Lead Information Security Compliance & Assurance activities for a regulated SaaS organisation. Deliver SOC 2 audits and ISO 27001 certification. Strengthen security governance and compliance framework.
Key Highlights
Key Responsibilities
Technical Skills Required
Benefits & Perks
Nice to Have
Job Description
Information Security Compliance & Assurance Lead
Permanent - £85,000
Location: Fully Remote
Information Security Compliance & Assurance Lead
We are seeking an experienced Information Security Compliance & Assurance Lead to support a regulated SaaS organisation through a critical period of security assurance and certification activity.
This is a hands-on role focused on leading and coordinating the delivery of a SOC 2 audits and ISO 27001 certification/surveillance audits, ensuring the business is audit-ready whilst strengthening its overall compliance and security governance framework.
This position will work closely with Technology, Engineering, Risk, Compliance, Legal and Executive stakeholders to drive audit preparedness, evidence collection, control effectiveness reviews and remediation activities.
The Information Security Compliance & Assurance Lead will have the following Responsibilities -
- Lead the end-to-end preparation and delivery of SOC 2 audits.
- Manage ISO 27001 certification, surveillance or recertification activities.
- Assess and mature security controls against relevant frameworks and regulatory requirements.
- Conduct control gap assessments and coordinate remediation plans.
- Develop and maintain information security policies, standards and procedures.
- Coordinate audit evidence gathering and validation across multiple business functions.
- Work directly with external auditors and certification bodies.
- Monitor and track remediation activities, ensuring timely closure of findings.
- Support risk assessments and control effectiveness reviews.
- Provide executive-level reporting on audit readiness, risks and compliance posture.
- Advise on security governance, assurance and continuous improvement initiatives.
Interested in remote work opportunities in Cyber Security? Discover Cyber Security Remote Jobs featuring exclusive positions from top companies that offer flexible work arrangements.
The Information Security Compliance & Assurance Lead will need to have the following skills/experience -
- Proven experience delivering successful SOC 2 Type II audits.
- Strong practical experience with ISO 27001 implementation and certification audits.
- Background in Information Security, Governance, Risk & Compliance (GRC), or Security Assurance.
- Experience working within a regulated environment, ideally SaaS, FinTech, HealthTech, InsurTech or other technology-led businesses.
- Strong understanding of information security controls, governance and risk management practices.
- Experience managing audit engagements and external auditor relationships.
- Ability to interpret and map controls across multiple frameworks.
- Excellent stakeholder management and communication skills.
- Experience driving remediation programmes across technical and business teams.
Browse our curated collection of remote jobs across all categories and industries, featuring positions from top companies worldwide.
Desirable Experience
- Experience within cloud-native environments (AWS, Azure and/or GCP).
- Familiarity with GDPR, NIST CSF, CIS Controls, PCI DSS or related frameworks.
- Security or audit certifications such as:
- ISO 27001 Lead Implementer or Lead Auditor
- CISSP
- CISM
- CRISC
- CISA
Similar Jobs
Explore other opportunities that match your interests