layiq
worthy; deserving; fitting; suitable.
A role, opportunity, or path that merits attention, time, and pursuit.
Loading LAYIQ…From Fresha's posting. “We” and “our” refer to the employer.
The AI-powered OS for beauty, wellness and self-care
Fresha is the AI-powered operating system for the global beauty, wellness and self-care industry, connecting and powering everything from salons and barbers to spas, medspas, fitness studios and health practices.
Trusted by millions of consumers and businesses worldwide. Fresha is used by 140,000+ businesses and 450,000+ stylists and professionals worldwide, processing over 1 billion appointments to date.
The company is headquartered in London, United Kingdom, with 15 global offices located across North America, EMEA and APAC.
Fresha allows consumers to discover, book and pay for beauty and wellness appointments with local businesses via its marketplace, while beauty and wellness businesses and professionals use an all-in-one platform to manage their entire operations with an intuitive business software and financial technology solutions.
Fresha’s ecosystem gives merchants everything they need to run their business seamlessly by facilitating appointment bookings, point-of-sale, customer records management, marketing automation, loyalty, beauty products inventory and team management.
The consumer marketplace unlocks revenue potential for partner businesses by leveraging the power of online bookings and automated marketing through mobile apps and advanced integrations with major tech brands including Instagram, Facebook and Google.
VP of Security, IT and Compliance
We're looking for someone to own security end-to-end at Fresha. You'll shape the security strategy alongside the VP, build and run the controls that protect the business, and be the person everyone — engineers, execs, auditors, customers — looks to regarding security questions.
You'll work alongside the Head of Compliance (who sits under the same VP) as a peer. They own the frameworks, the audits, and the evidence. You own the actual security posture, the tooling, and the response. The two roles need each other to succeed, and we expect you to work closely together rather than carve out territory.
We're a payments business operating in a regulated space, with HIPAA and ISO 27001 behind us and PCI DSS, GDPR, and SOC 2 Type II ahead of us this year. The security bar is not theoretical.
To foster a collaborative environment that thrives on face-to-face interactions and teamwork, this role will be based in our dog-friendly office 5 days per week in London: The Bower, 207-122, Old Street, London EC1V 9NR.
Shape the security strategy together with the VP — the VP sets direction at the exec level, you bring the ground truth, the technical depth, and the detailed plan that turns that direction into something real
Build this into a threat intel data warehouse that actually informs decisions: future threat modelling, control design, roadmap prioritisation, and tabletop scenarios. Not a dashboard nobody reads
Run threat modelling as a routine practice, not a one-off — including automated threat modelling using AI against designs, code, and infrastructure changes
Emerging threats
Keep a forward view on where the threat landscape is heading, especially around LLMs: prompt injection, model abuse, AI-augmented vulnerability scanning by attackers, and exposure of sensitive data through AI tooling
Own the security-specific training content: phishing simulations, secure coding for engineers, threat modelling training, IR tabletop participation, and role-based training for anyone handling cardholder data, PHI, or other sensitive material
Look at every recurring task in this function and ask "why is a human still doing this?" — triage, alert enrichment, vulnerability prioritisation, evidence gathering, threat modelling, IR runbooks
You're fluent with AI tools and comfortable building automation. "I'll wait for someone to build it for me" isn't the right mindset — but neither is "let's put an LLM on everything."You know the difference
How you'll work: You'll have a team to lead from day one, with scope to grow it as the roadmap demands. You'll work closely with the VP on strategy, and with the Head of Compliance, IT, Engineering, Infrastructure, and Product on execution. You'll be in front of customers and auditors often enough that polish matters. Expect to spend real time hands-on — in tooling, in incidents, in design reviews — not just managing.
Interview Process: Screen Stage
1st Stage
Final Stage -
Video interview with CTO (60min) and Head of Talent (30min)
We aim to finalise the entire interview process and deliver feedback within 4 weeks.
Every job application received is reviewed manually by our talent team. While we strive to assess applications within 7 days, the sheer volume of talented individuals expressing interest may occasionally extend this timeframe
Inclusive workforce
At Fresha, we are creating a culture where individuals of all backgrounds feel comfortable.
We want all Fresha people to feel included and truly empowered to contribute fully to our vision and goals. Everyone who applies will receive fair consideration for employment.
We do not discriminate based on race, colour, religion, sex, sexual orientation, age, marital status, gender identity, national origin, disability, or any other applicable legally protected characteristics in the location in which the candidate is applying.
If you have any accessibility requirements that would make you more comfortable during the interview process and/or once you join, please let us know so that we can support you.
LAYIQ is an independent job-discovery service. This listing does not imply a partnership with or endorsement by the employer. Review the original posting for current details and availability.
Employer posted: