Skyscanner Security Squad

Additional Info

Job title of nominated professional (or team name)Head of IT Security
Company (where nominated professional or team is working)Skyscanner
Websitehttp://www.skyscanner.net
Company size (employees)800
CountryScotland

Overview

Over the past three years Skyscanner has quadrupled in size, and while there was solid foundation work in the Security function, it was led by a single person and the company lacked a security culture. In the past 12-18 months, a small team of 3 have expedited security, making it central to daily operations as part of company culture. The team has driven exceptional business change and helped foster security considerations across business practice and a wide range of teams.

All in a context of a website with 50m monthly users across the world and a working environment that makes use of the latest technologies. Skyscanner’s working model is of ‘Squads and Tribes’, where the business is split into many autonomous ‘mini start-ups’ within the company. This company dynamic has meant the Security Squad has had to be as innovative as the rest of the business in redefining how it approaches such a fast-changing part of our industry.

The Squad has not been able to rely on tried and tested methodologies of the past and has had to define its own path and be incredibly forward-thinking and brave, with initiatives including proactive war gaming and crowd-sourced bug bounties. It has embedded security into daily operations in a business structure.

This year the Security Squad set up the Security Scotland Meet Up, which now has approaching 500 members. The Squad have presented at schools, universities and other conferences, both at home and abroad, spreading the message of the importance of information security.

From Gareth Williams; Skyscanner CEO:
“Our Security Squad has achieved great things over the last 12 months. What I love about this team’s work is that they do so with a really strong customer-centricity. They are enthusiasts for security and thought leaders in eliminating our dangers and raising awareness”

Accomplishments

* Fundamentally changing an entire business to be best in breed in security in little over a year, with a small team
* Becoming respected thought-leaders in the security space
* Contributing hugely to the security community in the UK and beyond