Grant Cassin
Information Security Manager @loveholidays
Signup · Get unlimited contacts
WORK HISTORY
Information Security Manager @loveholidays
Leading information security governance and compliance as loveholidays prepares for IPO. Managing security across the business with focus on demonstrable maturity for external audit and investor due diligence.Governance & Compliance:∙ Operating the Information Security Risk Committee for company-wide security governance∙ Managing compliance with PCI DSS, ISO 27001, GDPR, NIS2, NIST CSF 2.0, and NIST SP 800-171∙ Coordinating external audit requirements and relationships∙ Managing NCSC Cyber Essentials certification annually (3 consecutive years) and external PCI DSS assessment with ongoing compliance∙ Building AI governance frameworks aligned to NIST AI RMF and ICO guidance as we expand into EU marketsOperations & Risk:∙ Running HackerOne\'s ethical hacking and penetration testing programmes∙ Managing public endpoint and API vulnerability scanning for continuous risk visibility∙ Managing vendor and supply chain due diligence assessments∙ Overseeing incident response and breach register management∙ Implementing workflow automation (n8n) and AI reasoning into infosec processes for efficiency and consistencyData Protection & Privacy:∙ Ensuring GDPR compliance across all operations, with focus on customer data protection∙ Managing data protection operations and overseeing Subject Access Requests∙ Implementing Google Cloud DLP and data monitoring to maintain visibility over customer information∙ Supporting further expansion into EU markets with appropriate data protection controlsMy Philosophy: Risk-based decision making based on actual business impact- customer data exposure, payment system risk, infrastructure threats, continuity. Security enables the business.
SKILLS
ABOUT GRANT CASSIN
Information Security Governance and Compliance Leader for high-growth tech firms.I blend technical infrastructure expertise with strategic security leadership, ensuring security measures are practical, scalable, and fully integrated with business objectives.At loveholidays, I lead the security programme across the EU, managing information security governance, compliance (PCI DSS, GDPR, NIS2, ISO 27001), and external audit relationships. Key achievements include establishing the Information Security Risk Committee for company-wide governance, building AI governance frameworks for EU market expansion, and running HackerOne\'s ethical hacking and pen test programmes.My approach: demonstrable security maturity, actual risk reduction based on business impact—not theoretical vulnerability counts. I\'ve been early in embedding AI and intelligent automation into everyday security operations: automating subject access requests and privacy data handling, triaging security events and tickets, processing vendor security questionnaires, and optimising vulnerability scanning workflows. Practical efficiency gains that let a small team scale governance across hundreds of systems.Previously at Zoopla Property Group, I scaled infrastructure and embedded security practices through IPO and complex M&A activity across multiple offices. 25+ years in IT, including technical infrastructure roles and engineering wireless network access control architectures.Focus: cross-functional collaboration with technology, legal, and operations; managed compliance; vendor due diligence; and workflow automation through n8n and AI reasoning.CompTIA Security+ certified. CRISC and CISM exams scheduled for 2026, with focus on AI governance and UK/EU regulatory evolution.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.