Head of Information Security
Job in
London, Greater London, W1B, England, UK
Listed on 2026-09-03
Listing for:
MOO
Full Time
position Listed on 2026-09-03
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
We started in 2004. Since then we’ve built an award-winning and much-loved brand, with customer satisfaction and Trustpilot ratings that make most businesses want to give up and hire an army of review bots. We’ve got half a million customers, mostly small and medium businesses in North America, the UK, and Europe – businesses that, like us, get all excited about putting something real and beautiful into people’s hands.
Does that make us nerds? Probably, and we’re ok with that. We’ve been given the highest business award in Britain, ‘The Queen’s Award for Enterprise’. Backed by venture capital, we’re part of Tech Nation’s ‘Future Fifty’, recently passing $1bn in lifetime revenue, and featuring in the Guardian’s top 10 UK start-ups list. Ok, we’ll stop bragging now.
Today, we’re more than 400 people with our global HQ in London, UK, while we also have premises in Dagenham. In the US, you’ll find us in Boston, MA, as well as East Providence, RI and Denver, CO and with our most recent office expansion in Cape Town South Africa.
MOO is seeking an experienced Head of Information Security to review and re-build our security, privacy and resilience capabilities from the ground up and, in the first 12 months, to act as build lead for the digital and security aspects of a company-wide Business Continuity, Disaster Recovery and Incident Response programme.
This is a standalone role, reporting to the Head of Legal It is not a caretaker or compliance-only position. You will operate as a hands-on builder defining strategy, establishing governance, writing playbooks, and directly influencing Engineering's roadmap and delivery practices to embed security, privacy and resilience by design.
The Person We Want We’re looking for a hands-on builder with a proven track record of building security, privacy and resilience programmes from the ground up.
You’ll be comfortable working with executive and board level, while also getting into the details of security incident response, business continuity, disaster recovery, cloud security and data privacy.
You’ll be pragmatic and business-focused, balancing security with delivery velocity and availability, and have a collaborative mindset as a partner, not an auditor or advisor.
Responsibilities Strategic Security Leadership & Governance Define and own information security strategy aligned with business objectives.
Establish security governance framework, including policies, standards, risk management and risk appetite.
Chair the Security Governance Forum and run a board-level reporting cadence.
Build a security roadmap prioritising compliance, privacy, App Sec and resilience.
Hold explicit authority to gate Engineering roadmap and release decisions on security and resilience grounds.
Drive adoption of UK Cyber Essentials across the business and CIS AWS Foundations for the Platform.
Stand up centralised monitoring and alerting across Security Hub and Wiz.
Incident Response, Business Continuity & Disaster Recovery Own and continuously improve the security incident response plan and playbooks; act as incident commander when needed.
Create and maintain the Business Impact Analysis (BIA) and risk assessments to inform continuity strategies, covering cyber scenarios.
Define and maintain DR strategy, architectures and playbooks to meet RTO/RPO targets for in-scope services.
Design and own the data recovery strategy and identity recovery strategy.
Establish backup, restore and failover testing cadence with evidence of success criteria.
Lead security incident crisis management, including cross-functional command structure, executive communications, customer and regulator notifications, liaison with the cyber insurer/broker, and after-action reviews.
Plan, facilitate and participate directly in tabletop cyber exercises and live cyber simulations at least quarterly.
For any incident classified Severity 1 or 2,…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×