Information Security & Compliance Lead

Achilles
Abingdon, UK
about 1 month ago
Apply on uk.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Cloud Computing Security Cyber Security Data Streaming Information Technology

Job description

The Information Security & Compliance Lead will lead the practical security and compliance work required for Achilles to achieve and maintain a SOC 2 Type I and Type II attestation. The role will translate the applicable Trust Services Criteria into effective, sustainable controls; close readiness gaps; coordinate evidence and audit activity; and strengthen day-to-day security engineering across Achilles’ systems, products and suppliers. Working across IT, Engineering, Product, Legal, People and business teams, the postholder will ensure that controls are well designed, consistently operated and demonstrably effective without creating unnecessary friction for the business., * Own and maintain the SOC 2 delivery roadmap, initially supporting Type I readiness and progressing to Type II operating effectiveness and ongoing annual assurance.

  • Define and maintain the in-scope systems, services, data flows, locations, vendors and Trust Services Criteria in partnership with business and technical stakeholders.
  • Perform readiness and control-gap assessments; translate findings into prioritised remediation plans with clear owners, milestones, risks and acceptance criteria.
  • Design and document proportionate controls, control narratives, policies, procedures and evidence requirements that align with how Achilles operates.
  • Coordinate readiness assessors and the independent auditor, manage requests and walkthroughs, validate evidence quality, and drive timely resolution of exceptions and findings.
  • Establish a sustainable control calendar and evidence repository so control performance is traceable, repeatable and audit-ready throughout the year.

Requirements

  • Degree or equivalent practical experience in cyber security, information technology, computer science or a related discipline.
  • A relevant professional certification such as CISA, CISSP, CCSP, ISO 27001 Lead Implementer/Lead Auditor, CRISC or Security+ is desirable; equivalent demonstrable experience will be considered.
  • SOC 2 practitioner, audit or control-assurance training is desirable.
  • Evidence of ongoing professional development in security engineering, assurance, cloud security or risk management.

Person Specification

  • Delivery focus: plans and drives complex, cross-functional work to clear outcomes, managing dependencies and escalating blockers early.
  • Influence and collaboration: builds credibility with technical teams, control owners, senior leaders and external auditors; explains requirements without unnecessary jargon.
  • Analytical judgement: evaluates risk and evidence objectively, distinguishes material weaknesses from minor issues, and proposes proportionate solutions.
  • Attention to detail: maintains accurate control documentation and evidence while retaining a clear view of programme priorities and business impact.
  • Ownership and integrity: handles sensitive information responsibly, challenges constructively and follows issues through to sustainable resolution.
  • Continuous improvement: simplifies, standardises and automates control activity where this improves assurance and operational efficiency.

We welcome applications from people of all backgrounds. We foster a diverse and inclusive culture that empowers staff to grow and maximise their skills in an environment free from all forms of inequality.

Benefits & conditions

Pulled from the full job description Annual leave Company pension Paid volunteer time, Our benefits packages vary from country to country dependant but we aim to provide flexible and competitive benefits that support individual financial, physical health and mental wellbeing. Some examples include:

  • Pension or retirement benefits
  • Health insurance cover
  • Paid Annual Leave / PTO
  • Charity / Volunteering Day
  • Family friendly policies
  • Flexible working practices (dependent upon role and location)
  • Health & Wellbeing initiatives

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on uk.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:50 min

Lowering pipeline latency with data streaming

Nathaniel Okenwa Nathaniel Okenwa · World Congress 2024

42 sec

Energy forecasts and resource demands of information technology

Marjolein Pordon · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:46 min

Missing equipment retrieval processes for departing employees

Jasmin Azemović Jasmin Azemović · World Congress 2026 Europe

2:13 min

Modernizing legacy applications for real-time streaming data consumption

Farooq Sheikh Farooq Sheikh +3 · World Congress 2025

Videos

See all

Related articles

See all