Information Security Team Lead

London, United Kingdom, United Kingdom
3 months ago
Job Type
Permanent
Work Location
Hybrid
Seniority
Lead
Posted
20 Jan 2026 (3 months ago)

The impact you will have:

Lead the day‑to‑day operation and uplift of Elliptic’s information and cyber security programme. Drive SSDLC v2.0 adoption, improve cloud and SaaS security posture, and ensure external audit and customer due diligence readiness. Partner with Engineering, Platform, Legal, Procurement and Customer teams to reduce risk while enabling delivery and revenue, including Enterprise Tier security features.

What we expect from you

Programme ownership and delivery

  • Own delivery of the InfoSec roadmap and metrics. Translate strategy into quarterly plans with measurable outcomes.

  • Establish gates, controls and reporting for SSDLC v2.0 across build and deploy pipelines.

  • Lead CSPM/SSPM baselining and targeted burn‑down of misconfigurations and vulnerabilities.

Risk, assurance and audit readiness

  • Maintain ISMS processes aligned to ISO 27001. Coordinate evidence for customer audits and external assurance (e.g., pen test, TPOs).

  • Chair or contribute to risk forums. Ensure timely remediation, risk acceptance and exception tracking.

Cloud and SaaS security

  • Partner with Platform to harden AWS (IAM, KMS, network segmentation, Security Hub, GuardDuty, logging).

  • Uplift endpoint, identity and access, vulnerability management, and logging across the estate.

People leadership and ways of working

  • Provide day‑to‑day guidance to TISO, Analysts and cross‑functional contributors.

  • Embed a pragmatic, developer‑friendly security culture through enablement, playbooks and training.

Vendor and data governance

  • Oversee vendor security due diligence with clear SLAs and evidence trails. Support data protection and BC/DR control owners.

You must have:

  • Proven experience leading security delivery in a cloud‑native product company.

  • Strong understanding of AWS security architecture, modern CI/CD, and application security practices.

  • Experience operationalising ISMS controls and preparing audit evidence for enterprise customers.

  • Excellent stakeholder management and communication skills.

  • Relevant certifications are a plus (e.g., CISSP, CCSP, AWS Security), but practical impact matters most.

Success measures in the first 12 months:

  • SSDLC v2.0 gates defined and enforced across critical services. Coverage reported monthly.

  • 40% reduction in outstanding high/critical vulnerabilities and misconfigurations.

  • Green audit outcomes for priority customers with evidence pack library established.

  • Baseline CSPM/SSPM metrics in place with trend improvement quarter‑on‑quarter.

  • Vendor DD process with SLAs and scorecards operating and measured.

How We Work

  • Hybrid working and the option to work from almost anywhere for up to 90 days per year

  • £500 Remote working budget to set up your home office space

Learning & Development

  • $1,000 Learning & Development budget to use on anything (agreed with your manager) that contributes to your growth and development

Vacation/Leave

  • Holidays: 25 days of annual leave + bank holidays

  • Anextra day for your birthday

  • Enhanced parental leave: we provide eligible employees, regardless of gender or whether they become a parent by birth or adoption,16 weeks fully-paid leave

Benefits

  • Private Health Insurance - we use Vitality!

  • Full access toSpill Mental Health Support

  • Life Assurance: 4 times your salary to your beneficiaries

  • £100 cryptocurrency for you!

  • Cycle to Work Scheme

Related Jobs

View all jobs

Dev Ops Engineer

BTC Capital Markets Ltd Chaucer, United Kingdom

Client Services Agent

Zodia Custody London, United Kingdom
Hybrid

Senior Solution Consultant

Elliptic London, United Kingdom, United Kingdom
Hybrid

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Where to Advertise Blockchain Jobs in the UK (2026 Guide)

Advertising blockchain jobs in the UK requires a different approach to most technical hiring. The candidate pool is global in outlook but concentrated in specific communities — protocol engineers, smart contract developers, DeFi specialists and Web3 product leaders who move between roles through networks and community channels as much as traditional job boards. General job boards reach a broad audience but lack the specificity that blockchain professionals expect. Specialist platforms, crypto-native communities and targeted outreach each serve a different part of the market. This guide, published by BlockchainJobs.uk, covers where to advertise blockchain roles in the UK in 2026, how the main platforms compare, what employers should expect to pay, and what the data says about hiring across different role types.

New Blockchain Employers to Watch in 2026: UK and Global Companies Driving Web3 Careers

The blockchain and Web3 job market in the UK is evolving rapidly. After a period of volatility, the sector has entered a more mature phase—defined by institutional investment, real-world use cases, and infrastructure-led growth. For candidates exploring opportunities on BlockchainJobs.uk, the key shift is clear: the most exciting employers are no longer speculative crypto startups, but well-funded companies building the future of finance, payments, and digital assets. In this article, we explore the new blockchain employers to watch in 2026, focusing on companies that have recently raised funding, secured major contracts, or expanded into the UK market.

How Many Blockchain Tools Do You Need to Know to Get a Blockchain Job?

If you are navigating the blockchain job market, it can feel like you need to master an entire tech stack before you’re even ready to apply. One job advert mentions Solidity, another talks about Hyperledger Fabric, another lists MetaMask, Hardhat, Git, Truffle, and Web3.js — and that’s before you scroll past three LinkedIn posts about “top blockchain skills for 2026.” It’s no wonder job seekers feel overwhelmed. But here’s the honest truth that many hiring managers quietly agree on: 👉 You don’t need to know every blockchain tool to get hired. 👉 You need to know the right ones for the role you’re targeting — and how to use them to solve real problems. Tools matter, but context and capability matter more. This guide breaks down exactly how many blockchain tools you need to learn, which ones matter for specific roles, and how to position what you know so hiring managers take notice.