About the Role
This role is for a dedicated owner of information security and compliance within the Technology & Operations team. It involves building and running the firm’s security and compliance program end-to-end, acting as the trusted point of contact for client data protection inquiries. The position is ideal for someone who wants to shape a program in a fast-moving, AI-forward consultancy.
Responsibilities
- Own and run Blue Matter’s information security program end-to-end, including for BlueCortex.
- Define, maintain, and operationalize security policies, standards, and procedures.
- Maintain the risk register, run regular risk assessments, and drive remediation.
- Report on security and compliance posture to leadership.
- Drive certification and attestation efforts (e.g., ISO 27001 and/or SOC 2).
- Build a sustainable, “always-audit-ready” approach.
- Track relevant regulatory and framework developments and translate them into practical action.
- Lead data protection under GDPR and UK GDPR.
- Maintain records of processing (RoPA), conduct Data Protection Impact Assessments (DPIAs), and own data-handling, retention, and minimization policies.
- Manage data subject requests and personal-data incidents.
- Oversee data transfer mechanisms and data residency considerations.
- Own the response to client security due-diligence.
- Support commercial and contractual discussions on security, privacy, and data processing terms.
- Maintain a library of reusable security documentation, certifications, and answers.
- Secure and govern the Microsoft 365 environment.
- Own identity and access management.
- Implement and tune data loss prevention (DLP), information protection/labelling, and device compliance.
- Partner with IT on secure configuration, patching, and endpoint hardening.
- Run third-party and vendor risk management.
- Maintain an inventory of vendors and their data access.
- Own the incident response plan; lead detection, triage, investigation, containment, and post-incident review.
- Investigate security events and produce incident reports.
- Run tabletop exercises.
- Build and deliver security awareness training and phishing simulations.
- Make security approachable and practical.
Requirements
- 5+ years of experience in information security and/or GRC, ideally in an environment that handles sensitive client data.
- Strong, practical knowledge of GDPR and UK GDPR and day-to-day data protection.
- Hands-on experience with ISO 27001 and/or SOC 2 implementation and audits.
- Working familiarity with the Microsoft security stack (Entra ID, Defender, Purview, Intune).
- Experience responding to client/customer security assessments and questionnaires.
- One or more relevant certifications (e.g., CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer/Auditor, CIPP/E, or CIPM) or equivalent demonstrable experience.
- Based in the UK with the right to work.
- Comfortable supporting a globally distributed team across time zones.
- Excellent written and verbal communication skills.
- Experience standing up or maturing a security/compliance program.
- Familiarity with EU and UK regulatory developments such as NIS2 and DORA.
- Experience managing third-party/vendor risk for SaaS and AI tooling.
- Exposure to life sciences or pharma, and awareness of GxP, GDP, or healthcare data considerations.
- Experience establishing data-protection or data-risk practices.
- Experience supporting M&A or subsidiary integration from a security and compliance perspective.
Skills
- Information Security
- GRC
- GDPR
- UK GDPR
- Data Protection
- ISO 27001
- SOC 2
- Microsoft Security Stack (Entra ID, Defender, Purview, Intune)
- Client Security Assessments
- Client Questionnaires
- CISSP
- CISM
- CISA
- CRISC
- ISO 27001 Lead Implementer/Auditor
- CIPP/E
- CIPM
- NIS2
- DORA
- Third-Party Risk Management
- Vendor Risk Management
- SaaS Security
- AI Tooling Security
- Life Sciences
- Pharma
- GxP
- GDP
- Healthcare Data
- HIPAA
- Data Protection Practices
- Data Risk Practices
- M&A Security Integration
- Subsidiary Integration Security
Location
- UK
Work Type
- Remote
- Hybrid
Experience Level
- 5+ years
About the Company
- Blue Matter is a rapidly growing strategic consulting firm serving clients in the life sciences industry.
- We partner with our clients to help them achieve commercial success across the lifecycle of their products, portfolios and organisations.
- Our project types include new product planning, launch strategy & planning, brand & life cycle planning and corporate & portfolio strategy, across a variety of specialty therapeutic areas.
- We have a unique entrepreneurial culture and invest in building Blue Matter to be one of the best places to work.
- We have a strong global presence with offices in the US (San Francisco, New York, Boston), Europe (London, Zurich, Netherlands), and India (Mumbai, Gurgaon, Pune).
