Skip to main content
AfterDuty

Head of Information Security

MOO · London, Greater London

Type
Full-time
Posted
9 days ago

Overview

Your incident command and crisis management experience directly maps to leading security incident response and tabletop exercises.

About this role

MOO is a design-led, technology and manufacturing business that operates in the global print and branded merchandise market.

The company is a leader in the market’s premium segment, with premium products and compelling ESG credentials. Customers are typically brand conscious SMEs based in North America, the UK, and Europe. MOO’s relentless focus on the customer has helped create an award-winning and much-loved brand, with exceptional customer satisfaction ratings.

A recipient of British business’ highest award, ‘The Queen’s Award for Enterprise’, MOO has also been profiled in the Financial Times, was ranked in the top 10 UK start-up companies by the Guardian Newspaper, and is part of the ‘Future 50’.

Founded in 2004, MOO employs 400 people today, and is headquartered in the UK, but with the majority of sales and key operations in the USA. The company has raised Venture Capital from Index Ventures, Accomplice, and LocalGlobe.

MOO is seeking an experienced Head of Information Security to review and re-build our security, privacy and resilience capabilities from the ground up and, in the first 12 months, to act as build lead for the digital and security aspects of a company-wide Business Continuity, Disaster Recovery and Incident Response programme.

This is a standalone role, reporting to the Head of Legal It is not a caretaker or compliance-only position. You will operate as a hands-on builder defining strategy, establishing governance, writing playbooks, and directly influencing Engineering's roadmap and delivery practices to embed security, privacy and resilience by design.

The Person We Want

We’re looking for a hands-on builder with a proven track record of building security, privacy and resilience programmes from the ground up.

You’ll be comfortable working with executive and board level, while also getting into the details of security incident response, business continuity, disaster recovery, cloud security and data privacy.

You’ll be pragmatic and business-focused, balancing security with delivery velocity and availability, and have a collaborative mindset as a partner, not an auditor or advisor.

Responsibilities

Strategic Security Leadership & Governance

  • Define and own information security strategy aligned with business objectives
  • Establish security governance framework, including policies, standards, risk management and risk appetite
  • Chair the Security Governance Forum and run a board-level reporting cadence
  • Build a security roadmap prioritising compliance, privacy, AppSec and resilience
  • Hold explicit authority to gate Engineering roadmap and release decisions on security and resilience grounds
  • Drive adoption of UK Cyber Essentials across the business and CIS AWS Foundations for the Platform
  • Stand up centralised monitoring and alerting across Security Hub and Wiz

Incident Response, Business Continuity & Disaster Recovery

  • Own and continuously improve the security incident response plan and playbooks; act as incident commander when needed
  • Create and maintain the Business Impact Analysis (BIA) and risk assessments to inform continuity strategies, covering cyber scenarios
  • Define and maintain DR strategy, architectures and playbooks to meet RTO/RPO targets for in-scope services
  • Design and own the data recovery strategy and identity recovery strategy
  • Establish backup, restore and failover testing cadence with evidence of success criteria
  • Lead security incident crisis management, including cross-functional command structure, executive communications, customer and regulator notifications, liaison with the cyber insurer/broker, and after-action reviews
  • Plan, facilitate and participate directly in tabletop cyber exercises and live cyber simulations at least quarterly
  • For any incident classified Severity 1 or 2, act as deputy incident decision-maker, holding delegated authority from the CFO to make time-critical operational decisions

Data Privacy & Regulatory

  • Partner with Legal to own the GDPR programme end-to-end from an information security perspective, including DPIAs, ROPA, DSR handling, consent and lawful basis
  • Partner with Legal to maintain DPAs, SCCs and appropriate transfer mechanisms for third countries
  • Implement data classification and protection standards across structured and unstructured data
  • Embed Privacy by Design and data minimisation into discovery, design and delivery processes
  • Own the roadmap towards enterprise assurance frameworks, including UK Cyber Essentials and SOC 2 readiness
  • Prepare for external audits and assessments and ensure customer security questionnaire responses reflect actual control status

Third-Party & Cloud Security

  • Establish and run the vendor risk management programme with pre-procurement security gates, continuous monitoring SLAs and breach flow-down obligations
  • Maintain a current inventory of third-party access and dependencies, including each vendor's own DR/BC posture
  • Drive cloud security posture management and foundational controls including IAM, network segmentation, encryption and secrets
  • Partner with Technology to eliminate shadow technology and tighten ownership/authorisation

About You

  • 6+ years in information security, with 3+ years of direct exposure to executive and board-level security reporting
  • Proven track record building security, privacy and resilience programmes from the ground up, including authoring a company’s first Business Continuity Plan for information security
  • Demonstrated experience running a Business Impact Analysis and translating it into a defensible Minimum Viable Company / recovery-tier model
  • Expertise in GDPR and PCI-DSS, with hands-on ownership of DPIAs, DSRs and retention programmes
  • Experience leading security incident response, business continuity, disaster recovery and crisis exercises
  • Solid grasp of cloud security
  • Strong understanding of e-commerce security (payments, customer data)
  • Excellent executive communication, able to brief the CFO and the Board directly and to hold the security incident-decision-maker role with credibility under pressure
  • Strong stakeholder management across Engineering, Product, Legal, Finance and Operations, with the standing to influence Engineering roadmap decisions
  • Pragmatic and business-focused, balancing security with delivery velocity and availability
  • Collaborative mindset: a partner, not an auditor or advisor

Nice to Have's

  • Experience with physical/production continuity planning
  • AWS experience
  • Working knowledge of UK Cyber Essentials and CIS AWS Foundations
  • Experience driving DR maturity and recurring cross-functional simulations
  • Experience with SOC 2 readiness

What’s it like to work at MOO?

MOO’s the kind of workplace where you can really be yourself. Dye your hair purple. Hit the sofa with your laptop. Whatever helps you feel comfortable and happy at work. We want to help you grow in your career and set you up for success – while also recognising the importance of a healthy work/life balance.

That’s why we offer 25 days holiday rising by one day for each year here (for 5 years), a matched pension scheme, and paid parental leave. We’ll offer you private healthcare, life insurance, a season ticket loan, and a cycle to work scheme. We also offer flexible work schedules with hybrid and remote working for certain roles as well as a Work From Anywhere program.

Diversity Statement

We are working hard to create a representative, inclusive and super-friendly team, because we know that different experiences, perspectives and backgrounds make for a better workplace. And that creates a better experience for our customers. MOO doesn’t discriminate on the basis of race, colour, religion or belief, gender, national origin, age, sexual orientation, marital status, disability or any other protected class.

As a design and technology company we have a desire and a responsibility to build a business that represents the world around us.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background — match score 65/100

  • Incident command & response
  • Risk & threat assessment
  • Working to legislation & regulation

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Full-time

    Your experience managing operational risk and leading incident reviews translates directly into shaping security culture and resilience.

    Posted 3 days ago

  • Information Security Analyst

    Europa Worldwide Group · London

    Full-time

    £40,000 – £45,000Estimated

    Your experience managing evidence, compliance, and risk under ISO standards translates directly into this security assurance role.

    Posted 3 days ago

  • Cyber Security & Compliance Analyst

    Shivom Consultancy Ltd · London

    Full-time

    Your incident management, evidence handling, and risk assessment from policing transfer directly to this role.

    Posted 4 days ago

  • £570 a dayEstimated

    Your experience managing security incidents and coordinating multi-agency responses transfers directly to this governance role.

    Posted 4 days ago