SECURITY LEADER · VP OF SECURITY, IT AND COMPLIANCE · UK

Enrique Cano Carballar

I build security teams from scratch, take them to a 24×7 operation, and still write the code they run on. Nearly 30 years in engineering and security, from critical-infrastructure software to a global marketplace and payments platform.

I'm a hands-on security leader. I can build a security team from scratch, take it to a 24×7 operation, and run it as an executive with board, investor and regulator accountability. I still write code, and the platforms my team operates on are mine.

I cover the whole discipline: security operations and platform defence under sustained attack, security engineering and architecture, risk and board assurance, supply chain security, corporate IT, and security for the AI era. I have done it in a fast-growing marketplace and payments company and in heavily regulated software for electricity and telecom utilities.

Currently VP of Security, IT and Compliance at Fresha. Previously Cyber Security Architect at General Electric.

Build and lead security teams

I can start a security function from a standing start and grow it into a multi-team organisation with its own strategy, budget and succession plan.

  • Build a function from the first hire into security engineering, security operations, GRC and IT teams spread across several countries.
  • Set strategy and roadmap, own budget, headcount and vendors, and hire end to end, then develop engineers into senior and lead roles and recruit leaders to carry the function forward.
  • Make security a team sport: a champions network with a champion in every engineering team, threat modelling embedded in the SDLC, and training compliance that runs itself.
  • Run corporate IT as a product, automating joiner/mover/leaver, device management, access provisioning and SaaS governance.

Security operations and platform defence

I can stand up detection, response and anti-abuse for a platform that is attacked every day, and run it 24×7.

  • Stand up a SOC from zero: cloud SIEM, alerting, runbooks, on-call and 24×7 cover, an incident response plan, tabletop exercises and a blameless post-mortem discipline. Recruit and develop the analysts who run it.
  • Lead the response to volumetric DDoS, distributed scraping, credential stuffing, account enumeration, BIN testing, SMS pumping, payout fraud and brand-impersonation phishing.
  • Deploy a WAF estate as code across every CDN distribution, with automated IP blocking from traffic analysis and OSINT, rate limiting, a maintenance-page capability for use under attack, and adaptive 2FA.
  • Run vulnerability management end to end: policy, scoring model and SLAs, automated triage into per-team tickets, the external penetration testing programme and bug bounty intake. Partner with payments, data science and trust teams on fraud scoring and account-takeover containment.

Security engineering and architecture

I can design and build the security platforms other engineers build on, and I still ship code myself.

  • Act as the security authority for hundreds of engineers across a large product portfolio, including mission-critical grid software under heavy regulation.
  • Architect and build shared security platforms: OAuth2, role-based authorisation, API gateways and automated certificate management with PKI over EST and OCSP.
  • Own a Secure Development Life Cycle, embed Privacy by Design, and fix authentication weaknesses hands-on in Elixir, Ruby and Python.
  • Harden the supply chain at organisation scale: CI pipeline hardening, a dependency firewall, secrets detection and rotation, rootless containers across a Kubernetes estate, and the response to a repository-borne worm.

Security for the AI era

I can re-platform security operations so analysts and AI agents work through the same controls, permissions and audit trail.

  • Build a security operations platform with a web UI and an MCP server, so people and AI tools such as Claude Code operate the SOC through one set of controls.
  • Ship production LLM agents with a tool and playbook architecture, an authorisation layer, guardrails and observability, giving non-engineers governed access to investigation and response actions.
  • Build LLM and vision-model detection pipelines for phishing campaigns and malicious content, benchmark them across providers and deploy them into live approval paths.
  • Set the AI usage policy and AI spend governance for an engineering organisation.

Risk and board assurance

I can give a board, investors and customers a clear, evidenced view of security risk, and carry the governance that comes with it.

  • Present risk posture, incident performance and roadmap to boards and C-suites, and front the security workstream of investor due diligence, evidence pack included.
  • Build an enterprise risk framework with a standing executive review forum, and a third-party risk programme with vendor tiering and contractual requirements.
  • Take a company through certification such as ISO 27001, HIPAA or PCI DSS from a standing start, with evidence collection automated rather than run from spreadsheets.
  • Run privacy operations through international growth: subject access, law-enforcement and regulator requests, transfer agreements and retention.

Code I wrote, running in production

security-hub

Security Hub

A web UI and MCP server aggregating threat intelligence, operational metrics and controls in one place, so analysts and AI tools such as Claude Code operate the SOC through the same controls, permissions and audit trail.

agent

Agentic security assistant

A Slack-native LLM agent with a tool and playbook architecture, authorisation layer, guardrails and observability. Governed access to investigation and response actions that previously needed an engineer.

detection

AI-based detection

LLM and vision-model pipelines for phishing-campaign and malicious-content detection, benchmarked across providers and deployed into the live campaign approval path.

security-platform

Shared security platform

OAuth2, role-based authorisation, an API gateway and automated certificate management with PKI over EST and OCSP, built for the next generation of a 60-product grid software portfolio.

waf-as-code

WAF estate as code

AWS WAF and Shield Advanced across every CloudFront distribution, with automated IP/CIDR blocking driven by traffic analysis and OSINT feeds.

it-hub

IT Hub

The Security Hub's counterpart for corporate IT: joiner/mover/leaver provisioning, device management, access provisioning and SaaS governance.

Fresha

2021 — now · London

Global beauty and wellness marketplace and payments platform. 140,000+ partner businesses in 120+ countries, 35m+ appointments a month, ~$1.4bn monthly marketplace value. Engineering across the UK, Poland and Kosovo.

Vice President of Security, IT and Compliance

2024 —

Accountable for cyber security, privacy, compliance and corporate IT across the group. Board and investor reporting, ISO 27001, HIPAA and PCI DSS, enterprise and third-party risk, AI governance, and the re-platforming of security operations around the Security Hub and the agentic assistant.

Head of Security

2022 — 2024

Built the operational security capability for a platform under continuous attack: the SOC, the WAF estate, anti-abuse and fraud defences, vulnerability management and the security champions network.

Principal Security Engineer

2021 — 2022

First dedicated security hire. Threat modelling across every team, the GDPR data inventory and obfuscation pipeline, the penetration test backlog and hands-on authentication fixes.

General Electric

2008 — 2021 · Cambridge

Grid Software Solutions: 60+ commercial products for electricity, telecom and utility companies, including mission-critical Energy and Distribution Management Systems under heavy regulation.

Cyber Security Architect

2018 — 2021

Cyber security authority for the portfolio. Architecture and hands-on development of the shared security platform, ownership of the Secure Development Life Cycle, and Privacy by Design for GDPR.

Technical Lead / Senior Staff / Staff Software Engineer

2012 — 2018

Technical lead and architect for microservices and web apps on Predix, GE's Industrial IoT platform. Site security lead for the Cambridge office across ~30 products. Gold Award for technical leadership; co-inventor on a filed patent.

Earlier

British Telecommunications · Database Administrator2004 — 2008
Centro Rural de Comercio y Actividades · Software Developer2002 — 2003
Implemental Systems · Project Manager, Services Consultant1999 — 2002
Sainco · Software Developer1997 — 1999

Leadership

Security strategy and roadmap · Board and investor reporting · Budget and headcount · Hiring and succession · Distributed multi-country teams · Vendor negotiation

Governance

ISO 27001 · HIPAA · PCI DSS (in progress) · GDPR and ICO · Enterprise and third-party risk · Policy and audit · GRC automation

Security engineering

Threat modelling · Secure SDLC · AppSec and OWASP Top 10 · Vulnerability management · Anti-abuse, bot and fraud defence · Incident response · Supply chain security · PKI and identity

Platform & AI

AWS (WAF, Shield, CloudFront, Bedrock, IAM) · Kubernetes · Terraform · Datadog Cloud SIEM · Python, JavaScript · LLM agents, MCP, Claude Code · CI/CD