Head of International Security
On-siteLondon, England, United Kingdom
Job Summary
Execute the Global Security Strategy across non-US markets by translating regional regulatory requirements into concrete engineering controls and surfacing local needs into global architecture decisions. Own the execution of identity, secrets management, and infrastructure protection for cross-border data flows while establishing high-fidelity detection and response capabilities aligned with local time zones. Secure products and AI systems for international customers through multi-tenant isolation, prompt injection defenses, and secure SDLC practices. Lead insider risk mitigation and serve as the primary security partner for enterprise and public sector engagements in the UK, EU, and MENA regions. Partner with Sales, Legal, and Compliance to streamline security reviews and build durable customer confidence while driving the international clearable-infrastructure plan.
Required Qualifications
- 8+ years in cybersecurity (security engineering, product security, detection/response, or cloud security)
- at least 4 years leading or formally mentoring engineers in high-growth or enterprise environments
- Demonstrated experience building and scaling security programs that materially improved risk posture
- Strong technical depth in cloud-native security (AWS / GCP / Azure), IAM / Zero Trust, infrastructure security, logging and monitoring, and secure SDLC practices
- Hands-on familiarity with GDPR, ISO 27001, SOC 2, UK Cyber Essentials Plus, NIS2, and the EU AI Act
- Experience managing insider risk or securing environments with significant third-party, contractor, or marketplace-style user populations
- Ability to operate cross-functionally with Engineering, Product, Legal, Compliance, Sales, and Public Sector stakeholders
- Right to work in the UK
- Comfortable traveling regularly
- willing to be vetted for country-specific clearances where customer engagements require it
Desired Qualifications
- Experience securing AI / ML platforms, LLM-based systems, or agentic applications
- Familiarity with AI-specific threat vectors such as training data poisoning, prompt injection, tool/plugin abuse, and protection of model-related IP
- Experience operating at the intersection of enterprise SaaS and government or national security customers
- Working knowledge of GCC (Gulf Cooperation Council) sovereign compliance and privacy regulations (such as UAE DESC CSP and Qatar NCSA NISCF/NIA)
- Proven ability to build secure-by-design multi-tenant systems serving FTSE 100 / Euro Stoxx 50 / global Fortune 500 clients across multiple regulatory regimes
- Experience leading red-teaming, adversarial testing, or offense-informed defense programs
- Active or eligible for UK clearance (SC or DV), NATO clearance, or equivalent in another allied jurisdiction
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.