> Markdown version of [/jobs/ext/3184703-information-security-compliance-lead](https://www.wearedevelopers.com/jobs/ext/3184703-information-security-compliance-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security & Compliance Lead - **Company:** Avanti Recruitment - **Location:** Brighton and Hove, UK (Remote available) - **Experience:** Expert - **Salary:** £65,000.0 - £75,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software as a Service, Cyber Security - **Published:** September 8, 2026 - **Apply:** https://www.reed.co.uk/jobs/information-security-compliance-lead/57322267 ## About the Role * Strong practical experience across information security, governance, risk and compliance * Significant hands-on experience with ISO 27001 * Experience managing a multi-framework compliance environment * Experience with at least one additional framework or standard such as ISO 27701, ISO 42001, SOC 2, Cyber Essentials, NIS2 or DORA * Experience within SaaS, technology or another relevant product-led environment * A track record of making compliance simpler and more accessible to non-specialists * A pragmatic approach to governance and an ability to avoid unnecessary process and bureaucracy * Confidence engaging with senior stakeholders and teams outside compliance * An understanding of how strong compliance and governance can create wider business and customer value * Working knowledge of the UK and EU regulatory landscape AI Governance Experience with AI governance or ISO 42001 would be a major advantage. You don't need to be an ISO 42001 expert, but the business is doing some particularly interesting work in this area and recognises that governing AI can require a different approach from traditional information security. Someone who has already had exposure to AI governance, understands those differences, or is genuinely interested in developing in this area will stand out. ## Description You will own the company's compliance posture across ISO 27001, ISO 27701, ISO 42001, Cyber Essentials and emerging standards, creating a best-practice implementation using the company's own SaaS platform. The approach they take to compliance is important. They want it to be light-touch, accessible and easy for people across the business to follow. Rather than acting as a gatekeeper, you will look at how good governance can make the organisation stronger, support customers and ultimately create commercial value. You will: * Own and continually improve the company's multi-framework compliance programme * Lead internal and external audit cycles * Maintain the risk register, Statement of Applicability and supporting compliance documentation * Simplify internal governance processes and embed them into everyday ways of working * Build a best-practice implementation across information security, privacy and AI governance * Become one of the platform's most knowledgeable internal users * Feed practical compliance experience directly back into the Product team * Work with Customer Success and Professional Services to turn internal best practice into approaches customers can use * Help demonstrate to customers and prospects what effective modern governance looks like * Advise senior leadership on governance, risk and compliance * Stay ahead of emerging standards and regulatory developments There is also an opportunity to develop a genuine voice within the industry. That could include getting involved in customer conversations, conferences, LinkedIn, podcasts, industry reports and other thought-leadership activity, representing a business that works at the heart of information security, privacy and AI governance. You don't need to already be an established industry speaker. What matters is that you're someone who enjoys talking about the subject and wants to get involved., This is an unusual opportunity for an experienced compliance professional. Rather than running compliance within a business where governance is simply a supporting function, you will be doing it inside a SaaS company whose entire proposition is built around helping organisations approach information security, privacy, AI governance and business resilience better. Your experience can directly influence: * How the company runs its own compliance programme * How the SaaS platform develops * How customers implement and manage governance * How the business talks about modern compliance * What best practice looks like across emerging areas such as AI governance If you believe compliance should be simple, useful and commercially valuable, rather than complicated for the sake of it, this could be a brilliant opportunity. ## Related Videos - [Outsmarting the System: What Game Cheaters Can Teach Us About Cyber Security](https://www.wearedevelopers.com/videos/1396-outsmarting-the-system-what-game-cheaters-can-teach-us-about-cyber-security) - [Rethinking Recruiting: What you didn’t know about Responsible AI](https://www.wearedevelopers.com/videos/1090-rethinking-recruiting-what-you-didn-t-know-about-responsible-ai) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Edit Your Future: Queerverse Radical AI](https://www.wearedevelopers.com/videos/909-edit-your-future-queerverse-radical-ai) - [Responsible AI @ Microsoft - Governance, Standards, Learnings](https://www.wearedevelopers.com/videos/1544-responsible-ai-microsoft-governance-standards-learnings) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Should AI be Regulated? The Arguments For and Against](https://www.wearedevelopers.com/magazine/271-should-ai-be-regulated-the-arguments-for-and-against) - [Panel Discussion: Responsible AI in Practice - Real-World Examples and Challenges](https://www.wearedevelopers.com/magazine/488-panel-discussion-responsible-ai-in-practice-real-world-examples-and-challenges) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)