Fresha
2021 — now · LondonGlobal beauty and wellness marketplace and payments platform. 140,000+ partner businesses in 120+ countries, 35m+ appointments a month, ~$1.4bn monthly marketplace value. Engineering across the UK, Poland and Kosovo.
Vice President of Security, IT and Compliance
2024 —Accountable for cyber security across the group: engineering, 24×7 operations, platform and anti-abuse defence, plus privacy, compliance and corporate IT. I own strategy, roadmap, budget, headcount and vendors.
- Board and investor assurance. I present risk posture, incident performance and roadmap to the board and C-suite. Led the security, privacy and compliance workstream of a major private-equity diligence, producing the evidence pack and fronting investor sessions.
- Certification. Led the first ISO 27001 certification end to end, through surveillance and recertification. Extended to HIPAA; now leading PCI DSS. Implemented a GRC platform automating evidence collection across AWS, GitHub and Datadog.
- Risk. Built the enterprise risk framework and the third-party risk programme, with a standing executive review forum.
- Supply chain and AI governance. GitHub Actions hardening, dependency firewall, and the org-wide response to a GitHub-borne worm event. I own the group AI usage policy and AI spend governance.
- Privacy. GDPR operations through rapid international growth: DSARs, law-enforcement and regulator requests, ICO submissions, intra-group transfer agreements, a group-wide retention framework.
- Corporate IT as a product. Took ownership of IT in 2025 and rebuilt it around automation, driven by the IT Hub I built. Hands-on delivered the HRIS and ATS migrations.
- Team. Grew a distributed team across security engineering, operations, GRC and IT. Developed engineers into lead roles and recruited a Head of Compliance beneath me.
Head of Security
2022 — 2024Built the operational security capability for a platform under continuous attack.
- Stood up the SOC. Cloud SIEM, alerting, runbooks, on-call and 24×7 cover, incident response plan, tabletop exercises, blameless post-mortems. Recruited and developed the analysts who run it.
- Platform defence at scale. WAF estate as code across every CloudFront distribution, automated IP blocking from traffic analysis and OSINT, rate limiting, a maintenance-page capability for use under attack, reCAPTCHA and adaptive 2FA.
- Held the line. Volumetric DDoS, distributed scraping, credential stuffing, BIN testing, SMS pumping, payout fraud and repeated brand-impersonation phishing.
- Fraud partnership. Partner risk scoring, phishing detection in the marketing approval path and account-takeover containment with Payments, Data Science and Trust.
- Vulnerability management. Policy, scoring model and SLAs; automated triage into per-team Jira tickets; external pen-test programme and bug bounty intake.
- Security as a team sport. The "Jedi" security champions network, one per engineering team, and threat modelling embedded in the SDLC.
Principal Security Engineer
2021 — 2022First dedicated security hire. Built the personal data inventory and the production data obfuscation pipeline for GDPR, cleared the inherited penetration test backlog and hands-on rebuilt authentication weaknesses in Elixir and Ruby.