Skip to main content
Wordsmith

Senior IT Security & Compliance Lead

RemoteUnited Kingdom only
Published
Role
Security
Experience
Senior
Employment
Full-time
Salary not disclosed
Check eligibility

Open to GB only. Set where you work from to check your eligibility.

No BS summary

Wordsmith is seeking a Senior IT Security & Compliance Lead to own security and compliance end-to-end, including strategy, certification programs (SOC 2, ISO 27001, ISO 42001), responsible-AI practices, and privacy/regulatory obligations. This senior role involves both strategy and hands-on execution, with a mandate to build out a team as the company grows.

Optional skills

CISSPISC2CISMAIGPCIPP/ECIPTCCSKFIP

What you'll do

  • Own Wordsmith's multi-year IT security and compliance roadmap — setting priorities, budget, and tooling decisions in partnership with Engineering and company leadership.
  • Own security architecture across corporate IT and infrastructure — identity & access management, endpoint protection, and cloud/network security — and lead incident response when issues arise.
  • Own SOC 2 Type II, ISO 27001/27017/27018, and ISO 42001 end-to-end — policies, controls, audit evidence, and the audits themselves.
  • Run our AI governance program, including AI Impact Assessments and model/AI-vendor risk reviews, ensuring responsible, compliant AI use across the product.
  • Own privacy operations end-to-end — GDPR and other regulatory obligations, DPIAs, RoPA maintenance, sub-processor management, and Data Subject Request fulfilment.

What they require

  • 8-10+ years in security, IT, or compliance roles, including a track record of owning a security or compliance function end-to-end at a fast-growing SaaS or tech company.
  • Proven experience building or scaling a security/compliance program from an early stage — ideally including time as the sole or founding owner of the function.
  • Deep, hands-on expertise across SOC 2, the ISO 27000 series, and ideally ISO 42001.
  • Strong grounding in core IT security fundamentals — identity & access management, endpoint/device security, and cloud or network infrastructure security.
  • Practical, working knowledge of GDPR and related privacy regulation (ePrivacy, HIPAA, or similar).

Wordsmith is building the AI-enabled command centre for in-house legal teams. Our customers are some of the most demanding enterprise legal departments in the world, and they hold us to a high bar on how we secure our systems, devices, and infrastructure. We're looking for someone to build the IT security function that keeps that trust intact as we scale.

LegalTechStartup
Salary not disclosed