> Markdown version of [/jobs/ext/2824673-senior-it-security-compliance-lead](https://www.wearedevelopers.com/jobs/ext/2824673-senior-it-security-compliance-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior IT Security & Compliance Lead - **Company:** Wordsmith AI - **Location:** Edinburgh, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software as a Service, Cyber Security, Information Security Management, Network Security, Network Architecture, EndPointSecurity - **Published:** September 10, 2026 - **Apply:** https://www.collegerecruiter.com/job/2840581580-senior-it-security--compliance-lead ## About the Role * 8-10+ years in security, IT, or compliance roles, including a track record of owning a security or compliance function end-to-end at a fast-growing SaaS or tech company. * Proven experience building or scaling a security/compliance program from an early stage - ideally including time as the sole or founding owner of the function. * Deep, hands-on expertise across SOC 2, the ISO 27000 series, and ideally ISO 42001. * Strong grounding in core IT security fundamentals - identity & access management, endpoint/device security, and cloud or network infrastructure security. * Practical, working knowledge of GDPR and related privacy regulation (ePrivacy, HIPAA, or similar). * Experience presenting security posture, risk, and roadmap to executives, boards, or investors. * Experience building and/or managing a team - or a clear point of view on how you'd grow one as the function scales. * Comfortable owning budget and vendor decisions at a strategic level, not just executing against someone else's plan. * A strong cross-functional operator and executive communicator, bridging Security, IT, Legal/Privacy, Engineering, and GTM., * Prior experience as a Head of Security, Director of Security/IT, or similar senior/leadership title. * Relevant certifications - e.g. CISSP/ISC2, CISM, AIGP, CIPP/E, CIPT, CCSK, or FIP. * Experience in legal tech, AI, or another highly regulated SaaS environment. * Experience designing AI risk or impact-assessment processes from scratch. * Familiarity with tools such as Datagrail, MineOS, Whistic, or SafeBase. ## Description Senior IT Security & Compliance Leads own security and compliance at Wordsmith end-to-end - setting the strategy for IT and infrastructure security, running our certification program across SOC 2, ISO 27001, and ISO 42001, embedding responsible-AI practices into how we build and ship product, and making sure privacy and regulatory obligations (GDPR and beyond) are handled properly as we grow. This is a senior role that blends strategy and hands-on execution. You'll set multi-year direction, represent Wordsmith's security posture to executives, customers, and - as we grow - the board, and build the team, tooling, and controls the company needs at the next stage, not just maintain what exists today., * Own SOC 2 Type II, ISO 27001/27017/27018, and ISO 42001 end-to-end - policies, controls, audit evidence, and the audits themselves., * Run our AI governance program, including AI Impact Assessments and model/AI-vendor risk reviews, ensuring responsible, compliant AI use across the product., * Act as the senior voice on security for enterprise deals - security questionnaires, DPAs, and our Trust Center - partnering with Sales, Customer Success, and Legal to unblock deals without cutting corners. ## Related Videos - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Small, Secure, Interconnected: The next Internet Protocol](https://www.wearedevelopers.com/videos/100062-small-secure-interconnected-the-next-internet-protocol) - [WWC24 - Chris Wysopal, Helmut Reisinger and Johannes Steger - Fighting Digital Threats in the Age of AI](https://www.wearedevelopers.com/videos/926-wwc24-chris-wysopal-helmut-reisinger-and-johannes-steger-fighting-digital-threats-in-the-age-of-ai) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Blockchains: One Size doesn't Fit All](https://www.wearedevelopers.com/videos/409-blockchains-one-size-doesn-t-fit-all) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production)