted to set strategy, represent security to executives and customers, and drive outcomes without heavy oversight. #J-18808-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.collegerecruiter.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:16 min

Securing internal pod communication with network security policies

Marc Nimmerrichter · World Congress 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:10 min

Balancing rapid artificial intelligence development with strict compliance regulations

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

2:11 min

Addressing security audits and regional data compliance legislation

Videos

See all

Related articles

See all