> Markdown version of [/jobs/ext/3100383-information-security-lead](https://www.wearedevelopers.com/jobs/ext/3100383-information-security-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Lead - **Company:** Weekpermanentat Dexory - **Location:** Wallingford, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Encodings, Cyber Security, Phishing, Software Vulnerability Management - **Published:** September 27, 2026 - **Apply:** https://www.apply4u.co.uk/jobs/information-security-lead/48815088 ## About the Role Dexory's incident response and vulnerability management processesMonitor the threat landscape for risks relevant to an autonomous robotics and warehouse intelligence businessDevelop and run security awareness training and phishing simulation programmes across the businessExperience in an information security, GRC, or compliance role, ideally within a B2B SaaS or technology businessHands-on experience with ISO 27001 as an implementer or internal auditor; genuine ownership, not just process participationSolid working knowledge of SOC 1 and SOC 2 frameworks (AICPA Trust Services Criteria)Familiarity with cloud security principles, particularly AWSNice to Have Certs (ISO 27001 Lead Implementer, CISM, CISA, CISSP, or CompTIA Security+)Experience with GRC/compliance platforms such as Thoropass, Vanta, or Drata (nice to have)Knowledge of OT, IoT, or robotics security considerations - a genuine differentiator given what we buildBenefitsStarting from the interview process and ## Description Job DescriptionInformation Security Lead / ISO27001 / SOC / GRC /Location: Wallingford - Oxfordshire (Hybrid) onsite circa 3 days minimum per weekPermanentAt Dexory, we are transforming the warehousing and logistics industry through data intelligence.We're currently recruiting for an Information Security Lead to own and drive our compliance programmes (ISO 27001, SOC 1 Type 2, SOC 2 Type 2), act as the primary responder to customer security due diligence, and build the systems and knowledge base that allow Dexory to scale securely without friction.You'll work closely with the Head of IT & Security, embedding good security practice across engineering, product, and operations.Offices based in Wallingford, Oxford and looking for someone who can do 3 days minimum on site ideally more.Any experience within robotics or start up / scale up environments highly desirable.Please apply for more information.Responsibilities / SkillsOwn the day-to-day execution of Dexory's ISO 27001, SOC 1 Type 2, and SOC 2 Type 2 programmes, including evidence collection, control testing, policy maintenance, and auditor liaisonMaintain our GRC platform - keeping controls, evidence, and risk registers current and audit-ready at all timesDrive continuous improvement of policies, procedures, and controls across the businessServe as the primary point of contact for all inbound customer security questionnaires (SIG, CAIQ, VSAQ, bespoke RFP security sections)Build, own, and continuously improve a centralised security knowledge base to enable faster, consistent, and accurate responses at scalePartner closely with Sales and Customer Success to unblock deals where security is a gate, providing timely responses and where needed, direct engagement with customer security teamsSupport the development and maintenance of Dexory's information security policies and risk management frameworkConduct vendor and third-party security assessments as part of the procurement and onboarding processContribute to ## Related Videos - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [A Brief History of Data Storage](https://www.wearedevelopers.com/videos/974-a-brief-history-of-data-storage) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [JSON and Beyond](https://www.wearedevelopers.com/videos/968-json-and-beyond) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)