Head of Security

Fresha
Fresha

IT

London, UK

Posted on Sep 28, 2026

Head of Security | London

About Fresha

Fresha is the leading AI-powered operating system for the global beauty and wellness industry, giving businesses everything they need to run smarter, grow faster and build stronger client relationships.

In May 2026, Fresha secured an $80M growth investment from KKR at a valuation of $1B, officially reaching unicorn status and bringing total funding raised to $285M. Already profitable, Fresha is using this investment to accelerate global expansion and drive the next generation of AI and product innovation.

Today, Fresha operates at global scale, with offices across Europe, North America, the Middle East and Asia Pacific. Our platform is trusted by 130,000+ beauty and wellness businesses across 120 countries, with more than 1.5 billion appointments booked to date.

Our mission is simple: help beauty and wellness businesses grow by giving them the technology they need to attract clients, manage their operations and run their business in one place.

We’re continuing to scale rapidly across markets, teams and products, making this an exciting time to join us.

Role Overview

Head of Security | London, HQ | Office-based (5 days/week)

You'll own security end to end at Fresha. Reporting to the VP of Security, IT and Compliance, you'll shape the security strategy alongside them, build and run the controls that protect the business, and be the person everyone looks to on security: engineers, execs, auditors and customers.

You'll work as a peer to the Head of Compliance, who sits under the same VP. They own the frameworks, audits, and evidence. You own the security posture, tooling, and response. The two roles need each other to succeed, and we expect you to work closely together.

You'll have a team to lead from day one, with scope to grow it as the roadmap demands. Expect to spend real time hands-on: in tooling, in incidents, in design reviews.

To foster a collaborative environment that thrives on face-to-face interactions and teamwork, this role will be based in our dog-friendly office 5 days per week in London: The Bower, 207-122 Old Street, London EC1V 9NR.

What You’ll Do

  • Lead the Security Team: Hiring, priorities, the on-call rota and the day-to-day direction. Coach the people on it so each of them is measurably better a year in.

  • Controls & Protections: Deploy and run the controls across the estate: endpoint, network, cloud, identity and application. Prove they are working through continuous validation, so we know where we stand on any given day. Partner with Engineering and IT to get controls in at design time, while a change is still cheap to shape.

  • Penetration Testing & Vulnerability Management: Run the external pentest cadence across application and infrastructure, and make sure findings are triaged and closed. Own the vulnerability management programme: scanning, prioritisation, SLAs and closure. Work with the Head of Compliance on the evidence side. They need clean data for audits, you need clean closure on the underlying issues.

  • Incident Response: Own the IR process end-to-end: detection, triage, containment, eradication, recovery, and post-incident review. Run the on-call model, the playbooks, the tabletop exercises and the tooling behind them. Be the person in the room when something real happens, and the person writing the honest post-mortem afterwards.

  • Automation & AI: Look at every recurring task in this function and ask why a human is still doing it: triage, alert enrichment, vulnerability prioritisation, evidence gathering, threat modelling, IR runbooks. Push existing tooling as far as it will go, then fill the gaps with scripts, workflows or AI where it makes sense. Treat the operating model as a product: fewer manual rituals each quarter, better coverage, faster response.

  • Security Strategy & Roadmap: Shape the strategy with the VP. They set direction at exec level, you bring the ground truth, the technical depth and the plan that turns direction into something real. Own the roadmap that falls out of it: what we're building, what we're retiring, what we're deferring, and why. Make the day-to-day investment calls on tooling, headcount, external services and automation, and translate the roadmap into something the exec team can read and fund.

  • Threat Intelligence & Threat Modelling: Stand up a threat intelligence capability where past incidents, near-misses, industry reports, and internal telemetry get captured, tagged, and made useful. Build it into a threat intel data warehouse that informs control design, roadmap prioritisation and tabletop scenarios. The test is whether people reach for it when they make a decision. Run threat modelling as a routine practice, including automated threat modelling using AI against designs, code and infrastructure changes.

  • Emerging Threats: Keep a forward view on where the threat landscape is heading, especially around LLMs: prompt injection, model abuse, AI-augmented scanning by attackers, and exposure of sensitive data through AI tooling. Make sure we're ready for what will be hitting everyone in 12 months, and turn that view into roadmap items with owners and dates.

  • Security Advisory: Be the go-to person for security questions across the business: architecture reviews, vendor assessments, new products, acquisitions, anything risky. Give engineers a straight answer and a path forward, so they leave the conversation able to keep building.

  • Security Training & Awareness: Own the security-specific content: phishing simulations, secure coding, threat modelling training, IR tabletops, and role-based training for anyone handling cardholder data, PHI, or other sensitive material. The Head of Compliance runs the overall programme and evidence; you bring the substance and keep it current. Make the training good enough that engineers walk away knowing something they didn't know before.

What We're Looking For:

  • Security Team Leadership: You've led a security team before, and the people on it got better while you ran it.

  • Modern Attack Surface Depth: You understand cloud, SaaS, identity, supply chain and application security, and you treat them as one surface.

  • Real Incident Response: You've run IR for live incidents, with the post-mortems you wrote to show for it.

  • AI & Automation Fluency: You have a track record of measurably reducing manual security work through automation, and you use LLMs sensibly for drafting, review, analysis and automation. You're clear-eyed about the new risks they bring. You'll build the thing yourself when it pays off, and you can tell which problems deserve an LLM and which want a ten-line script.

  • Strategy Co-Ownership: You're comfortable co-owning strategy with a VP: bringing strong opinions, challenging when it matters, and aligning once a direction is set.

  • Threat Intelligence Builder: You've built or meaningfully improved a threat intel or threat modelling capability that your team came to rely on.

  • Two Audiences, One Person: You can hold your own with engineers on technical depth and with execs on business framing.

  • Bonus: You've led security at a company under real regulatory pressure (payments, healthcare, financial services or similar), you've worked in PCI DSS, ISO 27001, GDPR or HIPAA environments, or you have an offensive security background.

Inclusive Workforce

At Fresha, we are creating a culture where individuals of all backgrounds feel comfortable.

We want all Fresha people to feel included and truly empowered to contribute fully to our vision and goals. Everyone who applies will receive fair consideration for employment.

We do not discriminate based on race, colour, religion, sex, sexual orientation, age, marital status, gender identity, national origin, disability, or any other applicable legally protected characteristics in the location in which the candidate is applying.

If you have any accessibility requirements that would make you more comfortable during the interview process and/or once you join, please let us know so that we can support you.