Fractional Chief Information Security Officer - London - ApprovalMax Limited

    ApprovalMax Limited
    ApprovalMax Limited London

    10 hours ago

    Description

    Fractional Chief Information Security Officer (CISO)

    Contract

    ApprovalMax is redefining how finance teams manage the Money Out cycle — from purchase orders and supplier bills to employee expense management and payroll. Trusted by 18,000+ businesses worldwide , our platform empowers companies to automate financial controls, ensure compliance, and scale efficiently.

    At the end of 2024 , ApprovalMax secured a £10 million growth investment from Yttrium , a leading European technology investor. This funding marks the beginning of a new chapter in our journey — scaling our category leadership in Money Out automation, expanding enterprise capabilities, and accelerating product innovation.

    We are seeking an experienced Fractional CISO to provide hands‐on security leadership as we evolve our security function to support continued growth and European expansion. This is a permanent fractional engagement reporting directly to the CTO.

    You will own our information security strategy, maintain our ISO 27001 certification, build our security roadmap, and prepare the organisation for SOC 2 readiness in 2026‐2027. This role requires someone who can operate both strategically and tactically — developing policy one day and reviewing cloud configurations the next.

    Key Responsibilities

    Develop and own the Information Security strategy aligned with ApprovalMax's business objectives and European expansion plans

    Maintain and continuously improve the Information Security Management System (ISMS)

    Create, review, and maintain core security policies, standards, and procedures

    Establish and chair a cross‐functional Security Working Group (Engineering, Architecture, IT, HR)

    Build and present a multi‐year security roadmap with clear milestones, resource requirements, and priorities

    Serve as the central authority on risk assessment, risk treatment, and risk acceptance decisions

    Assess and provide guidance on secure AI adoption across the organisation, including AI‐powered product features and internal AI tooling

    Compliance & Certification

    Maintain ISO 27001 certification and prepare for the 2027 recertification audit

    Lead SOC 2 Type II readiness programme (target: 2026‐2027), including gap analysis and control mapping

    Ensure compliance with GDPR and data protection requirements across EU/UK/US/AU/NZ/CA/ZA jurisdictions

    Collaborate with external DPO support provider on privacy‐related matters and customer security questionnaires as needed

    Cloud & Technical Security

    Provide security oversight across Azure, AWS, and Google Workspace environments

    Conduct access reviews and advise on identity and access management best practices

    Evaluate and guide implementation of security tooling (SIEM, vulnerability management, endpoint protection)

    Oversee VMware Workspace ONE MDM deployment and device security policies

    Advise engineering teams on secure SDLC practices, DevSecOps integration, and application security principles

    Operational Security

    Develop and maintain incident response plans and procedures

    Lead incident response tabletop exercises and post‐incident reviews

    Provide guidance on business continuity and disaster recovery planning

    Advise on vendor security assessments and third‐party risk management

    Awareness & Culture

    Design and deliver company‐wide security awareness training programmes

    Mentor and upskill internal staff on security best practices

    Foster a security‐first culture across all departments

    Act as a trusted advisor to leadership on emerging threats and security trends

    Stakeholder Engagement

    Report regularly to the CTO on security posture, risks, and programme progress

    Prepare board‐level security presentations as required (infrequent)

    Support commercial teams by contributing to customer security discussions when escalated

    Qualifications

    8+ years of progressive experience in information security, with at least 3 years in a CISO, Head of Security, or senior security leadership role

    Demonstrated experience in B2B SaaS environments, ideally in fintech, finance software, or similarly regulated industries

    Proven track record of achieving and maintaining ISO 27001 certification

    Experience preparing organisations for SOC 2 Type II certification

    Hands‐on experience securing cloud environments (Azure and/or AWS required; GCP a plus)

    Experience with Google Workspace security configuration and administration

    Background working with distributed, remote‐first engineering teams

    Technical Knowledge

    Strong understanding of cloud security architecture, identity management, and zero‐trust principles

    Familiarity with secure software development lifecycle (SDLC) and DevSecOps practices

    Knowledge of MDM solutions (VMware Workspace ONE experience preferred)

    Understanding of API security and integration risk management

    Practical experience with security tooling: SIEM, vulnerability scanners, endpoint protection, etc.

    Awareness of AI/ML security risks, including secure AI adoption practices and emerging AI governance frameworks (desirable)

    Compliance & Regulatory

    Deep knowledge of ISO 27001:2022 requirements and audit processes

    Familiarity with SOC 2 Trust Service Criteria (Security, Availability, Confidentiality, Privacy)

    Understanding of GDPR, UK Data Protection Act, and international data transfer mechanisms

    Awareness of regional requirements across EU, UK, US, Australia, New Zealand, Canada, and South Africa

    Benefits

    Growing international business with 10,000+ subscribers

    Regular performance‐based compensation reviews

    26 days paid time off

    1 additional day off for your Birthday

    Remote office assistance

    Service years recognition financial reward

    #J-18808-Ljbffr


  • Work in company

    Security Officer

    Only for registered members

    The Security Officer is responsible for ensuring a safe, secure, and welcoming environment for staff, students, and campus visitors. · ...

    London Part time

    1 month ago

  • Work in company

    Security Officer

    Only for registered members

    We are a respected UK-based firm specializing in risk assessment, security management, · and proactive threat prevention. Our mission is to empower clients to navigate complex threats by delivering ethical,Knowledge and experience in risk assessment, · security operations, · proa ...

    London

    1 month ago

  • Work in company

    Security Officer

    Only for registered members

    An exciting opportunity for a Security Officer who will ensure the safety of a whole host of people during the status quo and specialist events while always maintaining a professional customer focused mentality. · ...

    London

    3 weeks ago

  • Work in company

    Security Officer

    Only for registered members

    A fantastic opportunity has arisen for a Security Officer who will work in various sites in Hackney Area, demonstrating high quality guarding and customer service to both clients and service users. · ...

    London

    1 month ago

  • Work in company

    Security Officer

    Only for registered members

    The position of Security Officer at a 5 Star Hotel requires exceptional customer service skills, · being able to work in a team and conduct patrols. · ...

    London

    3 weeks ago

  • Work in company

    Security Officer

    Only for registered members

    Harvey Nichols is seeking a Security Officer to join our team in Knightsbridge, a destination for modern luxury and cutting-edge style. Harvey Nichols curates an edit of the world's most sought-after fashion brands, and our Security team plays a vital role in protecting our peopl ...

    London £26,000 - £42,000 (GBP) per year

    1 week ago

  • Work in company

    Security Officer

    Only for registered members

    We are seeking a reliable and proactive Security Officer to help maintain a safe and secure environment for our staff, visitors, · and assets.In this role, you will be responsible for monitoring premises, conducting patrols, · responding to incidents, and ensuring that security p ...

    London

    1 month ago

  • Work in company

    Security Officer

    Only for registered members

    We're looking for a Security Officer to join our Security team.Mandarin Oriental Hotel Group is the award-winning owner and operator of some of the most luxurious hotels, resorts and residences located in prime destinations around the world. · Mandarin Oriental Hyde Park is Londo ...

    London

    1 month ago

  • Work in company

    Security Officer

    Only for registered members

    +Join Our Team as a Security Officer · Are you a vigilant and dedicated professional looking for a rewarding career in security?In this role, you will be responsible for monitoring premises, conducting patrols, responding to incidents, and ensuring that security protocols are uph ...

    London

    1 month ago

  • Work in company

    Security Officer

    Only for registered members

    The London EDITION is looking for its next Security Officer. · You will strive to continually improve guest and employee satisfaction and maximise the financial performance of the hotel by proactive guest relations. · ...

    London Full time

    2 weeks ago

  • Work in company

    Security Officer

    Only for registered members

    We are seeking a highly motivated and SIA licensed Security Officer to join our team. · The ideal candidate will have excellent observational skills, a strong sense of integrity, and the ability to handle challenging situations with professionalism. ...

    London

    2 weeks ago

  • Work in company

    Security Officer

    Only for registered members

    We are on the hunt for top talent. We require professional, flexible and attentive SIA licenced Door Supervisors and Security Officers to safeguard our Luxury Retail clients in Central London. · You will carry out regular checks of sites to identify, report and deal with any situ ...

    London, England

    1 month ago

  • Work in company

    Security Officer

    Only for registered members

    We are seeking a reliable and proactive Security Officer to help maintain a safe and secure environment for our staff, visitors, and assets. · As a Security Officer, · You will be responsible for monitoring premises, conducting patrols. · ...

    London

    4 weeks ago

  • Work in company

    Security Officer

    Only for registered members

    Security Officer · Permanent · Location: London · Hours: Nights only, 19:00 - 07:00, 4 on, 2 off, 56 hours a week · Pay: £14.23 ph · Join Our Team as a Security Officer · Are you a vigilant and dedicated professional looking for a rewarding career in security? We are seeking a re ...

    London £26,000 - £42,000 (GBP) per year

    10 hours ago

  • Work in company

    Security Officer

    Only for registered members

    The London EDITION is looking for its next Security Officer responsible for protecting hotel assets and employees. · Patrolling the property · Assisting with guests · ...

    London

    2 weeks ago

  • Work in company

    Security Officer

    Only for registered members

    +Job summary · A fantastic opportunity has arisen within G4S for a Protective Security Incident Management Officer. · +ResponsibilitiesProvide a high-quality service to support branches/offices and achieve customer satisfaction which is an essential element of the role. · Monitor ...

    London

    1 week ago

  • Work in company

    Security Officer

    Only for registered members

    We are seeking a reliable and proactive Security Officer to help maintain a safe and secure environment for our staff, visitors, and assets. · ...

    London

    1 week ago

  • Work in company

    Security Officer

    Only for registered members

    Welcome our guests. As a Security Officer, you will give them real peace of mind by keeping everyone in our hotel safe and secure. · ...

    London

    1 month ago

  • Work in company

    Security Officer

    Only for registered members

    The Security Officer is responsible for ensuring a safe and secure environment for staff students and campus visitors. · This role includes managing campus security monitoring the activity of students staff and visitors and providing a high standard of customer service. · The Sec ...

    London

    1 month ago

  • Work in company

    Security Officer

    Only for registered members

    You will be responsible for maintaining the security requirements of the client whilst maintaining a good corporate image and high standards of professionalism through adherence to directions from the security management team. · Maintain a polite, courteous, and friendly manner t ...

    London

    3 weeks ago

  • Work in company

    Security Officer

    Only for registered members

    A career with us means joining a values based Company that is growing and is in the top 35 security companies in the UK. · Excellent communication skills, both written and verbal, with a confident and personable manner · ...

    London

    2 weeks ago

Jobs
>
London