S

Information Security Compliance & Assurance Lead

spencer rose United Kingdom
Remote
Apply
AI Summary

Lead Information Security Compliance & Assurance activities for a regulated SaaS organisation. Deliver SOC 2 audits and ISO 27001 certification. Strengthen security governance and compliance framework.

Key Highlights
Lead SOC 2 audits and ISO 27001 certification
Strengthen security governance and compliance framework
Work with Technology, Engineering, Risk, Compliance, Legal and Executive stakeholders
Key Responsibilities
Lead the end-to-end preparation and delivery of SOC 2 audits
Manage ISO 27001 certification, surveillance or recertification activities
Assess and mature security controls against relevant frameworks and regulatory requirements
Technical Skills Required
ISO 27001 SOC 2 Information Security
Benefits & Perks
£85,000 annual salary
Fully remote work
Permanent employment
Nice to Have
Experience within cloud-native environments (AWS, Azure and/or GCP)
Familiarity with GDPR, NIST CSF, CIS Controls, PCI DSS or related frameworks
Security or audit certifications such as: ISO 27001 Lead Implementer or Lead Auditor

Job Description


Information Security Compliance & Assurance Lead


Permanent - £85,000

Location: Fully Remote



Information Security Compliance & Assurance Lead


We are seeking an experienced Information Security Compliance & Assurance Lead to support a regulated SaaS organisation through a critical period of security assurance and certification activity.

This is a hands-on role focused on leading and coordinating the delivery of a SOC 2 audits and ISO 27001 certification/surveillance audits, ensuring the business is audit-ready whilst strengthening its overall compliance and security governance framework.

This position will work closely with Technology, Engineering, Risk, Compliance, Legal and Executive stakeholders to drive audit preparedness, evidence collection, control effectiveness reviews and remediation activities.


The Information Security Compliance & Assurance Lead will have the following Responsibilities -

  • Lead the end-to-end preparation and delivery of SOC 2 audits.
  • Manage ISO 27001 certification, surveillance or recertification activities.
  • Assess and mature security controls against relevant frameworks and regulatory requirements.
  • Conduct control gap assessments and coordinate remediation plans.
  • Develop and maintain information security policies, standards and procedures.
  • Coordinate audit evidence gathering and validation across multiple business functions.
  • Work directly with external auditors and certification bodies.
  • Monitor and track remediation activities, ensuring timely closure of findings.
  • Support risk assessments and control effectiveness reviews.
  • Provide executive-level reporting on audit readiness, risks and compliance posture.
  • Advise on security governance, assurance and continuous improvement initiatives.


The Information Security Compliance & Assurance Lead will need to have the following skills/experience -

  • Proven experience delivering successful SOC 2 Type II audits.
  • Strong practical experience with ISO 27001 implementation and certification audits.
  • Background in Information Security, Governance, Risk & Compliance (GRC), or Security Assurance.
  • Experience working within a regulated environment, ideally SaaS, FinTech, HealthTech, InsurTech or other technology-led businesses.
  • Strong understanding of information security controls, governance and risk management practices.
  • Experience managing audit engagements and external auditor relationships.
  • Ability to interpret and map controls across multiple frameworks.
  • Excellent stakeholder management and communication skills.
  • Experience driving remediation programmes across technical and business teams.


Desirable Experience

  • Experience within cloud-native environments (AWS, Azure and/or GCP).
  • Familiarity with GDPR, NIST CSF, CIS Controls, PCI DSS or related frameworks.
  • Security or audit certifications such as:
  • ISO 27001 Lead Implementer or Lead Auditor
  • CISSP
  • CISM
  • CRISC
  • CISA


Similar Jobs

Explore other opportunities that match your interests

Senior Identity and Access Management (IAM) Security Engineer (Cloud-Native, AWS)

Cyber Security
1d ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

Lawrence Harvey

United Kingdom
Visa Sponsorship Relocation Remote
Job Type Contract
Experience Level Not Applicable

Alignerr

United Kingdom
Visa Sponsorship Relocation Remote
Job Type Contract
Experience Level Not Applicable

cloud bridge tech recruitment

United Kingdom

Subscribe our newsletter

New Things Will Always Update Regularly