Head of Security

Company: Fresha
Apply for the Head of Security
Location: London
Job Description:

Overview

In this role you will own Fresha’s security posture end-to-end, shaping the strategy with the VP of Security, IT and Compliance and turning it into a concrete, funded plan. You will deploy and validate controls across endpoints, networks, cloud, identity, and applications, and drive incident response, threat intelligence, and vulnerability management. You’ll collaborate closely with Engineering, IT and Compliance to prepare for audits and regulatory requirements in a payments-focused, highly regulated environment. This is a hands-on leadership role at a fast-growing company where security enables scalable product and customer trust.

Responsibilities

  • Define and execute the security strategy and roadmap with the VP
  • Build and operate security controls across estate (endpoint, network, cloud, identity, app)
  • Lead penetration testing cadence and vulnerability management program
  • Own end-to-end incident response, IR playbooks, and post-mortems
  • Establish threat intelligence and threat modelling program including a data warehouse
  • Monitor emerging threats (including AI/LLM risks) and translate into roadmap items
  • Collaborate with Compliance for audits and evidence, ensuring clean data and closure
  • Drive automation and AI-driven improvements, reducing manual security work
  • Provide security advisory to engineers, vendors, acquisitions and new products
  • Lead security training content and collaborate with Compliance on training programs

Key requirements

  • Led security in a regulated environment with payments, healthcare, or financial services
  • Driven real incident response including post-mortems
  • Broad understanding of cloud, SaaS, identity, supply chain, and applications security
  • Built or meaningfully improved threat intel or threat modelling capability
  • Fluent with AI tools and capable of building automation; pragmatic about AI risks
  • Comfortable co-owning strategy with a VP and communicating with engineers and executives
  • Collaborative and cross-functional collaboration
  • Strong communication with both engineers and leadership
  • Hands-on and pragmatic; able to work in incidents and design reviews
  • Security strategy and roadmap development
  • End-to-end security controls (endpoint, network, cloud, identity, app)
  • Threat modelling and threat intel

Posted: September 14th, 2026