Head of Information Security

Posted 7 Days Ago
Be an Early Applicant
London, Greater London, England, GBR
Hybrid
Senior level
Marketing Tech
The Role
Lead rebuilding of security, privacy and resilience programmes. Own strategy, governance and incident response; drive BC/DR, cloud and third-party security, GDPR/PCI compliance, board reporting, and embed security into engineering and delivery.
Summary Generated by Built In
MOO brings brands to life in a sustainable way, with a range of remarkable print and merchandise products. We combine design, technology, manufacturing and service, so that people can connect in memorable ways. Not online but out there, in real life.
 
We started in 2004. Since then we’ve built an award-winning and much-loved brand, with customer satisfaction and Trustpilot ratings that make most businesses want to give up and hire an army of review bots. We’ve got half a million customers, mostly small and medium businesses in North America, the UK, and Europe – businesses that, like us, get all excited about putting something real and beautiful into people’s hands. Does that make us nerds? Probably, and we’re ok with that. 
 
We’ve been given the highest business award in Britain, ‘The Queen’s Award for Enterprise’. Backed by venture capital, we’re part of Tech Nation’s ‘Future Fifty’, recently passing $1bn in lifetime revenue, and featuring in the Guardian’s top 10 UK start-ups list. Ok, we’ll stop bragging now.
 
Today, we’re more than 400 people with our global HQ in London, UK, while we also have premises in Dagenham. In the US, you’ll find us in Boston, MA, as well as East Providence, RI and Denver, CO and with our most recent office expansion in Cape Town South Africa.

MOO is seeking an experienced Head of Information Security to review and re-build our security, privacy and resilience capabilities from the ground up and, in the first 12 months, to act as build lead for the digital and security aspects of a company-wide Business Continuity, Disaster Recovery and Incident Response programme.

This is a standalone role, reporting to the Head of Legal It is not a caretaker or compliance-only position. You will operate as a hands-on builder defining strategy, establishing governance, writing playbooks, and directly influencing Engineering's roadmap and delivery practices to embed security, privacy and resilience by design.

The Person We Want

    We’re looking for a hands-on builder with a proven track record of building security, privacy and resilience programmes from the ground up.

    You’ll be comfortable working with executive and board level, while also getting into the details of security incident response, business continuity, disaster recovery, cloud security and data privacy.

    You’ll be pragmatic and business-focused, balancing security with delivery velocity and availability, and have a collaborative mindset as a partner, not an auditor or advisor.

Responsibilities

     
    Strategic Security Leadership & Governance
     
  • Define and own information security strategy aligned with business objectives.
  • Establish security governance framework, including policies, standards, risk management and risk appetite.
  • Chair the Security Governance Forum and run a board-level reporting cadence.
  • Build a security roadmap prioritising compliance, privacy, AppSec and resilience.
  • Hold explicit authority to gate Engineering roadmap and release decisions on security and resilience grounds.
  • Drive adoption of UK Cyber Essentials across the business and CIS AWS Foundations for the Platform.
  • Stand up centralised monitoring and alerting across Security Hub and Wiz.
  •  
    Incident Response, Business Continuity & Disaster Recovery
  • Own and continuously improve the security incident response plan and playbooks; act as incident commander when needed.
  • Create and maintain the Business Impact Analysis (BIA) and risk assessments to inform continuity strategies, covering cyber scenarios.
  • Define and maintain DR strategy, architectures and playbooks to meet RTO/RPO targets for in-scope services.
  • Design and own the data recovery strategy and identity recovery strategy.
  • Establish backup, restore and failover testing cadence with evidence of success criteria.
  • Lead security incident crisis management, including cross-functional command structure, executive communications, customer and regulator notifications, liaison with the cyber insurer/broker, and after-action reviews.
  • Plan, facilitate and participate directly in tabletop cyber exercises and live cyber simulations at least quarterly.
  • For any incident classified Severity 1 or 2, act as deputy incident decision-maker, holding delegated authority from the CFO to make time-critical operational decisions.
  •  
    Data Privacy & Regulatory
  • Partner with Legal to own the GDPR programme end-to-end from an information security perspective, including DPIAs, ROPA, DSR handling, consent and lawful basis.
  • Partner with Legal to maintain DPAs, SCCs and appropriate transfer mechanisms for third countries.
  • Implement data classification and protection standards across structured and unstructured data.
  • Embed Privacy by Design and data minimisation into discovery, design and delivery processes.
  • Own the roadmap towards enterprise assurance frameworks, including UK Cyber Essentials and SOC 2 readiness.
  • Prepare for external audits and assessments and ensure customer security questionnaire responses reflect actual control status.
  • Third-Party & Cloud Security
  • Establish and run the vendor risk management programme with pre-procurement security gates, continuous monitoring SLAs and breach flow-down obligations.
  • Maintain a current inventory of third-party access and dependencies, including each vendor's own DR/BC posture.
  • Drive cloud security posture management and foundational controls including IAM, network segmentation, encryption and secrets.
  • Partner with Technology to eliminate shadow technology and tighten ownership/authorisation.

About You

  • 6+ years in information security, with 3+ years of direct exposure to executive and board-level security reporting.
  • Proven track record building security, privacy and resilience programmes from the ground up, including authoring a company’s first Business Continuity Plan for information security.
  • Demonstrated experience running a Business Impact Analysis and translating it into a defensible Minimum Viable Company / recovery-tier model.
  • Expertise in GDPR and PCI-DSS, with hands-on ownership of DPIAs, DSRs and retention programmes.
  • Experience leading security incident response, business continuity, disaster recovery and crisis exercises.
  • Solid grasp of cloud security.
  • Strong understanding of e-commerce security (payments, customer data).
  • Excellent executive communication, able to brief the CFO and the Board directly and to hold the security incident-decision-maker role with credibility under pressure.
  • Strong stakeholder management across Engineering, Product, Legal, Finance and Operations, with the standing to influence Engineering roadmap decisions.
  • Pragmatic and business-focused, balancing security with delivery velocity and availability.
  • Collaborative mindset: a partner, not an auditor or advisor.

Nice to Have's

  • Experience with physical/production continuity planning.
  • AWS experience.
  • Working knowledge of UK Cyber Essentials and CIS AWS Foundations.
  • Experience driving DR maturity and recurring cross-functional simulations.
  • Experience with SOC 2 readiness.

What’s it like to work at MOO? 
MOO’s the kind of workplace where you can really be yourself. Dye your hair purple. Hit the sofa with your laptop. Whatever helps you feel comfortable and happy at work. We want to help you grow in your career and set you up for success – while also recognising the importance of a healthy work/life balance.
 
That’s why we offer 25 days holiday rising by one day for each year here (for 5 years), a matched pension scheme, and paid parental leave. We’ll offer you private healthcare, life insurance, a season ticket loan, and a cycle to work scheme. We also offer flexible work schedules with hybrid and remote working for certain roles as well as a Work From Anywhere program.
 
Diversity Statement
We are working hard to create a representative, inclusive and super-friendly team, because we know that different experiences, perspectives and backgrounds make for a better workplace. And that creates a better experience for our customers. MOO doesn’t discriminate on the basis of race, colour, religion or belief, gender, national origin, age, sexual orientation, marital status, disability or any other protected class.
 
As a design and technology company we have a desire and a responsibility to build a business that represents the world around us. So we strive to create a values-driven, purposeful and highly empowered organisation that we are all proud to work for. And we are committed to continuous investment in building an open and inclusive environment, welcoming a diverse audience of candidates who see themselves working and thriving at MOO. Therefore, we’d like to invite you to complete this optional survey to help us evaluate our inclusion and diversity efforts. Completing this form is entirely voluntary and if you decide not to it won’t in any way affect your job application. We keep the information separate from your application and it is kept secure and confidential, it is only used to better our inclusion and diversity efforts. By submitting this information, you consent to MOO's processing of it for these purposes.

Skills Required

  • 6+ years in information security with 3+ years of executive and board-level security reporting
  • Proven track record building security, privacy and resilience programmes from the ground up
  • Authored or led a company's Business Continuity Plan and run Business Impact Analyses
  • Experience leading security incident response, disaster recovery, business continuity and crisis exercises
  • Expertise in GDPR with hands-on ownership of DPIAs, DSRs and retention programs
  • Expertise in PCI-DSS and e-commerce/payments security
  • Solid grasp of cloud security and ability to drive cloud posture improvements
  • Excellent executive communication and credibility to brief CFO and Board and make time-critical decisions
  • Strong stakeholder management and ability to influence Engineering, Product, Legal, Finance and Operations
  • Experience with physical/production continuity planning
  • AWS experience
  • Working knowledge of UK Cyber Essentials and CIS AWS Foundations
  • Experience driving DR maturity, recurring cross-functional simulations and SOC 2 readiness
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: London
464 Employees
Year Founded: 2006

What We Do

At MOO, we love great design and believe it can work wonders for every business. That’s why we make it simple to create beautiful, expertly crafted business stationery and promotional materials that’ll help you start conversations, open doors and strengthen relationships. MOO launched in 2006 and aims to disrupt the trillion dollar global print industry by combining the values of professional design with accessibility and reach of the web. With rapid annual growth, MOO has become one of the fastest growing print businesses in the world and has over 300 employees across the UK and US London, Boston, Lincoln RI, and Denver CO. We believe in supporting our people to be themselves and be successful – because that’s what makes MOO a great place to work. We’re always looking for bright minds and bushy attitudes, so from software developers to social media specialists, copywriters to customer service heroes, we know we’re only as good as the teams we’ve built. If this sounds like you or someone you know, check out our vacancies and get in touch. Be part of something brilliant.

Similar Jobs

Moneybox Logo Moneybox

Head of Information Security

Fintech • Financial Services
Hybrid
London, Greater London, England, GBR
400 Employees

CDW Logo CDW

Head of Information Security

Information Technology
Hybrid
Manchester, Greater Manchester, England, GBR
15100 Employees

CDW Logo CDW

Head of Information Security

Information Technology
Hybrid
London, Greater London, England, GBR
15100 Employees

CDW Logo CDW

Head of Information Security

Information Technology
Hybrid
Peterborough, Cambridgeshire, England, GBR
15100 Employees

Similar Companies Hiring

ClickMint Thumbnail
AdTech • eCommerce • Marketing Tech • Generative AI
Malibu, CA
9 Employees
PRIMA Thumbnail
Travel • Software • Marketing Tech • Hospitality • eCommerce
US
15 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account