Talent Apply
Log in
All jobs
BM

Head of Information Security & Compliance

Blue Matter Consulting
United Kingdom
On-site

About this role

Job title: Head of Information Security & Compliance

About the Role Blue Matter is building a dedicated information security and compliance program for its AI-forward consulting environment. You’ll own the program end-to-end, including BlueCortex, and be the trusted point of contact for client data protection in GDPR/UK GDPR contexts across our global footprint.

What You'll Do

  • Own and run Blue Matter’s information security program end-to-end, including for BlueCortex.
  • Define, maintain, and operationalize security policies, standards, and procedures, and keep them current as the firm scales.
  • Maintain the risk register, run regular risk assessments, and drive remediation to closure.
  • Report on security and compliance posture to leadership in clear, business-oriented terms.
  • Drive certification and attestation efforts (e.g., ISO 27001 and/or SOC 2): design and maintain the control framework, own documentation and evidence, and lead internal and external audits.
  • Build a sustainable, “always-audit-ready” approach rather than a once-a-year scramble.
  • Lead data protection under GDPR and UK GDPR; act as, or closely support, our Data Protection function.
  • Maintain RoPA, conduct DPIAs, and own data-handling, retention, and minimization policies.
  • Manage data subject requests and any personal-data incidents, including regulator and individual notifications where required.
  • Oversee data transfer mechanisms and data residency considerations across our global footprint and subsidiaries.
  • Own the response to client security due-diligence: complete security questionnaires and assessments from biopharma and medtech clients accurately and on time.
  • Support commercial and contractual discussions on security, privacy, and data processing terms (e.g., DPAs).
  • Maintain a library of reusable security documentation, certifications, and answers to accelerate client reviews.
  • Microsoft 365 security operations: secure and govern our Microsoft 365 environment — Entra ID, Defender, Purview, and Intune; manage IAM, DLP, labeling, and device compliance; partner with IT on secure configuration, patching, and endpoint hardening.
  • Third-party and vendor risk: run vendor risk management across our supply chain; maintain inventory of vendors and data access; reassess risk regularly.
  • Incident response and investigations: own the incident response plan; lead detection, triage, investigation, containment, and post-incident review; run tabletop exercises and produce clear incident reports.
  • Security awareness and culture: deliver security training and phishing simulations; make security practical and a firm-wide partnership in protecting client data.

What We're Looking For

  • 5+ years of experience in information security and/or GRC, ideally in environments handling sensitive client data (regulated industries, professional services, SaaS, or similar).
  • Strong, practical knowledge of GDPR and UK GDPR and day-to-day data protection.
  • Hands-on experience with ISO 27001 and/or SOC 2 implementation and audits.
  • Working familiarity with the Microsoft security stack (Entra ID, Defender, Purview, Intune).
  • Experience responding to client/customer security assessments and questionnaires.

Your next opportunity starts here

Prepare, apply, track, interview and get hired — all from one platform, with AI in your corner.

Download app

Or sponsor Premium for someone who's job hunting →