MOO

MOO

London

Head of Information Security

Full-Time£50,000 - 90,000 per yearпозавчераUnited Kingdom
IT

Job Description

Salary: £50,000 - 90,000 per year

Requirements:
  • 6+ years in information security, with 3+ years of direct exposure to executive and board-level security reporting.
  • Proven track record of building security, privacy and resilience programmes from the ground up, including authoring a companys first Business Continuity Plan for information security.
  • Demonstrated experience running a Business Impact Analysis and translating it into a defensible Minimum Viable Company / recovery-tier model.
  • Expertise in GDPR and PCI-DSS, with hands-on ownership of DPIAs, DSRs and retention programmes.
  • Experience leading security incident response, business continuity, disaster recovery and crisis exercises.
  • Solid grasp of cloud security.
  • Strong understanding of e-commerce security, including payments and customer data.
  • Excellent executive communication, able to brief the CFO and the Board directly and to hold the security incident-decision-maker role with credibility under pressure.
  • Strong stakeholder management across Engineering, Product, Legal, Finance and Operations, with the standing to influence Engineering roadmap decisions.
  • Pragmatic and business-focused, balancing security with delivery velocity and availability.
  • Collaborative mindset: a partner, not an auditor or advisor.
  • Nice to have: experience with physical/production continuity planning.
  • Nice to have: AWS experience.
  • Nice to have: working knowledge of UK Cyber Essentials and CIS AWS Foundations.
  • Nice to have: experience driving DR maturity and recurring cross-functional simulations.
  • Nice to have: experience with SOC 2 readiness.
Responsibilities:
  • Define and own our information security strategy aligned with business objectives.
  • Establish our security governance framework, including policies, standards, risk management and risk appetite.
  • Chair our Security Governance Forum and run a board-level reporting cadence.
  • Build our security roadmap, prioritising compliance, privacy, AppSec and resilience.
  • Hold explicit authority to gate Engineering roadmap and release decisions on security and resilience grounds.
  • Drive adoption of UK Cyber Essentials across the business and CIS AWS Foundations for the Platform.
  • Stand up centralised monitoring and alerting across Security Hub and Wiz.
  • Own and continuously improve our security incident response plan and playbooks, and act as incident commander when needed.
  • Create and maintain the Business Impact Analysis and risk assessments to inform continuity strategies, covering cyber scenarios.
  • Define and maintain our DR strategy, architectures and playbooks to meet RTO/RPO targets for in-scope services.
  • Design and own our data recovery strategy and identity recovery strategy.
  • Establish backup, restore and failover testing cadence with evidence of success criteria.
  • Lead security incident crisis management, including cross-functional command structure, executive communications, customer and regulator notifications, liaison with the cyber insurer/broker, and after-action reviews.
  • Plan, facilitate and participate directly in tabletop cyber exercises and live cyber simulations at least quarterly.
  • For any incident classified Severity 1 or 2, act as deputy incident decision-maker, holding delegated authority from the CFO to make time-critical operational decisions.
  • Partner with Legal to own the GDPR programme end-to-end from an information security perspective, including DPIAs, ROPA, DSR handling, consent and lawful basis.
  • Partner with Legal to maintain DPAs, SCCs and appropriate transfer mechanisms for third countries.
  • Implement data classification and protection standards across structured and unstructured data.
  • Embed Privacy by Design and data minimisation into discovery, design and delivery processes.
  • Own the roadmap towards enterprise assurance frameworks, including UK Cyber Essentials and SOC 2 readiness.
  • Prepare for external audits and assessments and ensure customer security questionnaire responses reflect actual control status.
  • Establish and run the vendor risk management programme with pre-procurement security gates, continuous monitoring SLAs and breach flow-down obligations.
  • Maintain a current inventory of third-party access and dependencies, including each vendors own DR/BC posture.
  • Drive cloud security posture management and foundational controls including IAM, network segmentation, encryption and secrets.
  • Partner with Technology to eliminate shadow technology and tighten ownership and authorisation.
Technologies:
  • AWS
  • Cloud
  • Flow
  • IAM
  • Network
  • Security
  • AI
  • Support

More:

We are MOO, a design-led, technology and manufacturing business operating in the global print and branded merchandise market. We are a leader in the premium segment, serving brand-conscious SMEs in North America, the UK and Europe. Founded in 2004, we are headquartered in the UK with the majority of sales and key operations in the USA, and we employ around 400 people. We are an award-winning brand with strong customer satisfaction, and our benefits include 25 days holiday rising by one day each year for five years, a matched pension scheme, paid parental leave, private healthcare, life insurance, a season ticket loan, a cycle to work scheme, flexible work schedules, hybrid and remote working for certain roles, and a Work From Anywhere program. We also value an inclusive, friendly workplace where people can be themselves and grow their careers.

last updated 34 week of 2026

Interested in this role?

Submit your application now

How to Apply

Ready to apply for this position? Here's what you need:

  • An updated resume highlighting relevant experience
  • A compelling cover letter (if required)
  • Portfolio or work samples (for relevant positions)

About MOO

MOO

MOO

London

IT

Skills & Technologies

GoAWSRESTAIUI

Inferred from job description

Salary Insight

£70,000

This role

£55,000

UK median

This salary is 27% above the UK median for UK tech roles55,000/yr).

Based on 2024–2025 UK technology sector benchmarks

Explore More UK Opportunities

Thousands of tech jobs across the United Kingdom