Head of Security
Geordieai
| Company | Geordieai |
| Category | Security |
| Location | London |
| Remote | Hybrid |
| Employment | Not stated |
| Level | Director |
| Salary | Not stated by the employer |
| Posted | 29 Jul 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (ashby) |
Description
THE ROLE
We are seeking a Head of Security to build and own the security program that enables Geordie to move incredibly quickly without compromising trust through its next stage of growth.
You’ll be joining a rapidly growing team and product that is already serving some of the world’s largest enterprises. You'll combine modern security engineering, thoughtful governance and AI-first operations to ensure our customers, employees and partners can confidently rely on Geordie as we scale.
With SOC 2 Type II and ISO 27001 already in place, your mission is to build an effective AI-native security programme that keeps certifications healthy as a byproduct of how we already operate.
Initially, you'll be a hands-on individual contributor owning security end-to-end. This includes both product security for the platform our customers trust to govern their agents, and the internal security program that keeps Geordie itself defensible. You'll own security strategy, engineering, governance and compliance while partnering closely with Engineering, our Internal Systems & AI Lead, and the wider leadership team.
You'll also be Customer Zero for Geordie. Working closely with our Product and Engineering teams, you'll own the implementation of our platform, ensuring Geordie is the best example of secure AI adoption, thereby shaping the future of the product and industry best practice.
WHAT YOU'LL DO
PRODUCT SECURITY
- Own product security for the Geordie platform, with secure by design, threat modelling and security architecture review embedded throughout the SDLC, enabling rapid development safely.
- Drive vulnerability management, penetration testing, and remediation across the product.
- Act as the stakeholder for product security requirements for authn/authz, tenant isolation, and privileged access
- Immerse yourself in the agent security domain our customers are focused on: prompt injection, agent supply chain, mcp permissions, and non-human identities
SECURITY ENGINEERING & OPERATIONS
- Own security across Geordie's cloud infrastructure and internal environments.
- Own the company's security roadmap, risk management approach and overall security governance.
- Own security policy and technical requirements across identity, endpoints, cloud infrastructure and SaaS applications.
- Partner closely with our Internal Systems & AI Lead, who owns identity platforms, endpoint management, device provisioning and SaaS administration, ensuring security controls are designed, implemented and continuously improved.
- Lead incident preparedness and response, ensuring Geordie can respond rapidly and effectively when required.
- Continuously improve monitoring and detection capabilities across the business.
AI NATIVE RISK, GOVERNANCE & TRUST
- Build one of the industry's best AI-native security programs through thoughtful use of AI and automation, growing security leverage through AI rather than manual process.
- Develop AI-powered workflows that automate investigations, governance, policy enforcement and repetitive security operations.
- Own Geordie's Information Security Management System (ISMS), automating evidence collection, control monitoring and questionnaire response so that ISO 27001, SOC 2 and audit-readiness are continuously maintained rather than periodically assembled.
- Partner with Solutions Engineering on customer security questionnaires, due diligence and enterprise security reviews.
- Ensure the business maintains the operational maturity and trust required to support the world’s largest enterprises.
CUSTOMER ZERO
- Own Geordie’s implementation of our product, making us the best example anywhere of the product deployed well and an effective agent security programme
- Validate new capabilities in production before they reach customers, and provide real operator experience to our product engineering teams.
- Act as an external reference for customers and prospects, showi