SOC 2 Security & Compliance Lead

Achilles Information Limited

East Hagbourne

Hybrid

GBP 85,000 - 120,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Achilles Information Limited is seeking an experienced Information Security & Compliance Lead to drive its SOC 2 assurance journey and strengthen security and compliance across the business. This highly visible role combines governance, risk and compliance with hands-on security leadership to achieve SOC 2 Type I/II attestations while embedding scalable controls for global growth.

You'll work with Technology, Product, Legal, People and Operations to make security a natural part of operations,

Qualifications

  • Proven experience leading SOC 2 Type I & II programmes.
  • Strong knowledge of SOC 2 Trust Services Criteria and evidence management.
  • Hands-on security controls in cloud-first or SaaS environments.
  • Familiarity with ISO 27001, NIST CSF and CIS Controls.
  • Experience coordinating with external auditors and internal control owners.
  • Professional certifications (CISSP, CISA, CRISC, CCSP, ISO 27001 Lead Auditor/Implementer, Security+) are advantageous.

Responsibilities

  • Lead the SOC 2 roadmap from readiness to Type I, Type II and ongoing assurance.
  • Design, implement and improve controls aligned to SOC 2 and industry frameworks.
  • Conduct readiness assessments, identify control gaps, and drive remediation across the business.
  • Coordinate with internal stakeholders, external auditors and assessors to ensure audit success.
  • Establish and manage a sustainable controls and evidence programme.
  • Strengthen security operations across IAM, cloud security, endpoint protection, vulnerability management, monitoring and incident response.
  • Partner with Engineering and Product teams to embed security into architecture and development.
  • Manage third-party security assessments and supplier assurance activities.
  • Support business continuity, disaster recovery and incident management exercises.
  • Develop security metrics and provide reporting on risk, compliance and remediation progress.
  • Deliver security awareness guidance and support customer due diligence and security assurance.
  • Champion automation, standardisation and risk management.

Skills

SOC 2 leadership
Audit readiness & evidence management
Cloud security (SaaS)
Stakeholder communication
Risk management
Analytical thinking
Auditor coordination
Security metrics & reporting
Automation & process improvement
Security governance

Tools

CISSP
CISA
CRISC
CCSP
ISO 27001 Lead Auditor/Implementer

Job description

Achilles Information Limited is seeking an experienced Information Security & Compliance Lead to drive its SOC 2 assurance journey and strengthen security and compliance across the business. This highly visible role combines governance, risk and compliance with hands-on security leadership to achieve SOC 2 Type I/II attestations while embedding scalable controls for global growth.

You'll work with Technology, Product, Legal, People and Operations to make security a natural part of operations,

Get your free, confidential resume review.
or drag and drop your file here.