Senior IT Security & Compliance Lead
full-time
lead
Posted 1 month ago
Before you apply
Build my evidence-backed draft — free Apply on company site →Paste your relevant resume section or 2–4 true bullets. See supported requirements and honest gaps. No account and no application sent.
About this role
Senior IT Security & Compliance Lead
Edinburgh
Wordsmith
Wordsmith is building the AI-enabled command centre for in-house legal teams.
Our customers are some of the most demanding enterprise legal departments in the world, and they hold us to a high bar on security, privacy, and responsible AI.
We're looking for a senior leader to take ownership of security and compliance as we scale.
The Role
Senior IT Security & Compliance Leads own security and compliance at Wordsmith end-to-end — setting the strategy for IT and infrastructure security, running our certification program across SOC 2, ISO 27001, and ISO 42001, embedding responsible-AI practices into how we build and ship product, and making sure privacy and regulatory obligations (GDPR and beyond) are handled properly as we grow.
This is a senior role that blends strategy and hands-on execution. You'll set multi-year direction, represent Wordsmith's security posture to executives, customers, and — as we grow — the board, and build the team, tooling, and controls the company needs at the next stage, not just maintain what exists today.
What You'll Do
Security Strategy & Leadership
- Own Wordsmith's multi-year IT security and compliance roadmap — setting priorities, budget, and tooling decisions in partnership with Engineering and company leadership.
IT & Infrastructure Security
- Own security architecture across corporate IT and infrastructure — identity & access management, endpoint protection, and cloud/network security — and lead incident response when issues arise.
Compliance & Certification
- Own SOC 2 Type II, ISO 27001/27017/27018, and ISO 42001 end-to-end — policies, controls, audit evidence, and the audits themselves.
AI Governance
- Run our AI governance program, including AI Impact Assessments and model/AI-vendor risk reviews, ensuring responsible, compliant AI use across the product.
Privacy Operations
- Own privacy operations end-to-end — GDPR and other regulatory obligations, DPIAs, RoPA maintenance, sub-processor management, and Data Subject Request fulfilment.
Third-Party & Vendor Risk
- Assess vendors and AI tools for security, privacy, and AI risk before they're adopted, and put the right contractual safeguards in place at a program level.
Team & Function Building
- Build the people, process, and tooling the function needs as it scales — starting as the senior owner of the program today, with a mandate to build out a team as Wordsmith grows.
Executive & Board Reporting
- Own risk and compliance reporting to leadership and, as we scale, the board — translating technical risk into business terms.
Customer & Deal Support
- Act as the senior voice on security for enterprise deals — security questionnaires, DPAs, and our Trust Center — partnering with Sales, Customer Success, and Legal to unblock deals without cutting corners.
Automation & Tooling
- Build lean, automation-first tooling (e.g. Vanta) for evidence collection and ongoing compliance monitoring, so the program scales without scaling headcount unnecessarily.
What we're looking for
Essential
- 8-10+ years in security, IT, or compliance roles, including a track record of owning a security or compliance function end-to-end at a fast-growing SaaS or tech company.
- Proven experience building or scaling a security/compliance program from an early stage — ideally including time as the sole or founding owner of the function.
- Deep, hands-on expertise across SOC 2, the ISO 27000 series, and ideally ISO 42001.
- Strong grounding in core IT security fundamentals — identity & access management, endpoint/device security, and cloud or network infrastructure security.
- Practical, working knowledge of GDPR and related privacy regulation (ePrivacy, HIPAA, or similar).
- Experience presenting security posture, risk, and roadmap to executives, boards, or investors.
- Experience building and/or managing a team — or a clear point of view on how you'd grow one as the function scales.
- Comfortable owning budget and vendor decisions at a strategic level, not just executing against someone else's plan.
- A strong cross-functional operator and executive communicator, bridging Security, IT, Legal/Privacy, Engineering, and GTM.
Valued
- Prior experience as a Head of Security, Director of Security/IT, or similar senior/leadership title.
- Relevant certifications — e.g. CISSP/ISC2, CISM, AIGP, CIPP/E, CIPT, CCSK, or FIP.
- Experience in legal tech, AI, or another highly regulated SaaS environment.
- Experience designing AI risk or impact-assessment processes from scratch.
- Familiarity with tools such as Datagrail, MineOS, Whistic, or SafeBase.
Why this role matters
You'll take a senior leadership seat over security and compliance, with real ownership over how the function is shaped and grown.
You'll sit at the centre of trust for a fast-growing legal AI platform, directly enabling enterprise sales and cus
Similar Jobs
Related searches:
Get jobs like this delivered weekly
Free AI jobs newsletter. No spam.