> Markdown version of [/jobs/ext/2307816-information-security-compliance-lead](https://www.wearedevelopers.com/jobs/ext/2307816-information-security-compliance-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security & Compliance Lead - **Company:** Achilles - **Location:** East Hagbourne, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software as a Service, Cloud Computing Security, Cyber Security, Disaster Recovery, Identity and Access Management, Software Vulnerability Management, CIS Benchmarks - **Published:** August 30, 2026 - **Apply:** https://www.collegerecruiter.com/job/2815106966-information-security--compliance-lead ## About the Role * Proven experience leading or significantly contributing to successful SOC 2 Type I and Type II programmes. * Strong understanding of SOC 2 Trust Services Criteria, control design, audit preparation and evidence management. * Hands-on experience implementing and operating security controls within cloud-first or SaaS environments. * Knowledge of security frameworks such as ISO 27001, NIST Cybersecurity Framework and CIS Controls. * Experience with identity and access management, vulnerability management, incident response, secure change management and third-party risk management. * Ability to communicate complex security concepts clearly to both technical and non-technical stakeholders. * Strong analytical and problem-solving skills, with the ability to balance risk management and business objectives. * Experience working with external auditors, assessors and multiple internal control owners. * Professional certifications such as CISSP, CISA, CRISC, CCSP, ISO 27001 Lead Auditor/Implementer or Security+ are advantageous. * Experience working across international or distributed teams would be beneficial. ## Description Working closely with teams across Technology, Product, Legal, People and Operations, you'll ensure security and compliance become a natural part of how we operate., * Lead the delivery of our SOC 2 roadmap, from readiness through to Type I, Type II and ongoing annual assurance. * Design, implement and improve security controls aligned to SOC 2 Trust Services Criteria and broader industry frameworks. * Conduct readiness assessments, identify control gaps, and drive remediation activities across the business. * Coordinate internal stakeholders, external auditors and assessors to ensure successful audit outcomes. * Establish and manage a sustainable controls and evidence programme that keeps Achilles audit-ready all year round. * Strengthen security operations across identity and access management, cloud security, endpoint protection, vulnerability management, monitoring and incident response. * Partner with Engineering and Product teams to embed security into architecture, development and operational processes. * Manage third-party security assessments and supplier assurance activities. * Support business continuity, disaster recovery and incident management exercises. * Develop meaningful security metrics and provide clear reporting on risk, compliance and remediation progress. * Deliver security awareness guidance and support customer due diligence and security assurance activities. * Champion continuous improvement through automation, standardisation and pragmatic risk management. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Convincing Product teams to Adopt Gitops in a Large Org](https://www.wearedevelopers.com/videos/1936-convincing-product-teams-to-adopt-gitops-in-a-large-org) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)