Senior IT Security & Compliance Lead

Wordsmith · Edinburgh
full-time lead Posted 1 month ago

Before you apply

Build my evidence-backed draft — free Apply on company site →

Paste your relevant resume section or 2–4 true bullets. See supported requirements and honest gaps. No account and no application sent.

Get weekly job alerts like this →

About this role

Senior IT Security & Compliance Lead Edinburgh Wordsmith Wordsmith is building the AI-enabled command centre for in-house legal teams. Our customers are some of the most demanding enterprise legal departments in the world, and they hold us to a high bar on security, privacy, and responsible AI. We're looking for a senior leader to take ownership of security and compliance as we scale. The Role Senior IT Security & Compliance Leads own security and compliance at Wordsmith end-to-end — setting the strategy for IT and infrastructure security, running our certification program across SOC 2, ISO 27001, and ISO 42001, embedding responsible-AI practices into how we build and ship product, and making sure privacy and regulatory obligations (GDPR and beyond) are handled properly as we grow. This is a senior role that blends strategy and hands-on execution. You'll set multi-year direction, represent Wordsmith's security posture to executives, customers, and — as we grow — the board, and build the team, tooling, and controls the company needs at the next stage, not just maintain what exists today. What You'll Do Security Strategy & Leadership - Own Wordsmith's multi-year IT security and compliance roadmap — setting priorities, budget, and tooling decisions in partnership with Engineering and company leadership. IT & Infrastructure Security - Own security architecture across corporate IT and infrastructure — identity & access management, endpoint protection, and cloud/network security — and lead incident response when issues arise. Compliance & Certification - Own SOC 2 Type II, ISO 27001/27017/27018, and ISO 42001 end-to-end — policies, controls, audit evidence, and the audits themselves. AI Governance - Run our AI governance program, including AI Impact Assessments and model/AI-vendor risk reviews, ensuring responsible, compliant AI use across the product. Privacy Operations - Own privacy operations end-to-end — GDPR and other regulatory obligations, DPIAs, RoPA maintenance, sub-processor management, and Data Subject Request fulfilment. Third-Party & Vendor Risk - Assess vendors and AI tools for security, privacy, and AI risk before they're adopted, and put the right contractual safeguards in place at a program level. Team & Function Building - Build the people, process, and tooling the function needs as it scales — starting as the senior owner of the program today, with a mandate to build out a team as Wordsmith grows. Executive & Board Reporting - Own risk and compliance reporting to leadership and, as we scale, the board — translating technical risk into business terms. Customer & Deal Support - Act as the senior voice on security for enterprise deals — security questionnaires, DPAs, and our Trust Center — partnering with Sales, Customer Success, and Legal to unblock deals without cutting corners. Automation & Tooling - Build lean, automation-first tooling (e.g. Vanta) for evidence collection and ongoing compliance monitoring, so the program scales without scaling headcount unnecessarily. What we're looking for Essential - 8-10+ years in security, IT, or compliance roles, including a track record of owning a security or compliance function end-to-end at a fast-growing SaaS or tech company. - Proven experience building or scaling a security/compliance program from an early stage — ideally including time as the sole or founding owner of the function. - Deep, hands-on expertise across SOC 2, the ISO 27000 series, and ideally ISO 42001. - Strong grounding in core IT security fundamentals — identity & access management, endpoint/device security, and cloud or network infrastructure security. - Practical, working knowledge of GDPR and related privacy regulation (ePrivacy, HIPAA, or similar). - Experience presenting security posture, risk, and roadmap to executives, boards, or investors. - Experience building and/or managing a team — or a clear point of view on how you'd grow one as the function scales. - Comfortable owning budget and vendor decisions at a strategic level, not just executing against someone else's plan. - A strong cross-functional operator and executive communicator, bridging Security, IT, Legal/Privacy, Engineering, and GTM. Valued - Prior experience as a Head of Security, Director of Security/IT, or similar senior/leadership title. - Relevant certifications — e.g. CISSP/ISC2, CISM, AIGP, CIPP/E, CIPT, CCSK, or FIP. - Experience in legal tech, AI, or another highly regulated SaaS environment. - Experience designing AI risk or impact-assessment processes from scratch. - Familiarity with tools such as Datagrail, MineOS, Whistic, or SafeBase. Why this role matters You'll take a senior leadership seat over security and compliance, with real ownership over how the function is shaped and grown. You'll sit at the centre of trust for a fast-growing legal AI platform, directly enabling enterprise sales and cus

Similar Jobs

Related searches:

Remote Jobs Lead Jobs Remote Lead Jobs legal

Get jobs like this delivered weekly

Free AI jobs newsletter. No spam.