Information Security Team Lead

London, United Kingdom, United Kingdom
4 months ago
Job Type
Permanent
Work Location
Hybrid
Seniority
Lead
Posted
20 Jan 2026 (4 months ago)

The impact you will have:

Lead the day‑to‑day operation and uplift of Elliptic’s information and cyber security programme. Drive SSDLC v2.0 adoption, improve cloud and SaaS security posture, and ensure external audit and customer due diligence readiness. Partner with Engineering, Platform, Legal, Procurement and Customer teams to reduce risk while enabling delivery and revenue, including Enterprise Tier security features.

What we expect from you

Programme ownership and delivery

  • Own delivery of the InfoSec roadmap and metrics. Translate strategy into quarterly plans with measurable outcomes.

  • Establish gates, controls and reporting for SSDLC v2.0 across build and deploy pipelines.

  • Lead CSPM/SSPM baselining and targeted burn‑down of misconfigurations and vulnerabilities.

Risk, assurance and audit readiness

  • Maintain ISMS processes aligned to ISO 27001. Coordinate evidence for customer audits and external assurance (e.g., pen test, TPOs).

  • Chair or contribute to risk forums. Ensure timely remediation, risk acceptance and exception tracking.

Cloud and SaaS security

  • Partner with Platform to harden AWS (IAM, KMS, network segmentation, Security Hub, GuardDuty, logging).

  • Uplift endpoint, identity and access, vulnerability management, and logging across the estate.

People leadership and ways of working

  • Provide day‑to‑day guidance to TISO, Analysts and cross‑functional contributors.

  • Embed a pragmatic, developer‑friendly security culture through enablement, playbooks and training.

Vendor and data governance

  • Oversee vendor security due diligence with clear SLAs and evidence trails. Support data protection and BC/DR control owners.

You must have:

  • Proven experience leading security delivery in a cloud‑native product company.

  • Strong understanding of AWS security architecture, modern CI/CD, and application security practices.

  • Experience operationalising ISMS controls and preparing audit evidence for enterprise customers.

  • Excellent stakeholder management and communication skills.

  • Relevant certifications are a plus (e.g., CISSP, CCSP, AWS Security), but practical impact matters most.

Success measures in the first 12 months:

  • SSDLC v2.0 gates defined and enforced across critical services. Coverage reported monthly.

  • 40% reduction in outstanding high/critical vulnerabilities and misconfigurations.

  • Green audit outcomes for priority customers with evidence pack library established.

  • Baseline CSPM/SSPM metrics in place with trend improvement quarter‑on‑quarter.

  • Vendor DD process with SLAs and scorecards operating and measured.

How We Work

  • Hybrid working and the option to work from almost anywhere for up to 90 days per year

  • £500 Remote working budget to set up your home office space

Learning & Development

  • $1,000 Learning & Development budget to use on anything (agreed with your manager) that contributes to your growth and development

Vacation/Leave

  • Holidays: 25 days of annual leave + bank holidays

  • Anextra day for your birthday

  • Enhanced parental leave: we provide eligible employees, regardless of gender or whether they become a parent by birth or adoption,16 weeks fully-paid leave

Benefits

  • Private Health Insurance - we use Vitality!

  • Full access toSpill Mental Health Support

  • Life Assurance: 4 times your salary to your beneficiaries

  • £100 cryptocurrency for you!

  • Cycle to Work Scheme

Related Jobs

View all jobs

Dev Ops Engineer

BTC Capital Markets Ltd Chaucer, United Kingdom

Senior Solution Consultant

Elliptic London, United Kingdom, United Kingdom
Hybrid

Client Services Agent

Zodia Custody London, United Kingdom
Hybrid

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Where to Advertise Blockchain Jobs in the UK (2026 Guide)

Advertising blockchain jobs in the UK requires a different approach to most technical hiring. The candidate pool is global in outlook but concentrated in specific communities — protocol engineers, smart contract developers, DeFi specialists and Web3 product leaders who move between roles through networks and community channels as much as traditional job boards. General job boards reach a broad audience but lack the specificity that blockchain professionals expect. Specialist platforms, crypto-native communities and targeted outreach each serve a different part of the market. This guide, published by BlockchainJobs.uk, covers where to advertise blockchain roles in the UK in 2026, how the main platforms compare, what employers should expect to pay, and what the data says about hiring across different role types.

Blockchain Jobs UK 2026: What to Expect Over the Next 3 Years

Blockchain is creating jobs in places nobody predicted three years ago. What began as infrastructure for cryptocurrency is now embedded in financial services, supply chain management, digital identity, healthcare records, and the emerging architecture of tokenised assets. The roles being hired for today bear little resemblance to the developer-heavy, crypto-native job adverts that defined the sector's early years. For job seekers, this is both the complexity and the opportunity of building a blockchain career in 2026. The sector has matured beyond its speculative phase and into serious institutional adoption — and that shift has fundamentally changed what employers are looking for, where the jobs are, and which skills command a premium. The candidates who will thrive over the next three years aren't necessarily those who got in earliest or who can recite the Bitcoin whitepaper from memory. They're the ones who understand where enterprise blockchain, decentralised finance, digital assets regulation, and Web3 infrastructure are heading — and who are building their skills accordingly. This article breaks down what the UK blockchain jobs market is likely to look like through to 2028 — covering the titles emerging right now, the technologies driving employer demand, the skills that will matter most, and how to position your career ahead of the next wave rather than behind it.

New Blockchain Employers to Watch in 2026: UK and Global Companies Driving Web3 Careers

The blockchain and Web3 job market in the UK is evolving rapidly. After a period of volatility, the sector has entered a more mature phase—defined by institutional investment, real-world use cases, and infrastructure-led growth. For candidates exploring opportunities on BlockchainJobs.uk, the key shift is clear: the most exciting employers are no longer speculative crypto startups, but well-funded companies building the future of finance, payments, and digital assets. In this article, we explore the new blockchain employers to watch in 2026, focusing on companies that have recently raised funding, secured major contracts, or expanded into the UK market.