1

Head Of Programs Jobs in Kentucky (NOW HIRING)

Head of Security

London, KY · On-site

$120 - $150/hr

Own the vulnerability management programme: scanning, prioritisation, SLAs, and closure. * Work with the Head of Compliance on the evidence side -- they need clean data for audits, you need clean ...

The Head of Learning and Talent Management Technologies leads and advances IFF's learning and ... and talent programs. Why Choose Us? * Join a purpose-driven company focused on sustainable ...

$220 - $250/hr

Position Overview Carlyle is seeking a senior marketing leader to serve as Head of Integrated ... Translate enterprise narratives into integrated programs spanning paid, owned, and earned channels.

$189K - $261K/yr

Head of Total Rewards Operations - U.S. & Canada Siemens Healthineers is seeking a Head of Total ... Not Total Rewards strategy or program design * Not a siloed functional role This is a high-impact ...

To assist the Head of Entertainment in the implementation of the recreation programme by ensuring that the needs of guests, staff and external users are met. * To ensure that the sport facilities and ...

next page

Showing results 1-20

Head Of Programs information

What is the difference between Head Of Programs vs Program Manager?

AspectHead Of ProgramsProgram Manager
ResponsibilitiesOversees multiple projects, sets strategic direction, manages teams, and aligns programs with organizational goals.Manages individual projects or a set of related projects, ensuring timely delivery and resource coordination.
Required CredentialsTypically requires a bachelor’s or master’s degree in a related field, with extensive experience in program management and leadership certifications.Usually requires a bachelor’s degree, project management certifications (e.g., PMP), and relevant experience.
Work EnvironmentSenior leadership setting, often in non-profit, government, or corporate sectors, with strategic planning responsibilities.Operational environment, working closely with project teams, stakeholders, and clients to deliver specific projects.

The Head Of Programs focuses on strategic oversight and leadership of multiple programs, while the Program Manager handles the day-to-day management of individual projects. Both roles require strong project management skills, but the Head Of Programs has a broader, more strategic scope.

What does a head of programs do?

A Head of Programs is responsible for overseeing the planning, development, and execution of multiple projects or initiatives within an organization. This role involves managing program teams, ensuring alignment with organizational goals, measuring program success, and often reporting progress to senior leadership. The Head of Programs collaborates with various stakeholders to secure resources, mitigate risks, and adapt strategies as needed. Their work is crucial to ensuring that programs are delivered on time, within budget, and with the desired impact.

What are some common challenges faced by a head of programs when managing multiple projects across different teams?

A Head of Programs often encounters challenges such as balancing competing priorities, ensuring clear communication across diverse teams, and aligning multiple projects with overall organizational goals. Managing resource allocation and timelines can be complex, especially when teams have overlapping needs or dependencies. Additionally, adapting to shifting stakeholder expectations and maintaining high program quality requires strong leadership, strategic thinking, and proactive problem-solving.

What are the key skills and qualifications needed to thrive as a head of programs?

To thrive as a Head Of Programs, you need expertise in program management, strategic planning, and budgeting, usually backed by an advanced degree in management or a related field. Familiarity with project management tools, data analysis software, and reporting systems is typically required, along with certifications like PMP or PRINCE2. Strong leadership, stakeholder management, and communication skills distinguish top performers in this role. These abilities are critical for ensuring program success, driving organizational objectives, and maintaining effective team and partner relationships.
Infographic showing various Head Of Programs job openings in Kentucky as of August 2026, with employment types broken down into 1% As Needed, 77% Full Time, 19% Part Time, and 3% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution.

Head of Security

Medium

London, KY • On-site

$120 - $150/hr

Other

Re-posted 26 days ago


Job description

About Fresha

The AI‑powered operating system for the global beauty, wellness and self‑care industry, connecting and powering everything from salons and barbers to spas, med‑spas, fitness studios and health practices. Trusted by millions of consumers and businesses worldwide. Fresha is used by 140,000+ businesses and 450,000+ stylists and professionals worldwide, processing over 1 billion appointments to date. The company is headquartered in London, United Kingdom, with 15 global offices located across North America, EMEA and APAC.

About the role

Reports to: VP of Security, IT and Compliance

We're looking for someone to own security end‑to‑end at Fresha. You'll shape the security strategy alongside the VP, build and run the controls that protect the business, and be the person everyone — engineers, execs, auditors, customers — looks to regarding security questions.

You'll work alongside the Head of Compliance (who sits under the same VP) as a peer. They own the frameworks, the audits, and the evidence. You own the actual security posture, the tooling, and the response. The two roles need each other to succeed, and we expect you to work closely together rather than carve out territory.

We're a payments business operating in a regulated space, with HIPAA and ISO 27001 behind us and PCI DSS, GDPR, and SOC 2 Type II ahead of us this year. The security bar is not theoretical.

To foster a collaborative environment that thrives on face‑to‑face interactions and teamwork, this role will be based in our dog‑friendly office 5 days per week in London: The Bower, 207‑122, Old Street, London EC1V 9NR.

What you’ll own Security strategy and roadmap
  • Shape the security strategy together with the VP — the VP sets direction at the exec level, you bring the ground truth, the technical depth, and the detailed plan that turns that direction into something real.
  • Own the security roadmap that falls out of it: what we're building, what we're retiring, what we're deferring, and why.
  • Make the call on where to invest day‑to‑day: tooling, headcount, external services, automation — within the strategic envelope agreed with the VP.
  • Translate that roadmap into something the exec team can actually read and fund.
Controls and protections
  • Deploy and run the security controls across the estate — endpoint, network, cloud, identity, application.
  • Make sure controls are actually working, not just deployed — continuous validation, not annual tick‑boxing.
  • Partner with Engineering and IT to get controls in early, rather than bolted on after the fact.
Penetration testing and vulnerability management
  • Run the regular external pentest cadence — application, infrastructure — and make sure findings are triaged and closed.
  • Own the vulnerability management programme: scanning, prioritisation, SLAs, and closure.
  • Work with the Head of Compliance on the evidence side — they need clean data for audits, you need clean closure on the underlying issues. Same data, different purposes.
Incident response
  • Own the IR process end‑to‑end: detection, triage, containment, eradication, recovery, and post‑incident review.
  • Run the on‑call model, the playbooks, the tabletop exercises, and the tooling behind them.
  • Be the person in the room when something real happens, and the person writing the honest post‑mortem afterwards.
Threat intelligence and threat modelling
  • Stand up a threat intelligence capability — somewhere past incidents, near‑misses, industry reports, and internal telemetry get captured, tagged, and made useful.
  • Build this into a threat intel data warehouse that actually informs decisions: future threat modelling, control design, roadmap prioritisation, and tabletop scenarios. Not a dashboard nobody reads.
  • Run threat modelling as a routine practice, not a one‑off — including automated threat modelling using AI against designs, code, and infrastructure changes.
Emerging threats
  • Keep a forward view on where the threat landscape is heading, especially around LLMs: prompt injection, model abuse, AI‑augmented vulnerability scanning by attackers, and exposure of sensitive data through AI tooling.
  • Don't just react to what's hitting us today — make sure we're not blindsided by what's hitting everyone in 12 months.
  • Feed that view into the strategy conversation with the VP, and turn it into concrete roadmap items rather than slide decks.
Security training and awareness
  • Own the security‑specific training content: phishing simulations, secure coding for engineers, threat modelling training, IR tabletop participation, and role‑based training for anyone handling cardholder data, PHI, or other sensitive material.
  • Partner with the Head of Compliance — they run the overall training programme, cadence, and evidence; you bring the security substance and keep it current with the threat landscape.
  • Make the training actually useful. Engineers should walk away knowing something they didn't before, not clicking through slides to get a completion tick.
Automation and AI
  • Look at every recurring task in this function and ask “why is a human still doing this?” — triage, alert enrichment, vulnerability prioritisation, evidence gathering, threat modelling, IR runbooks.
  • Push existing tooling as far as it’ll go, and fill the gaps with scripts, workflows, or AI where it makes sense.
  • Use LLMs sensibly for drafting, review, analysis, and automation — while being clear‑eyed about where they introduce new risks we have to manage ourselves.
  • Treat the function's operating model as a product: fewer manual rituals each quarter, better coverage, faster response.
Security advisory
  • Be the go‑to person for security questions across the business — architecture reviews, vendor assessments, new products, acquisitions, anything risky.
  • Give engineers a straight answer and a path forward, not a ticket queue and a policy link.
What we’re looking for
  • You’ve led security at a company operating under real regulatory pressure — payments, healthcare, financial services, or similar.
  • You’ve run incident response for real incidents, not just exercises, and you’ve written the post‑mortems.
  • You understand modern attack surfaces: cloud, SaaS, identity, supply chain, application — and you don't reduce security to any one of them.
  • You’ve built or meaningfully improved a threat intel or threat modelling capability, not just consumed vendor feeds. You're fluent with AI tools and comfortable building automation. 'I’ll wait for someone to build it for me’ isn't the right mindset — but neither is “let’s put an LLM on everything.” You know the difference.
  • You’re comfortable co‑owning strategy with a VP — bringing strong opinions, challenging when it matters, and aligning once a direction is set.
  • You can hold your own with engineers on technical depth and with execs on business framing.
  • Bonus: experience with payments/PCI environments, offensive security background, or a track record of measurably reducing manual security work through automation.
How you’ll work

You’ll have a team to lead from day one, with scope to grow it as the roadmap demands. You'll work closely with the VP on strategy, and with the Head of Compliance, IT, Engineering, Infrastructure, and Product on execution. You'll be in front of customers and auditors often enough that polish matters. Expect to spend real time hands‑on — in tooling, in incidents, in design reviews — not just managing.

Interview Process
  • Screen Stage — Video‑call with a member from the Talent Team (45‑60 min)
  • 1st Stage — Interview with the VP of Security, IT & Compliance (60 min)
  • Final Stage — Video interview with CTO (60 min) and Head of Talent (30 min)

We aim to finalise the entire interview process and deliver feedback within 4 weeks. Every job application received is reviewed manually by our talent team. While we strive to assess applications within 7 days, the sheer volume of talented individuals expressing interest may occasionally extend this timeframe.

Inclusive workforce

At Fresha, we are creating a culture where individuals of all backgrounds feel comfortable. We want all Fresha people to feel included and truly empowered to contribute fully to our vision and goals. Everyone who applies will receive fair consideration for employment.

We do not discriminate based on race, colour, religion, sex, sexual orientation, age, marital status, gender identity, national origin, disability, or any other applicable legally protected characteristics in the location in which the candidate is applying.

If you have any accessibility requirements that would make you more comfortable during the interview process and/or once you join, please let us know so that we can support you.

#J-18808-Ljbffr