Skip to main content
AfterDuty

Director of Security & Compliance

Oscar · London, Greater London

Type
Full-time
Posted
14 days ago

Overview

Director of Security & Compliance | London | £110-140k + Benefits A high-profile organisation with a complex international operating environment is looking for a Director of Security & Compliance to take ownership of its security, governance, risk and compliance function as it enters its next phase…

About this role

Director of Security & Compliance | London | £110-140k + Benefits

A high-profile organisation with a complex international operating environment is looking for a Director of Security & Compliance to take ownership of its security, governance, risk and compliance function as it enters its next phase of maturity.

This is a newly created senior leadership position, reporting directly to the CTO. With Cyber Essentials Plus already achieved and a 24/7 outsourced SOC in place, the organisation is now focused on achieving ISO 27001 certification, strengthening its governance and compliance framework, and ensuring the secure adoption of a rapidly expanding enterprise AI estate.

You'll become the senior accountable owner for security certifications, organisational risk, business continuity, AI security and governance, and information security - acting as the authoritative voice on cyber and security matters across the organisation.

*Location:*London, hybrid (2-3 days onsite)

*Package:*£110,000-140,000 + excellent benefits

Key Responsibilities

  • Own security monitoring, incident response and security tooling, working closely with the outsourced SOC
  • Line manage the IT Security Engineer and lead the organisation-wide security awareness programme
  • Define identity, access and authentication standards, including RBAC, MFA and SSO
  • Own the IT governance framework and regulatory/standards compliance posture
  • Lead the programme to achieve ISO 27001 certification, including defining and managing scope
  • Own the central digital and data security risk register in partnership with Legal & Risk
  • Develop and maintain data classification, retention and GDPR operating frameworks
  • Own disaster recovery and business continuity planning, including RTO/RPO requirements for critical systems
  • Lead security governance across the enterprise AI estate, including access controls, data protection, prompt injection, jailbreaking and third-party AI risk
  • Own and develop the organisation's Responsible Use Policy for AI
  • Lead the DevSecOps security function, including secrets management, vulnerability scanning, pipeline security and workload protection
  • Own third-party security assessments and ongoing supplier/vendor security monitoring
  • Develop and mature the organisation's wider security strategy, policies and control environment

What You'll Bring

  • Significant senior leadership experience across security, cyber, governance, risk and compliance
  • Experience operating within a mid-to-large, complex or internationally distributed organisation
  • Deep, demonstrable ISO 27001 expertise, ideally having led or owned a successful certification programme
  • Strong working knowledge of SOC 2, NIST CSF and other recognised security frameworks
  • Strong technical understanding across SIEM, EDR, IAM, vulnerability management and DevSecOps
  • Proven GDPR and data protection experience, ideally within a multi-jurisdiction environment
  • Strong understanding of AI security and governance, including prompt injection, model risk and third-party AI vendor risk
  • Experience establishing and managing enterprise-level security and risk registers
  • Excellent executive stakeholder management and communication skills
  • A pragmatic approach to security, with the ability to balance risk management with business delivery
  • Experience managing security professionals and outsourced security partners
  • The credibility to operate as the organisation's senior security authority while remaining commercially and strategically focused

Certifications

One or more of the following certifications is required

CISSP | CISM | ISO 27001 Lead Implementer | CIPP/E | CIPM | CRISC | CGEIT | CCSP | AIGP

Please note: candidates must have the legal right to work in the UK.

Apply now for immediate consideration.

About compliance & regulatory roles for ex-police

Compliance, AML and regulatory roles. Working to PACE, RIPA and CPIA is a stronger regulatory grounding than most civilian applicants can offer — firms increasingly recognise this.

See all compliance & regulatory jobs in London

Why this fits a police background — match score 90/100

  • Incident command & response
  • Working to legislation & regulation
  • Security operations

What compliance & regulatory roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Compliance analyst£32,000–£42,000
Compliance / AML officer£40,000–£55,000
Compliance manager£55,000–£80,000
Senior manager / head of compliance£80,000–£120,000+
Full compliance & regulatory salary guide →

More compliance & regulatory jobs for ex-police

  • Full-time

    Who We Are Since 1843, The Economist Group has championed independence, excellence and openness, helping people understand and tackle the critical challenges shaping the world.

    Posted 4 days ago

  • Full-time

    Your risk assessment and policy compliance skills from policing are directly applicable to managing accreditation frameworks.

    Posted 4 days ago

  • Your experience with regulatory frameworks, policy adherence and FCA-style standards from policing transfers directly.

    Posted 4 days ago

  • EMEA Risk and Compliance Manager

    Flight Centre Travel Group · London

    Full-time

    Your experience managing risk, compliance, and multi-agency coordination in policing transfers directly to this role.

    Posted 4 days ago