About the Role
The Director of Security & Compliance is a new, senior role accountable for the security, governance, risk, compliance, continuity and data protection posture of TBI. This role leads the Security & Compliance function and provides authoritative leadership on cyber, AI and information security across the Institute. It is the named accountable owner for certifications, risk register, continuity arrangements and the security and governance of TBI's AI estate.
Responsibilities
- Accountable for security monitoring, incident response, remediation and security tooling / platform management across TBI.
- Own the relationship with the outsourced SOC and line manage the IT Security Engineer.
- Own the firm-wide security awareness programme, including phishing simulation, user training and security culture.
- Own the design of identity, access (RBAC) and authentication (MFA / SSO) standards.
- Own TBI's IT governance framework adoption and maintenance.
- Own the regulatory and standards compliance posture, including certification maintenance, control evidence, audit readiness and statutory reporting.
- Lead TBI's path to ISO 27001 certification as a strategic programme.
- Own the central Digital & Data Security risk register.
- Own the data classification framework, data retention policies and the GDPR / data subject rights operating model.
- Partner with Legal on the firm-wide data protection programme and breach notification process.
- Own disaster recovery and business continuity planning, testing and recovery.
- Own the security posture of TBI's AI estate, including access, authentication, prompt and output data protection, and third-party AI vendor risk assessment.
- Own TBI's Responsible Use Policy for AI tools across the firm.
- Own DevSecOps practice: secret management, vulnerability scanning, pipeline security gates, container and workload security and code-level vulnerability management.
- Own third-party security risk assessment and ongoing vendor security monitoring.
Requirements
- Significant senior leadership experience in security and compliance roles within a mid-to-large global organisation.
- Deep, demonstrable expertise in ISO 27001, with working knowledge of SOC 2, NIST CSF and other relevant frameworks.
- Strong technical credibility across modern security operations: SIEM, EDR, IAM, vulnerability management and DevSecOps tooling.
- Demonstrable expertise in GDPR and data protection in a global, multi-jurisdiction context.
- Demonstrable understanding of AI security and AI governance.
- Experience designing and running risk registers and risk processes at an organisational level.
- Strong stakeholder credibility at executive level; able to articulate security posture in business terms and influence non-technical audiences.
- Pragmatic, proportionate and able to balance security rigour with delivery velocity.
- Experience managing technical security staff and outsourced security partners.
- Comfortable operating in politically sensitive contexts and exercising judgement on disclosure, escalation and risk acceptance.
- Candidates must have the legal right to work in the UK.
Skills
- Cyber operations
- Governance frameworks
- Risk management
- AI security
- AI governance
- ISO 27001
- GDPR
- Data protection
- SIEM
- EDR
- IAM
- Vulnerability management
- DevSecOps
- Prompt injection defence
- Model risk assessment
- Third-party AI vendor risk assessment
Location
- UK
Work Type
- Full-time
Experience Level
- Senior leadership
Education Level
- CISSP (ISC)
- CISM (ISACA)
- ISO 27001 Lead Implementer
- CIPP/E or CIPM (IAPP)
- CRISC or CGEIT (ISACA)
- CCSP
- AIGP
About the Company
- At the Tony Blair Institute for Global Change, we work with political leaders around the world to drive change.
- We help governments turn bold ideas into reality so they can deliver for their people.
- We do it by advising on strategy, policy and delivery, unlocking the power of technology across all three.
- We share what we learn on the ground, so everyone can benefit.
- We do it to build more open, inclusive and prosperous countries for people everywhere.
- We are a global team of over 800 changemakers, operating in more than 40 countries, across five continents.
- We are political strategists, policy experts, delivery practitioners, technology specialists and more.
- We speak more than 45 languages.
- We are working on over 100 projects, tackling some of the world’s biggest challenges.
- We’re all here at TBI to make a difference.
- In a world of ever more complex challenges, we believe diversity of background and perspective is a strength.
- We pride ourselves on a culture that values and nurtures difference.
- We are dedicated to unlocking potential, not only for the countries we work in but also for each of our team members.
- No matter where you’re from or who you are, if you’re passionate about the transformative power of progressive politics, we invite you to build a better future with us.
