
Head of Information Cyber Security
- Bournemouth
- £65,000-75,000 per year
- Permanent
- Full-time
- Develop and own Nourish's SaaS security roadmap, aligned with growth, architecture evolution, and compliance needs
- Act as the subject matter expert on all things security, internally and externally (customers, partners, prospects, auditors)
- Support Sales and Customer Success in security assurance and due diligence processes (e.g. RFPs, InfoSec questionnaires)
- Own Nourish’s external security posture, including input to Trust Centre, whitepapers, and customer-facing documentation
- Champion secure-by-design principles across the software development lifecycle
- Own DevSecOps processes: shift-left security, secrets management, CI/CD hardening, container security, vulnerability scanning
- Collaborate with Product and Engineering teams on threat modelling, penetration testing, and remediation efforts
- Select, implement, and manage key SaaS security tooling (e.g. SAST/DAST, SIEM, CSPM, endpoint protection, IAM)
- Ensure alignment with cloud-native architecture and tooling (we primarily use AWS, GitHub Actions, and Terraform)
- Lead ongoing readiness and evidence for ISO 27001, SOC 2 Type I & II, and Cyber Essentials Plus
- Maintain and evolve the ISMS in line with business growth and operational maturity
- Maintain the security risk register, treatment plans, and internal audit programme
- Collaborate with Compliance and DPO on data protection alignment (e.g. DPIAs, vendor risk, breach response)
- Own incident response procedures, including tabletop exercises and post-mortems
- Oversee endpoint and cloud security tooling, logging, and alerting (in collaboration with DevOps/IT)
- Manage business continuity and disaster recovery processes from a security perspective
- Deliver internal training and awareness programmes across the business
- Lead monthly security KPIs and reports into SMT and governance forums
- Monitor emerging threats, SaaS-specific security risks, and evolving regulation to inform strategy
- Drive a strong security culture across the business through storytelling, education, and leadership
- Successful recertification of ISO 27001 and Cyber Essentials Plus
- SOC 2 Type I and II: audit readiness, gap closure, and ongoing assurance
- Up-to-date ISMS documentation and live security risk register
- Completion of security training for >95% of staff within policy windows
- Continuous improvement in internal vulnerability management and response SLAs
- Measurable maturity improvements in DevSecOps and SaaS infrastructure controls
- Demonstrated impact on commercial outcomes via faster security assurance for enterprise deals
- Proven experience leading security in a B2B SaaS company, ideally in healthtech, govtech, or another regulated vertical
- Deep understanding of cloud-native architecture (AWS preferred) and SaaS security challenges (multi-tenancy, authN/Z, data segregation)
- Hands-on familiarity with common tools across the security stack (e.g. Terraform, GitHub Actions, Datadog, Snyk, AWS Config, CrowdStrike)
- Experience managing ISO 27001, SOC 2, or equivalent frameworks in production environments
- Strong communicator who can balance risk with pragmatism and align security priorities with business goals
- Experience scaling security capabilities alongside company growth and product maturity
- 25 Days paid leave, Plus Public holidays
- Additional incremental leave for length of service up to 5 days.
- Private Medical Insurance including a personal health plan
- Group Life Assurance
- Employee Referral Bonus Scheme
- Enhanced Maternity leave
- Pension Contribution
- Employee Assistance Programme
- Birthday Day off
- and many more