Head of Information Security – Compliance and Governance

Location
Reading
Workplace
Hybrid

About this role

Reporting to the CISO, the Head of Information Security – Compliance and Governance will lead Proactis’ information security governance, compliance and assurance capability. The role will be responsible for maintaining and continuously improving the Information Security Management System (ISMS), driving audit readiness, strengthening control effectiveness and ensuring that Proactis can evidence robust security, privacy and operational assurance to customers, auditors and internal stakeholders.
This is a hands-on leadership role suited to an experienced security governance professional who can operate strategically while also being comfortable owning detail, evidence, documentation and delivery. The successful candidate will work closely with Product, Engineering, Cloud Infrastructure, Operations, Legal, HR, Finance, Sales and Customer Success to embed effective security governance into the way Proactis designs, delivers and supports its SaaS services.
  • Lead, maintain and continuously improve Proactis’ ISMS, ensuring it remains effective, auditable and aligned with ISO 27001 requirements and business priorities.
  • Own and coordinate external certification and assurance activities, including ISO 27001 audits and other customer or regulatory assurance requirements relevant to a SaaS provider.
  • Drive audit readiness and evidence management across security, technology and business control areas, including ISAE 3402 Type II / SOC 1, SOC 2, ISO 27001 and related assurance frameworks where applicable.
  • Maintain the security governance framework, including policies, standards, procedures, control documentation, risk registers, exceptions, evidence repositories and reporting packs.
  • Lead internal security control reviews and internal audit activities, ensuring findings are clearly documented, risk-rated, tracked and remediated in a timely manner.
  • Partner with Product, Engineering and Infrastructure teams to ensure security and compliance requirements are embedded into SaaS platform design, software development, change management and operational processes.
  • Support customer assurance activities, including security questionnaires, due diligence requests, contractual security reviews, customer audits and evidence-based responses to enterprise customers.
  • Support privacy and data protection governance, including GDPR-aligned processes, records of processing, DPIAs, supplier assessments and privacy-by-design activities in collaboration with Legal and other stakeholders.
  • Ensure effective governance of third-party and supplier security risk, particularly for cloud, hosting, managed service and technology suppliers supporting Proactis’ SaaS services.
  • Support security incident governance by ensuring escalation, notification, evidence capture, lessons learned and stakeholder communications processes are defined, tested and understood.
  • Define and report meaningful security and compliance metrics, KPIs and KRIs to the CISO and senior stakeholders, using data to drive prioritisation and continuous improvement.
  • Oversee security awareness, policy attestation and compliance training activities, ensuring colleagues understand their responsibilities in protecting customer and company information.
  • Champion continuous improvement of governance, risk and compliance processes, including opportunities to improve automation, documentation quality, knowledge management and audit efficiency.
  • Extensive experience implementing, maintaining or materially improving an ISMS in a technology, SaaS, software, cloud services or similarly complex environment.
  • Strong practical knowledge of ISO 27001, including experience managing external audits, certification cycles, surveillance audits, internal audit programmes and control remediation.
  • Experience supporting or managing independent assurance frameworks such as ISAE 3402 Type II / SOC 1, SOC 2, ISO 27017, ISO 27018, Cyber Essentials / Cyber Essentials Plus or equivalent customer assurance programmes.
  • Strong understanding of SaaS security governance, including cloud service operations, secure software development lifecycle, access control, vulnerability management, change management, incident response and customer data protection.
  • Experience designing, maintaining and governing security policies, standards, control libraries, risk registers, evidence repositories and compliance documentation.
  • Demonstrable experience working with external auditors, certification bodies, customer auditors and internal stakeholders to provide clear, accurate and timely evidence of control operation.
  • Experience responding to customer security questionnaires, due diligence requests and customer audit enquiries in an organised, consistent and commercially aware manner.
  • Good understanding of GDPR and privacy governance, including practical experience with privacy management processes and controls for personal data in business and SaaS environments.
  • Ability to assess risk findings in the context of the wider organisation, customer commitments and the threat landscape, and to explain risk clearly to technical and non-technical audiences.
  • Excellent documentation, report writing and presentation skills, with strong attention to detail and the ability to produce audit-ready materials.
  • Strong stakeholder management skills, with the ability to influence teams across Product, Engineering, Cloud Infrastructure, Legal, HR, Finance, Sales, Customer Success and senior management.
  • Highly organised, pragmatic and delivery-focused, with the ability to manage competing priorities and maintain progress across multiple governance, assurance and improvement activities.
  • Relevant professional certifications such as ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, CISM, CISSP, CRISC, CISA, CCSP, Security+ or equivalent experience.
  • Experience with Microsoft security and identity technologies such as Microsoft Defender, Microsoft Sentinel, Intune, Entra ID and Purview.
  • Experience with cloud platforms and SaaS operating models, including Azure, AWS or hybrid cloud environments.
  • Knowledge of NIST, CIS Controls, OWASP Top 10, secure software development and vulnerability management practices.
  • Experience implementing or maintaining a Privacy Information Management System (PIMS), such as ISO 27701-aligned privacy governance.
  • Experience of PCI DSS, ISO 22301, ISO 20000 or ISO 9001 where relevant to service delivery or customer assurance.
  • Experience building or improving compliance knowledge bases, document management systems or evidence repositories, including SharePoint-based governance libraries.
  • Experience using GRC tooling, workflow automation or AI-enabled knowledge management to improve audit readiness and compliance efficiency.

Tired of cold applications?

Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.

Know someone who'd be great for this?