About this role
Job title: Head of Information Security & Compliance
About the Role Blue Matter is building a dedicated information security and compliance program for its AI-forward consulting environment. You’ll own the program end-to-end, including BlueCortex, and be the trusted point of contact for client data protection in GDPR/UK GDPR contexts across our global footprint.
What You'll Do
- Own and run Blue Matter’s information security program end-to-end, including for BlueCortex.
- Define, maintain, and operationalize security policies, standards, and procedures, and keep them current as the firm scales.
- Maintain the risk register, run regular risk assessments, and drive remediation to closure.
- Report on security and compliance posture to leadership in clear, business-oriented terms.
- Drive certification and attestation efforts (e.g., ISO 27001 and/or SOC 2): design and maintain the control framework, own documentation and evidence, and lead internal and external audits.
- Build a sustainable, “always-audit-ready” approach rather than a once-a-year scramble.
- Lead data protection under GDPR and UK GDPR; act as, or closely support, our Data Protection function.
- Maintain RoPA, conduct DPIAs, and own data-handling, retention, and minimization policies.
- Manage data subject requests and any personal-data incidents, including regulator and individual notifications where required.
- Oversee data transfer mechanisms and data residency considerations across our global footprint and subsidiaries.
- Own the response to client security due-diligence: complete security questionnaires and assessments from biopharma and medtech clients accurately and on time.
- Support commercial and contractual discussions on security, privacy, and data processing terms (e.g., DPAs).
- Maintain a library of reusable security documentation, certifications, and answers to accelerate client reviews.
- Microsoft 365 security operations: secure and govern our Microsoft 365 environment — Entra ID, Defender, Purview, and Intune; manage IAM, DLP, labeling, and device compliance; partner with IT on secure configuration, patching, and endpoint hardening.
- Third-party and vendor risk: run vendor risk management across our supply chain; maintain inventory of vendors and data access; reassess risk regularly.
- Incident response and investigations: own the incident response plan; lead detection, triage, investigation, containment, and post-incident review; run tabletop exercises and produce clear incident reports.
- Security awareness and culture: deliver security training and phishing simulations; make security practical and a firm-wide partnership in protecting client data.
What We're Looking For
- 5+ years of experience in information security and/or GRC, ideally in environments handling sensitive client data (regulated industries, professional services, SaaS, or similar).
- Strong, practical knowledge of GDPR and UK GDPR and day-to-day data protection.
- Hands-on experience with ISO 27001 and/or SOC 2 implementation and audits.
- Working familiarity with the Microsoft security stack (Entra ID, Defender, Purview, Intune).
- Experience responding to client/customer security assessments and questionnaires.