Information Security & Compliance Lead
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
The Information Security & Compliance Lead will lead the practical security and compliance work required for Achilles to achieve and maintain a SOC 2 Type I and Type II attestation. The role will translate the applicable Trust Services Criteria into effective, sustainable controls; close readiness gaps; coordinate evidence and audit activity; and strengthen day-to-day security engineering across Achilles’ systems, products and suppliers. Working across IT, Engineering, Product, Legal, People and business teams, the postholder will ensure that controls are well designed, consistently operated and demonstrably effective without creating unnecessary friction for the business., * Own and maintain the SOC 2 delivery roadmap, initially supporting Type I readiness and progressing to Type II operating effectiveness and ongoing annual assurance.
- Define and maintain the in-scope systems, services, data flows, locations, vendors and Trust Services Criteria in partnership with business and technical stakeholders.
- Perform readiness and control-gap assessments; translate findings into prioritised remediation plans with clear owners, milestones, risks and acceptance criteria.
- Design and document proportionate controls, control narratives, policies, procedures and evidence requirements that align with how Achilles operates.
- Coordinate readiness assessors and the independent auditor, manage requests and walkthroughs, validate evidence quality, and drive timely resolution of exceptions and findings.
- Establish a sustainable control calendar and evidence repository so control performance is traceable, repeatable and audit-ready throughout the year.
Requirements
- Degree or equivalent practical experience in cyber security, information technology, computer science or a related discipline.
- A relevant professional certification such as CISA, CISSP, CCSP, ISO 27001 Lead Implementer/Lead Auditor, CRISC or Security+ is desirable; equivalent demonstrable experience will be considered.
- SOC 2 practitioner, audit or control-assurance training is desirable.
- Evidence of ongoing professional development in security engineering, assurance, cloud security or risk management.
Person Specification
- Delivery focus: plans and drives complex, cross-functional work to clear outcomes, managing dependencies and escalating blockers early.
- Influence and collaboration: builds credibility with technical teams, control owners, senior leaders and external auditors; explains requirements without unnecessary jargon.
- Analytical judgement: evaluates risk and evidence objectively, distinguishes material weaknesses from minor issues, and proposes proportionate solutions.
- Attention to detail: maintains accurate control documentation and evidence while retaining a clear view of programme priorities and business impact.
- Ownership and integrity: handles sensitive information responsibly, challenges constructively and follows issues through to sustainable resolution.
- Continuous improvement: simplifies, standardises and automates control activity where this improves assurance and operational efficiency.
We welcome applications from people of all backgrounds. We foster a diverse and inclusive culture that empowers staff to grow and maximise their skills in an environment free from all forms of inequality.
Benefits & conditions
Pulled from the full job description Annual leave Company pension Paid volunteer time, Our benefits packages vary from country to country dependant but we aim to provide flexible and competitive benefits that support individual financial, physical health and mental wellbeing. Some examples include:
- Pension or retirement benefits
- Health insurance cover
- Paid Annual Leave / PTO
- Charity / Volunteering Day
- Family friendly policies
- Flexible working practices (dependent upon role and location)
- Health & Wellbeing initiatives
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
The Most Popular IT Jobs on the Market
IT Salaries in UK
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.