Rodeo
Get started

Oscar

Director of Security & Compliance

London
£110k – £140k/yr
Posted about 23 hours ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Director of Security & Compliance | London | £110-140k + Benefits

A high-profile organisation with a complex international operating environment is looking for a Director of Security & Compliance to take ownership of its security, governance, risk and compliance function as it enters its next phase of maturity.

This is a newly created senior leadership position, reporting directly to the CTO. With Cyber Essentials Plus already achieved and a 24/7 outsourced SOC in place, the organisation is now focused on achieving ISO 27001 certification, strengthening its governance and compliance framework, and ensuring the secure adoption of a rapidly expanding enterprise AI estate.

You'll become the senior accountable owner for security certifications, organisational risk, business continuity, AI security and governance, and information security - acting as the authoritative voice on cyber and security matters across the organisation.

Location:

London, hybrid (2-3 days onsite)

Package:

£110,000-140,000 + excellent benefits

Key Responsibilities:

  • Own security monitoring, incident response and security tooling, working closely with the outsourced SOC
  • Line manage the IT Security Engineer and lead the organisation-wide security awareness programme
  • Define identity, access and authentication standards, including RBAC, MFA and SSO
  • Own the IT governance framework and regulatory/standards compliance posture
  • Lead the programme to achieve ISO 27001 certification, including defining and managing scope
  • Own the central digital and data security risk register in partnership with Legal & Risk
  • Develop and maintain data classification, retention and GDPR operating frameworks
  • Own disaster recovery and business continuity planning, including RTO/RPO requirements for critical systems
  • Lead security governance across the enterprise AI estate, including access controls, data protection, prompt injection, jailbreaking and third-party AI risk
  • Own and develop the organisation's Responsible Use Policy for AI
  • Lead the DevSecOps security function, including secrets management, vulnerability scanning, pipeline security and workload protection
  • Own third-party security assessments and ongoing supplier/vendor security monitoring
  • Develop and mature the organisation's wider security strategy, policies and control environment

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

What You'll Bring:

  • Significant senior leadership experience across security, cyber, governance, risk and compliance
  • Experience operating within a mid-to-large, complex or internationally distributed organisation
  • Deep, demonstrable ISO 27001 expertise, ideally having led or owned a successful certification programme
  • Strong working knowledge of SOC 2, NIST CSF and other recognised security frameworks
  • Strong technical understanding across SIEM, EDR, IAM, vulnerability management and DevSecOps
  • Proven GDPR and data protection experience, ideally within a multi-jurisdiction environment
  • Strong understanding of AI security and governance, including prompt injection, model risk and third-party AI vendor risk
  • Experience establishing and managing enterprise-level security and risk registers
  • Excellent executive stakeholder management and communication skills
  • A pragmatic approach to security, with the ability to balance risk management with business delivery
  • Experience managing security professionals and outsourced security partners
  • The credibility to operate as the organisation's senior security authority while remaining commercially and strategically focused

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Certifications:

One or more of the following certifications is required:

  • CISSP
  • CISM
  • ISO 27001 Lead Implementer
  • CIPP/E
  • CIPM
  • CRISC
  • CGEIT
  • CCSP
  • AIGP

Please note: candidates must have the legal right to work in the UK.

Apply now for immediate consideration.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Security strategy
Governance
Risk management
Compliance
ISO 27001
Cyber security
AI security
GDPR
DevSecOps
Identity and access management
Business continuity
Disaster recovery
Stakeholder management
Vulnerability management
Data protection
Security monitoring

Location

London, England, United Kingdom

Sign up to applySee more jobs like this