Information Security Lead
About Malted
Malted builds specialised customer interaction intelligence for financial institutions. Our platform combines advanced language technology with deep domain understanding to help firms make faster, more accurate decisions.
Our proprietary technology, purpose built for financial services, uncovers signals that generic AI misses, distilling intelligence into insights faster, more efficiently and more securely than anyone else.
We’re a small, passionate and highly technical team based in Edinburgh, combining deep machine learning experience with a rigorous approach to product design and engineering.
What you’ll do
You will define and execute on the security roadmap for Malted. You’ll work closely with the engineering team to ensure our infrastructure is "secure by design" and with the leadership team to ensure we meet the rigorous security standards expected by our enterprise clients.
Responsibilities
Own the ISMS: Lead the maintenance of our ISO 27001 certification and spearhead the upcoming SOC 2 Type 2 audit processes.
Endpoint & IT Security: Manage our fleet security via MDM (e.g. JumpCloud), ensuring robust encryption, patching, and access control across all company devices.
Cloud & Infrastructure Security: Work with engineers to harden our Kubernetes/container environments, manage IAM policies, and oversee vulnerability scanning and remediation.
Technical Implementation: Be the "boots on the ground" for security. Implement and manage security controls across our cloud environments (AWS) and internal IT systems.
Identity & Access Management: Own the lifecycle of user access, from onboarding and MFA enforcement to regular access reviews.
Vendor & Risk Management: Evaluate the security posture of our supply chain and conduct internal risk assessments.
Security Culture: Conduct security awareness training and act as the internal expert for all things privacy and security.
Who you are
We’re looking for a security professional who thrives in the "zero-to-one" phase of a startup. You are pragmatic and understand that security should enable the business, not block it. You are equally comfortable talking to an external auditor as you are debugging a CloudTrail log.
Minimum requirements
Eligible to work in the UK
At least 4 years of experience in information security, with a strong background in both compliance and technical security engineering.
Solid understanding of networking, encryption, and security fundamentals.
Proven track record of managing ISO 27001 and successfully delivering SOC 2 audits (ideally in a startup environment).
Ability to thrive in a fast-paced startup where you need to be self-directed and highly focused on execution.
Preferred requirements
Deep understanding of endpoint management and modern IT security tools (MDM, EDR, SSO).
Experience in the Financial Services sector, understanding the specific regulatory hurdles.
Professional certifications such as CISSP, CISM, or AWS/GCP Security Specialist.
Scripting proficiency (Python or Bash) to automate security checks and reporting.
Working at Malted
We’re based in Edinburgh and work from the office three days a week (Monday, Wednesday and Friday). The rest of the week is work from home. We keep a high bar for technical quality but a low tolerance for ego. You’ll join a team that values precision, humour and intellectual honesty.
Benefits
Competitive salary
Pension and stock options
Medical and life insurance
Hybrid working and ad-hoc flexibility
The chance to work on one-of-a-kind products at the forefront of the AI industry
Professional development and growth opportunities
A collaborative, inclusive workplace that promotes innovation and teamwork
Free snacks and drinks
Social events and company outings
Relocation assistance for candidates moving to Edinburgh
👉 Ready to apply? Click here
Note: Malted AI is an equal opportunity employer, and we encourage candidates from all backgrounds to apply.
We aren’t working with recruiters for these positions; we’re excited to connect directly with candidates who share our enthusiasm for small language models.
Location
Edinburgh
Job type
Part Time - 4 days per week. Hybrid (2 - 3 days on site)
Team
Engineering
Salary range
£75k - £95k