Main description:
Ranked #1 fastest-growing private company in The Sunday Times 100 2022, AYBL has quickly become one of the most iconic women’s activewear brands worldwide. We are a passionate, innovative and ambitious brand on a mission to empower women through the power of fitness. Based in the UK, we are dedicated to providing premium, yet affordable activewear that encompasses our ‘Together we thrive’ ethos.
We’re constantly on the lookout for new people who are equally ambitious, share our core values and consider themselves the best in their field. If this sounds like you and you’ve got what it takes to help push AYBL to the next level, this could be the place for you. The opportunities right now are limitless. We are looking to hire genuine people who demonstrate authenticity and a unique way of thinking.
As we grow, you’ll grow too.
Main purpose of the role:
AYBL Group is a fast-growing global consumer group, home to AYBL and Because of Alice, selling across 10+ Shopify stores in international markets. Our technology is modern and SaaS-based, built around Shopify Plus and Google Workspace, so this isn’t a traditional IT Manager role.
You’ll take ownership of cyber security, internal IT and technology governance across the Group, working closely with our Co-CEO, CFO and Head of Legal. Much of this currently sits informally across our ecommerce and digital teams, so your job is to bring clear ownership to it and build an IT and security function that scales through automation and AI rather than headcount. It’s a hands-on role: you’ll set the standards, implement the technology, lead on incidents and, over time, build a small team.
Roles & Responsibilities
Cyber security
- Own the security of our ecommerce and SaaS environment, including third-party apps, integrations, APIs and user permissions.
- Own identity and access across the Group: SSO, MFA, least privilege and automated joiner / mover / leaver processes.
- Protect against the threats that hit ecommerce, from account takeover and phishing to payment fraud and supplier compromise.
- Build our incident-response capability and lead the response to incidents and suspected data breaches.
- Lead the business to Cyber Essentials Plus and towards ISO 27001 readiness, maintaining PCI DSS and supporting UK GDPR compliance.
- Write and own our security, acceptable use and AI usage policies, and run security-awareness training across the Group.
AI and automation
- Automate IT processes such as onboarding, offboarding, access requests and licence management.
- Build an AI-assisted internal service desk with self-service and automated triage.
- Remove manual processes across the Group using Shopify Flow, n8n and APIs, and set clear AI governance.
IT operations and governance
- Own our core workplace systems, devices, hardware lifecycle, office networks and support for warehouse technology.
- Own backup, recovery and business-continuity planning, and test that it works.
- Manage external IT providers and vendors, review new software before adoption and support the IT budget.
- Maintain a technology and cyber-risk register and report clear KPIs to senior leadership.
Person Specification
Essential
- 5+ years’ hands-on experience in cyber security, IT or platform engineering.
- Experience securing modern ecommerce and SaaS environments, and a clear understanding of third-party app, integration and API risk.
- Strong Google Workspace administration, plus experience with MDM and implementing SSO and MFA.
- Practical knowledge of identity and access, endpoint security, vulnerability management and incident response, including real incidents.
- Evidence of building with AI and automation, with comfort in scripting (Python, TypeScript, shell) and APIs.
- Working knowledge of PCI DSS and UK GDPR.
- Strong communication skills and the confidence to challenge decisions where there is genuine risk.
Desirable
- Experience in ecommerce, DTC or retail, ideally with Shopify Plus.
- Cyber Essentials Plus or ISO 27001 experience.
- Experience managing or mentoring people, or ambition to build a team.
You don’t need to have held a “Head of” title. We care more about your capability, mindset and what you’ve actually built.
Perks
💰 Discretionary yearly bonus
🏖️ 25 days holiday + Bank Holidays + your birthday off
🏠 Flexible working
💻 35 working hours per week with 1 hour lunch break
🛍️ 50% staff discount across AYBL Group
🍸 Social events
💸 Pension scheme
🚗 Free on-site parking
🏋️ Free gym membership
💳 £100 gift card upon joining
💚Employee wellbeing support
Location
Our home is located in Redditch, South Birmingham, with easy access routes to the M5/M42, a 20-minute walk to the train station, as well as many bus routes. Not forgetting Arrow Valley Lake which is a stone’s throw away and a beautiful spot to get those steps in or enjoy your lunch with a view. We're also excited to be moving to a new home in Solihull soon, so it's important you're able to travel there as well as to Redditch.
Skills Required
- 5+ years of hands-on experience in cybersecurity, IT, or platform engineering
- Experience securing modern ecommerce and SaaS environments
- Understanding of third-party application, integration, and API risks
- Strong Google Workspace administration experience
- Experience with MDM and implementing SSO and MFA
- Practical knowledge of identity and access, endpoint security, vulnerability management, and incident response
- Experience handling real security incidents
- Experience building AI and automation solutions
- Comfort scripting with Python, TypeScript, or shell
- Experience working with APIs
- Working knowledge of PCI DSS and UK GDPR
- Strong communication skills and confidence challenging risky decisions
- Ecommerce, direct-to-consumer, or retail experience, ideally with Shopify Plus
- Cyber Essentials Plus or ISO 27001 experience
- Experience managing or mentoring people, or ambition to build a team
What We Do
RK Brands Ltd. was founded in 2018 and operates in the retail sale of products via television, catalog, and mail-order, primarily through the internet.






