
Requirements
The role requires 7+ years of experience in IT security, security engineering, or platform ownership. Candidates must possess strong knowledge of cloud security, identity management, and the ability to communicate complex security concepts to both technical and non-technical stakeholders.
Job Description
This role brings IT and security ownership in-house. You'll take responsibility for the platform architecture and security practices that protect Holistic AI's systems, data and the trust of our enterprise customers, working closely with Engineering, leadership and commercial teams as we build and scale our security capabilities.
It's a hands-on role with broad ownership across IT, security, platform architecture and customer security requirements. You'll establish practical security practices, support enterprise customers and make sure security stays embedded in how we build and run our platform.
About Holistic AI
Holistic AI builds AI governance and assurance tooling for enterprise customers. Our platform helps organisations test AI systems responsibly and align their governance with frameworks such as the EU AI Act and NIST. We're a team of about 40 people, hiring carefully: quality over speed. As we grow, we need dedicated in-house ownership of IT and security.
What you'll do
- Own and advance our IT and security posture across company systems and the product platform.
- Contribute to platform architecture decisions with a security-first lens.
- Establish and maintain practical security controls, access management and operational hygiene.
- Support enterprise customer and audit expectations on security, including the processes and evidence they require.
- Partner with Engineering on secure design, vulnerability management and incident readiness.
- Work with Sales and other teams on customer RFPs, security and InfoSec questionnaires, and other customer security requirements.
- Join customer calls to explain our security controls, practices and approach, and address customer security concerns.
- Develop and maintain security policies, procedures and documentation as the company grows.
- Support security risk management across systems, vendors and third-party services.
- Build IT and security capabilities towards sustainable in-house ownership.
What you'll bring
- 7+ years of experience in IT security, security engineering, or platform or security ownership roles.
- Working knowledge of cloud security, identity and access management, and secure architecture fundamentals.
- Experience supporting enterprise customer security requirements, including RFPs and InfoSec questionnaires.
- Confidence speaking directly with customers and explaining security concepts and controls to technical and non-technical audiences.
- Comfort working independently, getting hands-on where needed and building structure where none exists yet.
- The ability to prioritise risk pragmatically in a growing company: protecting what matters without freezing delivery.
- Clear communication with technical and non-technical stakeholders.
- An ownership mindset and strong documentation habits that support a growing team.
Nice to have
- Experience with security frameworks, audits or compliance requirements such as SOC 2, ISO 27001 or GDPR.
Location and working model
- London, United Kingdom.
Compensation
We offer competitive benefits; details are shared during the hiring process.
Interview process
- HR screen
- Hiring manager interview
- Technical assessment
- Task or skills assignment
- Culture fit
- Offer