More jobs:
Head of Security
Job in
London, Greater London, W1B, England, UK
Listed on 2026-09-04
Listing for:
Fresha
Full Time
position Listed on 2026-09-04
Job specializations:
-
IT/Tech
Cybersecurity
Job Description & How to Apply Below
Trusted by millions of consumers and businesses worldwide. Fresha is used by 140,000+ businesses and 450,000+ stylists and professionals worldwide, processing over 1 billion appointments to date.
The company is headquartered in London, United Kingdom, with 15 global offices located across North America, EMEA and APAC.Fresha allows consumers to discover, book and pay for beauty and wellness appointments with local businesses via its marketplace, while beauty and wellness businesses and professionals use an all-in-one platform to manage their entire operations with an intuitive business software and financial technology solutions.
Fresha’s ecosystem gives merchants everything they need to run their business seamlessly by facilitating appointment bookings, point-of-sale, customer records management, marketing automation, loyalty, beauty products inventory and team management.
The consumer marketplace unlocks revenue potential for partner businesses by leveraging the power of online bookings and automated marketing through mobile apps and advanced integrations with major tech brands including Instagram, Facebook and Google.
About the role
Reports to:
VP of Security, IT and Compliance We're looking for someone to own security end-to-end 'll shape the security strategy alongside the VP, build and run the controls that protect the business, and be the person everyone — engineers, execs, auditors, customers — looks to regarding security questions.
You'll work alongside the Head of Compliance (who sits under the same VP) as a peer. They own the frameworks, the audits, and the evidence. You own the actual security posture, the tooling, and the response. The two roles need each other to succeed, and we expect you to work closely together rather than carve out territory.
We're a payments business operating in a regulated space, with HIPAA and ISO 27001 behind us and PCI DSS, GDPR, and SOC 2 Type II ahead of us this year. The security bar is not theoretical. To foster a collaborative environment that thrives on face-to-face interactions and teamwork, this role will be based in our dog-friendly office 5 days per week in London:
The Bower, 207-122, Old Street, London EC1V 9NR
.What you'll own:
Security strategy and roadmap
Shape the security strategy together with the VP — the VP sets direction at the exec level, you bring the ground truth, the technical depth, and the detailed plan that turns that direction into something real
Own the security roadmap that falls out of it: what we're building, what we're retiring, what we're deferring, and whyMake the call on where to invest day-to-day: tooling, headcount, external services, automation — within the strategic envelope agreed with the VP Translate that roadmap into something the exec team can actually read and fund Controls and protections
Deploy and run the security controls across the estate — endpoint, network, cloud, identity, application
Make sure controls are actually working, not just deployed — continuous validation, not annual tick-boxing
Partner with Engineering and IT to get controls in early, rather than bolted on after the fact Penetration testing and vulnerability management
Run the regular external pentest cadence — application, infrastructure — and make sure findings are triaged and closed
Own the vulnerability management programme: scanning, prioritisation, SLAs, and closure
Work with the Head of Compliance on the evidence side — they need clean data for audits, you need clean closure on the underlying issues. Same data, different purposes
Incident response
Own the IR process end-to-end: detection, triage, containment, eradication, recovery, and post-incident review
Run the on-call model, the playbooks, the tabletop exercises, and the tooling behind them
Be the person in the room when something real happens, and the person writing the honest post-mortem afterwards
Threat intelligence and…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×