
NexGen Cloud · London
INFORMATION SECURITY OFFICER Location: London Department: Risk and Compliance Reporting to: Head of Risk and Compliance ABOUT NEXGEN CLOUD: NexGen Cloud is...
Location: London
Department: Risk and Compliance
Reporting to: Head of Risk and Compliance
NexGen Cloud is the company behind Hyperstack, a full-stack AI cloud serving tens of thousands of customers from AI researchers to
enterprises running the world's most compute-intensive workloads. We deliver on-demand and private GPU infrastructure to teams who
treat performance as a requirement, not a feature.
We're a tight-knit, fast-moving team working at the cutting edge of AI cloud infrastructure. We practice what we preach, equipping
our people with AI at every level so we can solve harder problems, ship faster, and keep raising the bar for what enterprise GPU
infrastructure looks like.
This role exists because as we scale our infrastructure and customer base, protecting the systems, data, and trust that underpin
Hyperstack is a business-critical priority. You'll have direct ownership over NexGen Cloud's information security posture — from
policy and risk frameworks through to incident response and compliance programmes.
This is a role for someone who operates independently, thinks in systems, and understands that good security is both a technical
and a business discipline.
Rather than a long checklist, here's what success in this role looks like:
tracking actions through to closure
We're more interested in how you think and work than in a perfect CV. You'll likely bring a combination of the following:
not required
Head over to our NexGen Cloud careers page to view current openings and follow us on LinkedIn and X to learn more about our
journey, newest releases and hear exciting news in the neocloud space.
Location: London, UK Weekly office requirement: Hybrid – 2 days per week Employment type: Permanent Seniority level: Mid-Senior At GWI we're always looking for extraordinary people who thrive on making an extraordinary impact. Right now we're looking for an Information Security GRC Specialist to play a key role in our Legal team in London. If that's you, and making a difference gets you out of bed in the morning, keep reading. It could be the start of something, well, extraordinary. SOUNDS GREAT, WHAT WILL I BE DOING? 🤔 As our Information Security GRC Specialist you'll play a pivotal role in shaping the future of security compliance at GWI. Reporting into our General Counsel and working closely with our Information Security, Product, and Technology teams, you'll own our compliance posture across security frameworks, vendor risk, and client-facing security requirements — while building a security-conscious culture across the business. A few things you'll be responsible for: 👉 Own and maintain GWI's ISO 27001 certification and compliance across relevant security frameworks, keeping our posture sharp as the threat landscape evolves. 👉 Develop, implement, and maintain information security policies and procedures aligned with industry best practices. 👉 Lead vendor risk management and client security assessments — including responding to client security questionnaires and onboarding requirements. 👉 Build and maintain GWI's security trust portal, showcasing our credentials to clients and stakeholders using tools such as Drata or Vanta. 👉 Drive security awareness across the business through training programmes and internal communications that promote a strong GRC culture. It's also fun; shaking things up is what working for GWI is all about. You'll need to be flexible, comfortable with continuous change, and working in a high-tempo environment. WHAT DO I NEED TO BRING WITH ME? 🧳 You'll need to be able to demonstrate the core skills this role requires. You don't have to tick all the boxes right away; the important thing is that you're willing to learn. Here's what the team will be looking for in you: 👉 In-depth, practical experience obtaining and maintaining ISO 27001 certification, with solid knowledge of frameworks such as NIST — typically 3–5 years in an information security compliance role, though other experience levels will be considered. 👉 Proven ability to develop and maintain security policies and procedures that align with industry best practice. 👉 Experience conducting vendor security assessments and managing client security onboarding requirements, balancing risk against commercial objectives. 👉 Hands-on experience building or maintaining a security trust portal; familiarity with tools such as Drata or Vanta is a plus. 👉 Knowledge of SaaS and AI environments, with experience implementing and managing cloud security best practices. 👉 Strong communication skills — able to translate complex GRC topics into clear internal guidance and keep the wider business informed and engaged on security matters. Equally important is attitude. We want people who think big (to make an impact), ask why (to find a better way), and show respect (to everyone, at every level, all the time). Those are our values, and they're a big part of what we're looking for in you. WHAT WE OFFER 🧘 At GWI, you’ll find meaningful work, visible impact, and a culture that empowers you to do your best. Our package includes: * Time to recharge – 25 days’ annual leave, plus office closures over the holidays. * Health & wellbeing – Health cash plan, enhanced family benefits, carer days, and mental health support. * Financial benefits – Competitive salary, 4% pension matching, and recognition programs that celebrate success. * Flexibility & balance – Flexitime, early Friday finishes, hybrid and remote options, plus a “work from home” budget. * Career growth – Accredited learning, leadership development, and global career mobility. * Community & impact – DE&I initiatives, volunteering opportunities, donation matching, and payroll giving. Put all that together and GWI is the friendliest, most fulfilling place any of us has ever worked. DIVERSITY, EQUITY & INCLUSION 🫶 Diversity is fundamental to who we are—both as a data company and as a workplace. Our data reflects global realities, and so must our teams. We strive to ensure our workforce is as diverse and inclusive as the insights we provide to our clients. As a Disability Confident employer, we welcome applications from disabled candidates and are committed to providing all necessary adjustments during the hiring process. We also actively encourage applications from underrepresented and marginalized communities. At GWI, you will find a place where you can contribute meaningfully, grow professionally, and belong fully. #li-hybrid #LI-NIKOSSS1
WPP is the trusted growth partner for the world’s leading brands. We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth. We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise. Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow. For more information, visit WPP.com. Why we're hiring: We're looking for a Business Security Services Director to partner with one of WPP's most strategically important technology platforms. This role will act as the dedicated security leader for WPP Open — our AI-powered marketing and business operating platform — helping ensure that security, trust, resilience and client assurance are embedded into how the platform evolves and scales. Working at the intersection of platform security, product security, AI risk and client trust, you'll collaborate closely with product, engineering, AI and operational teams to shape security outcomes across a high-growth, highly innovative environment. This is an opportunity to influence how one of WPP's most important technology investments manages security at scale while enabling innovation and business growth. What you'll be doing: Security Leadership & Business Partnering * Act as the primary security partner for WPP Open. * Build strong relationships across product, engineering, AI and architecture teams. * Translate enterprise security strategy into practical platform-specific outcomes. * Champion security as an enabler of innovation rather than a barrier to delivery. * Represent WPP Open within broader security governance and leadership forums. Product & AI Security * Partner with product and engineering teams to strengthen secure software development practices. * Support the ongoing evolution of platform, application and API security controls. * Help shape the governance and assurance of AI-enabled capabilities and agentic workflows. * Drive a risk-based approach to emerging challenges including AI misuse, prompt abuse and data protection. Client Trust & Security Assurance: * Help ensure robust controls around client data protection, segregation and confidentiality. * Support client assurance activities and security commitments for some of the world's leading brands. * Partner with internal stakeholders to maintain trust and confidence in WPP Open's security posture. Identity, Resilience & Risk: * Support the evolution of modern identity and access security models across the platform. * Contribute to platform resilience, continuity planning and recovery readiness. * Work closely with cyber incident response teams on security events, investigations and risk management activities. * Help define and communicate security metrics, risk indicators and platform security trends to senior stakeholders. What you'll need: * Significant experience in cyber security, product security, platform security or business-aligned security leadership roles. * Experience partnering with engineering, product and business teams in fast-moving technology environments. * Strong understanding of security challenges associated with cloud-native platforms, SaaS products and modern software delivery. * Knowledge of areas such as AI security, identity and access management, API security, client data protection and platform resilience. * Excellent stakeholder management, communication and influencing skills. * A pragmatic approach, balancing security requirements with product innovation and business objectives. Nice to Have * Experience securing AI-enabled products, platforms or digital services. * Familiarity with recognised security frameworks such as ISO 27001, ISO 42001, SOC2, NIST AI RMF or OWASP AI Top 10. * Experience working with cloud environments including Azure, AWS or Google Cloud. * Security certifications such as CISSP, CISM, CCSP or equivalent. Who you are: You're open: We are inclusive and collaborative; we encourage the free exchange of ideas; we respect and celebrate diverse views. We are open-minded: to new ideas, new partnerships, new ways of working. You're optimistic: We believe in the power of creativity, technology and talent to create brighter futures or our people, our clients and our communities. We approach all that we do with conviction: to try the new and to seek the unexpected. You're extraordinary: we are stronger together: through collaboration we achieve the amazing. We are creative leaders and pioneers of our industry; we provide extraordinary every day. What we'll give you: Passionate, inspired people – We aim to create a culture in which people can do extraordinary work. Scale and opportunity – We offer the opportunity to create, influence and complete projects at a scale that is unparalleled in the industry. Challenging and stimulating work – Unique work and the opportunity to join a group of creative problem solvers. Are you up for the challenge? #LI-Hybrid We believe the best work happens when we're together, fostering creativity, collaboration, and connection. That's why we’ve adopted a hybrid approach, with teams in the office around four days a week. If you require accommodations or flexibility, please discuss this with the hiring team during the interview process. WPP is an equal opportunity employer and considers applicants for all positions without discrimination or regard to particular characteristics. We are committed to fostering a culture of respect in which everyone feels they belong and has the same opportunities to progress in their careers. PLEASE READ OUR PRIVACY NOTICE (HTTPS://WWW.WPP.COM/EN/CAREERS/WPP-PRIVACY-POLICY-FOR-RECRUITMENT) FOR MORE INFORMATION ON HOW WE PROCESS THE INFORMATION YOU PROVIDE.
WPP is the trusted growth partner for the world’s leading brands. We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth. We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise. Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow. For more information, visit WPP.com. Why we're hiring: We're looking for a Technical Security Governance Lead – Software Development to help shape and strengthen secure software development governance across one of the world's largest technology and creative ecosystems. Working within WPP's Digital Security & Risk Management team, you'll partner with engineering, product and platform teams to govern secure-by-design ways of working, improve software security governance, and provide oversight across modern development environments. This role isn't about writing code day-to-day. Instead, you'll influence governance of how secure software is built, deployed and maintained across cloud-native platforms, APIs, AI-enabled applications and global engineering teams. This is an opportunity to influence software security governance at global scale, helping shape how security supports innovation across one of the world's largest and most diverse technology environments. You'll work alongside talented security and engineering professionals while helping build secure, resilient products and platforms for the future. What you'll be doing: * Define and evolve secure software development standards, guardrails and governance practices. * Partner with engineering and product teams to embed security into development lifecycles and delivery processes. * Improve visibility and management of software security risks, including vulnerabilities, insecure coding trends and dependency risks. * Strengthen governance of software supply chains, open-source dependencies and Software Bill of Materials (SBOM) practices. * Support the development of secure CI/CD pipelines through controls such as code scanning, secrets detection and release governance. * Help shape WPP's approach to securing AI-enabled applications, including areas such as prompt injection resilience, agent controls and data protection. * Provide insight, reporting and challenge to ensure software security risks are understood, prioritised and effectively managed. * Drive continuous improvements in software security maturity across the organisation. What you'll need: * Experience in application security, software security, DevSecOps, software assurance or technical security governance. * Strong understanding of Secure SDLC, application security and modern software development practices. * Knowledge of CI/CD security, cloud-native environments and software supply chain risk. * Experience working closely with engineering teams to improve security outcomes. * Strong stakeholder management and communication skills, with the ability to influence technical and non-technical audiences. * A pragmatic approach to balancing security, risk and delivery. Nice to Have: * Experience with cloud platforms such as AWS, Azure or Google Cloud. * Knowledge of SAST, DAST, SCA or software security tools. * Experience with AI-enabled applications and emerging software security challenges. * Security certifications such as CISSP, CSSLP or equivalent. Who you are: You're open: We are inclusive and collaborative; we encourage the free exchange of ideas; we respect and celebrate diverse views. We are open-minded: to new ideas, new partnerships, new ways of working. You're optimistic: We believe in the power of creativity, technology and talent to create brighter futures or our people, our clients and our communities. We approach all that we do with conviction: to try the new and to seek the unexpected. You're extraordinary: we are stronger together: through collaboration we achieve the amazing. We are creative leaders and pioneers of our industry; we provide extraordinary every day. What we'll give you: Passionate, inspired people – We aim to create a culture in which people can do extraordinary work. Scale and opportunity – We offer the opportunity to create, influence and complete projects at a scale that is unparalleled in the industry. Challenging and stimulating work – Unique work and the opportunity to join a group of creative problem solvers. Are you up for the challenge? #LI-Hybrid We believe the best work happens when we're together, fostering creativity, collaboration, and connection. That's why we’ve adopted a hybrid approach, with teams in the office around four days a week. If you require accommodations or flexibility, please discuss this with the hiring team during the interview process. WPP is an equal opportunity employer and considers applicants for all positions without discrimination or regard to particular characteristics. We are committed to fostering a culture of respect in which everyone feels they belong and has the same opportunities to progress in their careers. PLEASE READ OUR PRIVACY NOTICE (HTTPS://WWW.WPP.COM/EN/CAREERS/WPP-PRIVACY-POLICY-FOR-RECRUITMENT) FOR MORE INFORMATION ON HOW WE PROCESS THE INFORMATION YOU PROVIDE.