VP OF SECURITY, IT AND COMPLIANCE · FRESHA · UK

Enrique Cano Carballar

I built Fresha's security function from the first dedicated hire into a 24×7 operation defending the world's largest beauty and wellness marketplace. The platform the SOC runs on is code I wrote.

I'm a hands-on security leader. At Fresha, 140,000+ businesses sit under sustained DDoS, credential stuffing, fraud and phishing. I stood up the SOC, the WAF and anti-abuse defences, threat modelling across every engineering team and the vulnerability management programme.

Then I re-platformed security operations for the AI era: the Security Hub and the agentic security assistant my team runs on are code I wrote. Underneath sits the governance a board expects: ISO 27001 and HIPAA certified, PCI DSS underway, enterprise risk and private-equity diligence.

Before Fresha, 13 years at General Electric securing mission-critical software for electricity and telecom utilities.

Fresha

2021 — now · London

Global beauty and wellness marketplace and payments platform. 140,000+ partner businesses in 120+ countries, 35m+ appointments a month, ~$1.4bn monthly marketplace value. Engineering across the UK, Poland and Kosovo.

Vice President of Security, IT and Compliance

2024 —

Accountable for cyber security across the group: engineering, 24×7 operations, platform and anti-abuse defence, plus privacy, compliance and corporate IT. I own strategy, roadmap, budget, headcount and vendors.

  • Board and investor assurance. I present risk posture, incident performance and roadmap to the board and C-suite. Led the security, privacy and compliance workstream of a major private-equity diligence, producing the evidence pack and fronting investor sessions.
  • Certification. Led the first ISO 27001 certification end to end, through surveillance and recertification. Extended to HIPAA; now leading PCI DSS. Implemented a GRC platform automating evidence collection across AWS, GitHub and Datadog.
  • Risk. Built the enterprise risk framework and the third-party risk programme, with a standing executive review forum.
  • Supply chain and AI governance. GitHub Actions hardening, dependency firewall, and the org-wide response to a GitHub-borne worm event. I own the group AI usage policy and AI spend governance.
  • Privacy. GDPR operations through rapid international growth: DSARs, law-enforcement and regulator requests, ICO submissions, intra-group transfer agreements, a group-wide retention framework.
  • Corporate IT as a product. Took ownership of IT in 2025 and rebuilt it around automation, driven by the IT Hub I built. Hands-on delivered the HRIS and ATS migrations.
  • Team. Grew a distributed team across security engineering, operations, GRC and IT. Developed engineers into lead roles and recruited a Head of Compliance beneath me.

Head of Security

2022 — 2024

Built the operational security capability for a platform under continuous attack.

  • Stood up the SOC. Cloud SIEM, alerting, runbooks, on-call and 24×7 cover, incident response plan, tabletop exercises, blameless post-mortems. Recruited and developed the analysts who run it.
  • Platform defence at scale. WAF estate as code across every CloudFront distribution, automated IP blocking from traffic analysis and OSINT, rate limiting, a maintenance-page capability for use under attack, reCAPTCHA and adaptive 2FA.
  • Held the line. Volumetric DDoS, distributed scraping, credential stuffing, BIN testing, SMS pumping, payout fraud and repeated brand-impersonation phishing.
  • Fraud partnership. Partner risk scoring, phishing detection in the marketing approval path and account-takeover containment with Payments, Data Science and Trust.
  • Vulnerability management. Policy, scoring model and SLAs; automated triage into per-team Jira tickets; external pen-test programme and bug bounty intake.
  • Security as a team sport. The "Jedi" security champions network, one per engineering team, and threat modelling embedded in the SDLC.

Principal Security Engineer

2021 — 2022

First dedicated security hire. Built the personal data inventory and the production data obfuscation pipeline for GDPR, cleared the inherited penetration test backlog and hands-on rebuilt authentication weaknesses in Elixir and Ruby.

General Electric

2008 — 2021 · Cambridge

Grid Software Solutions: 60+ commercial products for electricity, telecom and utility companies, including mission-critical Energy and Distribution Management Systems.

Cyber Security Architect

2018 — 2021

Cyber security authority for hundreds of engineers across the portfolio. Led architecture and hands-on development of the shared security platform: OAuth2, role-based authorisation, an API gateway and automated certificate management with PKI over EST and OCSP. Owned the Secure Development Life Cycle and embedded Privacy by Design for GDPR.

Technical Lead / Senior Staff / Staff Software Engineer

2012 — 2018

Technical lead and architect for microservices and web apps on Predix, GE's Industrial IoT platform. Volunteered as site security lead for the Cambridge office across ~30 Smallworld products. Gold Award for technical leadership; co-inventor on a filed patent.

Earlier

British Telecommunications · Database Administrator2004 — 2008
Centro Rural de Comercio y Actividades · Software Developer2002 — 2003
Implemental Systems · Project Manager, Services Consultant1999 — 2002
Sainco · Software Developer1997 — 1999

Code I wrote, running in production

security-hub

Security Hub

A web UI and MCP server aggregating threat intelligence, operational metrics and controls in one place, so analysts and AI tools such as Claude Code operate the SOC through the same controls, permissions and audit trail.

agent

Agentic security assistant

A Slack-native LLM agent with a tool and playbook architecture, authorisation layer, guardrails and observability. Governed access to investigation and response actions that previously needed an engineer.

detection

AI-based detection

LLM and vision-model pipelines for phishing-campaign and malicious-content detection, benchmarked across providers and deployed into the live campaign approval path.

soc-shell

SOC Shell

The bespoke Python toolkit the SOC first ran on: one interface over observability data, WAF and CDN logs, production data and threat intelligence. Forerunner of the Security Hub.

it-hub

IT Hub

The Security Hub's counterpart for corporate IT: joiner/mover/leaver provisioning, device management, access provisioning and SaaS governance.

waf-as-code

WAF estate as code

AWS WAF and Shield Advanced across every CloudFront distribution, with automated IP/CIDR blocking driven by traffic analysis and OSINT feeds.

Leadership

Security strategy and roadmap · Board and investor reporting · Budget and headcount · Hiring and succession · Distributed multi-country teams · Vendor negotiation

Governance

ISO 27001 · HIPAA · PCI DSS (in progress) · GDPR and ICO · Enterprise and third-party risk · Policy and audit · GRC automation

Security engineering

Threat modelling · Secure SDLC · AppSec and OWASP Top 10 · Vulnerability management · Anti-abuse, bot and fraud defence · Incident response · Supply chain security

Platform & AI

AWS (WAF, Shield, CloudFront, Bedrock, IAM) · Kubernetes · Terraform · Datadog Cloud SIEM · Python, JavaScript · LLM agents, MCP, Claude Code · CI/CD