Founding role

Head of Security (Founding)

Panamorphix · Southampton / Hybrid · Post-seed · Founding team

Build Panamorphix's security function from zero and make the platform deployable inside environments that will verify everything before they buy.

On-premises onlyAir-gap compatibleRegulated-sector buyersFirst security hire

Status

This role is not open yet. Hiring starts when pre-seed closes, but the conversation starts now.

Contact

mark.nicoll@panamorphix.com

No CV required at this stage. Say where you have worked and what you have built.

The role

Panamorphix is building CongregationDB — deterministic-first context graph infrastructure that provides a provable truth layer for enterprise AI decision systems. Our deployment model is on-premises only. Our customers are regulated financial institutions, reinsurance groups, healthcare organisations and government bodies. Our architecture is air-gap compatible by design.

Security is not a compliance checkbox at Panamorphix. It is a core product property and a primary commercial enabler. Enterprise customers in our target sectors will not deploy infrastructure they cannot independently verify is secure. This role exists to make that verification possible — and to ensure that everything we build, ship and deploy meets the standard our customers require before they ask.

This is a founding role. You will be the first security hire. You will build the function from zero, own it entirely, and shape the next three security hires that follow immediately post-seed.

What you will own

Deployment security

CongDB is Rust-based, on-premises, and air-gap compatible. CongSynth — our context synthesis layer — prepares and enriches legacy enterprise data for ingestion into the truth architecture. You will own the security of the full stack: deployment pipeline, runtime environment, and the infrastructure patterns we recommend to customers. This means being deeply familiar with what we have built, not auditing it from a distance.

InfoSec questionnaire pack

Every enterprise customer in our target sectors runs a security due diligence process before deployment. You will build and own the questionnaire response pack — the document set that answers those questions completely and credibly without requiring a founder to translate technical reality into compliance language. This pack is a commercial asset. It will be used in every sales process.

Pen test programme

You will select, brief and manage external pen testing partners. You will own the remediation process and maintain the test history. For customers operating in regulated environments an up-to-date pen test report is a procurement requirement — you will ensure we always have one.

Security policy and documentation

We have none yet. You will build it — internal security policies, incident response framework, access control documentation, supplier security standards. Built to the standard required for ISO 27001 readiness, which is a medium-term target.

The environment

The founder is actively building. CongDB alpha is running against canary data from five mid-cap private equity portfolio companies. CongSynth — the context synthesis engine — is in active development alongside the deterministic lane. This is not a concept. It is a system in motion.

The deployment model is on-premises only. No SaaS, no multi-tenant cloud. Every deployment is a sovereign instance inside a customer's controlled infrastructure. The security model is fundamentally different from a cloud-native product — there is no shared responsibility model, no cloud provider security layer to lean on. You need to be comfortable in this environment and to have worked in it before.

Target sectors are reinsurance, insurance, private equity, banking, healthcare, and government. Each brings its own regulatory and procurement security requirements — BMA, FCA, PRA, NHS DSPT, NCSC Cyber Essentials, and security classification frameworks at the more sensitive end. You do not need deep expertise in all of them, but you need to understand what each one means for a deployment architecture and a due diligence process.

Who you are

You have worked in security inside or alongside regulated financial services, government, defence, or healthcare infrastructure. You understand what it means to deploy software into an air-gapped or highly restricted environment. You have built or significantly contributed to a security function rather than just operated within one. You are comfortable being the most senior security voice in a room and making calls without a committee.

You are not looking for a Head of Security role at a scaled company with an existing team and a mature programme. You are looking for the role where you build the programme — and where the decisions you make in the first twelve months define the security posture of a company that will operate inside some of the most sensitive data environments in the market.

Compensation

This role opens when pre-seed funding closes. The founding team joins on EMI options at pre-seed valuation. For a Head of Security hire at this stage that is the material part of the compensation — you are not taking a job, you are taking a position in a company at the point where it is cheapest to do so.

Base salary will be competitive for a senior security hire at a well-funded early-stage company. We will not ask you to take a significant cash compromise in exchange for equity — both need to work.

If this is the right role

This role is not open yet — it opens when pre-seed closes. If you are the right person and the timing works, we want to have the conversation now so that when we move, we move quickly.

No CV required at this stage. Tell us where you have worked and what you have built.