Padmi
Fresha logo
Fresha

beauty booking platform · salon management software

Head of Security

United Kingdom · OnsitePosted 3 months ago
SecurityStaff+Full Time
Apply at Fresha

Opens the source posting on jobs.lever.co

Source description

About the role

View original

Security strategy and roadmap

Shape the security strategy together with the VP — the VP sets direction at the exec level, you bring the ground truth, the technical depth, and the detailed plan that turns that direction into something real

Own the security roadmap that falls out of it: what we're building, what we're retiring, what we're deferring, and why

Make the call on where to invest day-to-day: tooling, headcount, external services, automation — within the strategic envelope agreed with the VP

Translate that roadmap into something the exec team can actually read and fund

Controls and protections

Deploy and run the security controls across the estate — endpoint, network, cloud, identity, application

Make sure controls are actually working, not just deployed — continuous validation, not annual tick-boxing

Partner with Engineering and IT to get controls in early, rather than bolted on after the fact

Penetration testing and vulnerability management

Run the regular external pentest cadence — application, infrastructure — and make sure findings are triaged and closed

Own the vulnerability management programme: scanning, prioritisation, SLAs, and closure

Work with the Head of Compliance on the evidence side — they need clean data for audits, you need clean closure on the underlying issues. Same data, different purposes

Incident response

Own the IR process end-to-end: detection, triage, containment, eradication, recovery, and post-incident review

Run the on-call model, the playbooks, the tabletop exercises, and the tooling behind them

Be the person in the room when something real happens, and the person writing the honest post-mortem afterwards

Threat intelligence and threat modelling

Stand up a threat intelligence capability — somewhere past incidents, near-misses, industry reports, and internal telemetry get captured, tagged, and made useful

Build this into a threat intel data warehouse that actually informs decisions: future threat modelling, control design, roadmap prioritisation, and tabletop scenarios. Not a dashboard nobody reads

Run threat modelling as a routine practice, not a one-off — including automated threat modelling using AI against designs, code, and infrastructure changes

Emerging threats

Keep a forward view on where the threat landscape is heading, especially around LLMs: prompt injection, model abuse, AI-augmented vulnerability scanning by attackers, and exposure of sensitive data through AI tooling

Don't just react to what's hitting us today — make sure we're not blindsided by what's hitting everyone in 12 months

Feed that view into the strategy conversation with the VP, and turn it into concrete roadmap items rather than slide decks

Security training and awareness

Own the security-specific training content: phishing simulations, secure coding for engineers, threat modelling training, IR tabletop participation, and role-based training for anyone handling cardholder data, PHI, or other sensitive material

Partner with the Head of Compliance — they run the overall training programme, cadence, and evidence; you bring the security substance and keep it current with the threat landscape

Make the training actually useful. Engineers should walk away knowing something they didn't before, not clicking through slides to get a completion tick

Automation and AI

Look at every recurring task in this function and ask "why is a human still doing this?" — triage, alert enrichment, vulnerability prioritisation, evidence gathering, threat modelling, IR runbooks

Push existing tooling as far as it'll go, and fill the gaps with scripts, workflows, or AI where it makes sense

Use LLMs sensibly for drafting, review, analysis, and automation — while being clear-eyed about where they introduce new risks we have to manage ourselves

Treat the function's operating model as a product: fewer manual rituals each quarter, better coverage, faster response

Security advisory

Be the go-to person for security questions across the business — architecture reviews, vendor assessments, new products, acquisitions, anything risky

Give engineers a straight answer and a path forward, not a ticket queue and a policy link

More at Fresha

Related open roles

View all roles