Ophelos

Information Security Manager

London Full Time

Our Mission

At Ophelos, we believe in a different way to deal with debt. One that puts empathy and understanding front and centre, approaching our customers as individuals — no matter what they’re going through.

For too long, people in debt have borne the brunt of poor industry practices. Intimidating tactics, time-consuming customer service and a one-size-fits-all approach that overlooks the reasons anyone can fall into debt in the first place. Meanwhile, businesses suffer too. Poor customer experience translates to poor customer satisfaction, high churn rates, bad brand reputation and ultimately missed opportunities.

That’s why we’re taking a radically different approach. Pioneering an industry-first AI-native collections platform, we build products that help individuals clear their debts in a way that suits them, whilst providing businesses with an improved customer experience and game-changing insights into their customer base.

Since our launch in 2021, we’ve worked with some of the UK’s leading companies, including Octopus, Scottish Power and Philips — helping millions of people move toward a more stable, debt-free future. In 2023, we were acquired by Intrum, Europe’s biggest credit management service and have begun the next phase in our growth — expansion into 17 European markets over the next two years.

The Role - Information Security Manager

We are looking for an experienced and strategic Information Security Manager to lead our newly forming Security & Compliance team. Reporting to the Engineering Director of Ophelos Tech, you will be joining Ophelos at a pivotal moment - we've consistently excelled at meeting compliance obligations (our previous ISO27001 audit came back with zero findings!), but we're now moving into a new AI-powered world with evolving compliance requirements to navigate and remediate.

Ophelos Tech is an AI-first technical organisation, and our platform makes significant use of LLM agents both in development and production contexts. A major part of this role will be ensuring their use is safe, compliant, and that the right guardrails are in place. You'll be working at the bridge between "startup" and "scaleup", where introducing security discipline to a fast-moving technical organisation becomes paramount. This role requires significant self-direction - you will need to surface security issues proactively, prioritise them effectively, and facilitate their remediation across the organisation.

Ophelos Tech operates hybrid working, and believe face-to-face working time is essential for planning and alignment. Our teams spend two days each week working in-person from our comfortable office near Liverpool Street in London.

 

In this role, you’ll get to:

  • Lead. Build and shape our new Security & Compliance team, managing and coaching your reports as they grow their careers within the organisation.
  • Own our security and compliance posture - maintaining and advancing our ISO27001 certification, UK GDPR obligations, and navigating broader frameworks including NIST, ISO31000, and CIS controls.
  • Partner with our Product-Engineering teams to ensure our AI-native platform operates with appropriate security guardrails and controls, with privacy-by-design embedded from the start.
  • Stay ahead of emerging AI compliance standards such as ISO42001 and the EU AI Act, and manage external audits and certification renewals end-to-end.
  • Drive security incident response efforts, leveraging observability tooling (Datadog and incident.io) to enhance monitoring and build meaningful dashboards and metrics.
  • Foster a security-aware culture across the organisation through training, awareness programmes, and cross-functional collaboration.

About you

We believe that no one is the finished article - however, some experience in the following is important for this role:

  • A proven track record of implementing security programmes in dynamic, fast-growing environments, particularly at the "startup" to "scaleup" bridge.
  • Strong working knowledge of ISO27001, UK GDPR, and broader frameworks such as NIST, ISO31000, and CIS controls.
  • Experience managing external audits and vendor/third-party security risk assessments.
  • Familiarity with AI compliance considerations - experience with ISO42001 or the EU AI Act is a bonus, but a genuine enthusiasm for navigating this evolving landscape is essential.
  • You thrive at the intersection of compliance, technology, and people - equally comfortable in the weeds of a technical platform and in the room securing organisational buy-in.
  • You are excited about Ophelos' mission to support households and businesses in breaking the vicious debt cycle.

 

Here at Ophelos we are committed to pay transparency. That's why we share the salary range with every job posting.

Salary Range
£80,000£95,000 GBP

About Our Team

Ophelos launched in June of 2021, backed by investors such as AlbionVC, Connect Ventures and Fly Ventures. In 2023, we were acquired by Intrum, Europe’s biggest credit management service. Our growing team has team helped build some of the world’s most successful businesses, including the likes of Monzo, Google, Oracle, ASAPP, IBM and more — in addition to pioneering innovative products, sitting at the intersection of enterprise, financial technology, artificial intelligence and academia, working with institutions such as Oxford University, the University of Amsterdam and the University of Hong Kong.

Our Values

Supporting customers and businesses to improve their financial health is a long-term mission. Our company values act as our north star, steering our every move as an organisation and are the backbone of our unique company culture. Our values and culture allow us to stay true to our larger purpose, even as we continue to grow at a rapid pace.

Customers and Clients first – We exist to help real people move through debt and to get clients paid back. This commitment drives how we design products, deliver services, and interact with customers and clients daily.

Dream big – We have ambition and drive to succeed - we’re not just raising the bar, we’re confidently asserting ourselves as the benchmark.

Get it done – We’re decisive and embrace a sense of urgency; we don’t let opportunities get away from us. We’d rather act quickly and take informed risks, iterating and learning as we go. 

Win as one - We work as one team, supporting each other and aiming for shared goals. At Ophelos, the team isn’t just individual departments - it’s all of us together.  We challenge and support each other because we care about everyone’s growth and success. 

Ophelos is committed to creating a diverse work environment and is proud to be an equal opportunity workplace, providing equal employment and advancement opportunities to all team members. We are building an environment where every Ophelos team member can thrive, feel a sense of belonging, and do the best work of their careers. We value diversity and recruit, hire, and promote individuals solely based on talent, qualifications, competence, and merit. We evaluate candidates without regard to race, colour, religion, age, sex, sexual orientation, gender identity, national origin, disability, or other protected characteristics as required by law and as a matter of our company values.

 

GDPR Notice

When you apply to a job on this site, the personal data contained in your application will be collected by Ophelos (“Controller”), which is located at 1 Finsbury Ave, London EC2M 2PF and can be contacted by emailing contact@ophelos.com. Controller’s data protection officer is Paul Chong, who can be contacted at contact@ophelos.com. Your personal data will be processed for the purposes of managing Controller’s recruitment related activities, which include setting up and conducting interviews and tests for applicants, evaluating and assessing the results thereto, and as is otherwise needed in the recruitment and hiring processes. Such processing is legally permissible under Art. 6(1)(f) of Regulation (EU) 2016/679 (General Data Protection Regulation) as necessary for the purposes of the legitimate interests pursued by the Controller, which are the solicitation, evaluation, and selection of applicants for employment.

Your personal data will be shared with Greenhouse Software, Inc., a cloud services provider located in the United States of America and engaged by Controller to help manage its recruitment and hiring process on Controller’s behalf. Accordingly, if you are located outside of the United States, your personal data will be transferred to the United States once you submit it through this site. Because the European Union Commission has determined that United States data privacy laws do not ensure an adequate level of protection for personal data collected from EU data subjects, the transfer will be subject to appropriate additional safeguards under . You can obtain a copy of the standard contractual clauses by contacting us at contact@ophelos.com.

Your personal data will be retained by Controller as long as Controller determines it is necessary to evaluate your application for employment. Under the GDPR, you have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted. You also have to right to data portability. In addition, you may lodge a complaint with an EU supervisory authority.