Sarah Gallagher

Operations, People & Information Security Leader

Operations, People, and Information Security leader with 10+ years in high-growth B2B SaaS, known for building governance and people functions from scratch and then personally running them. Built an ISO 27001:2022 ISMS end to end (GDPR policy, risk register, incident response) to Stage 2 certification, and is now a qualified Lead Auditor coordinating Cyber Essentials and planning ISO 9001. Owns full-cycle people operations — recruitment, performance management, culture, and comp & benefits — while contributing across customer onboarding, CS, and IT. Uses AI daily as a working tool, including benchmarking a full internal audit through Claude against a manual audit.

Experience

Head of Operations

SEAtS ONE (SaaS scale-up)

2022 – Present

  • Lead people operations and information security governance for a fast-growing SaaS business, while contributing across customer onboarding, customer success, and internal IT.
  • Built and own the ISMS and risk management framework from the ground up (GDPR policy, risk register, incident response plan), delivering ISO 27001:2022 Stage 2 certification; now qualified Lead Auditor running the internal audit programme, coordinating Cyber Essentials, and planning ISO 9001
  • Own end-to-end recruitment (role specification, sourcing, interview design, offer management, contracts) and the full onboarding/offboarding lifecycle across Asana, Softworks, SharePoint, and Hubstaff
  • Built the performance management framework from scratch: 1:2:1 cadence, probation and annual review scheduling, PIPs, and department competency frameworks
  • Lead culture and engagement (annual ESAT survey, internal comms, employee relations, events) and own compensation & benefits activity, including pay benchmarking, salary bands, and bonus framework design
  • Own responses to client and prospect RFIs, RFPs, and security questionnaires, representing security posture directly in customer due diligence conversations; manage supplier and vendor risk as part of the ISMS
  • Contribute to customer onboarding, customer success, and internal IT support; administer core systems (HubSpot, Asana, SharePoint, Hubstaff, Softworks, Docusign) and put internal systems and integrations in place, including independently designing and spec'ing a full employee management system in Bolt.ai
  • Created organisational structure, role definitions, and accountability frameworks across 8+ departments and 10+ managers as the business scaled to 50+ people; partner directly with the CEO on operational, people, and governance strategy
  • Use Claude daily for senior management reporting, policy drafting, and documentation; recently ran a full internal audit through Claude in parallel with a manual audit to compare outputs and refine the audit programme

Senior Project Manager

SEAtS Software Limited

2016 – 2022

  • Owned delivery of complex, regulated SaaS implementations across the UK and internationally, working directly with institutional and public-sector clients.
  • Ran a concurrent portfolio of 5–6 large-scale implementations, each managed from discovery through go-live
  • Managed budgets and financial reporting across the portfolio, maintaining clear visibility for leadership and clients
  • Served as primary point of contact for major clients through delivery, including regulated public-sector and higher-education organisations, presenting to C-suite and board-level stakeholders
  • Delivered projects in regulated environments (UKVI/Tier 4), maintaining audit-readiness throughout delivery
  • Supported pre-sales activity including bid and proposal writing, and responded to RFIs and security questionnaires covering business, technical, and security requirements

Project Administrator / Project Lead

University of South Wales

2013 – 2016

  • Led a compliance-critical systems implementation across four campuses, covering UKVI/Tier 4 deployment, biometric systems rollout, and organisation-wide training
  • Owned defined project areas independently within a multi-site environment, producing delivery plans and stakeholder reporting

Registration Team Leader / Project Administrator

Care Council for Wales

2011 – 2013

  • Line-managed a team of five while leading a full CRM implementation in a regulated public-sector environment, from requirements through rollout and training

Career highlights

January 2022

  • Started: Head of Operations at SEAtS ONE (SaaS scale-up)

    SEAtS ONE (SaaS scale-up)

January 2016

  • Started: Senior Project Manager at SEAtS Software Limited

    SEAtS Software Limited

January 2013

  • Started: Project Administrator / Project Lead at University of South Wales

    University of South Wales

January 2011

  • Started: Registration Team Leader / Project Administrator at Care Council for Wales

    Care Council for Wales

Skills

ISO 27001:2022 & ISO 9001 implementationGovernance, risk & auditIncident response design & deliveryGDPR & data protection policyRecruitment & talent acquisitionPerformance management & reviewsCulture, engagement & internal commsCompensation & benefitsVendor & supplier riskRFI/RFP & security questionnairesAI-enabled ways of workingExecutive & board reportingClaudeChatGPTBolt.aiNotion & Notion AISynthesiaCanvaHubSpotAsanaSharePointArrowsHubstaffSoftworksDocusignMicrosoft 365 & TeamsAzure

Education

Cambridge Management & Leadership School

University of the West of England

Certifications

  • ISO 27001:2022 Lead Auditor (2026)
  • PRINCE2 Foundation & Practitioner
  • Microsoft Azure: Cloud Infrastructure, Governance & Security Fundamentals
  • ILM Level 2 & 3, Team Leading
  • HubSpot Academy Certified
Built with Round Zero