
Security & Compliance Specialist
- London
- Permanent
- Full-time
- You will manage and mature our existing Security & Compliance program. This includes refining policies and procedures, tracking our compliance posture, and developing security and compliance awareness training for employees.
- You will facilitate regular risk review sessions with technical and business teams to identify and assess potential risks. You will be responsible for defining, documenting, and monitoring the effectiveness of our IT controls.
- You will own our third-party vendor risk assessment process from start to finish, evaluating the security and compliance posture of new and existing vendors to ensure they meet our standards.
- You will act as a key point of contact for external audits and help the business prepare for assessments against frameworks like ISO 27001 and SOC 2.
- You will help manage our compliance with data privacy regulations, particularly GDPR, by conducting data protection impact assessments and advising the business on data handling best practices.
- You will work closely with our Engineering, Product, Legal, and business teams to provide practical compliance advice and ensure requirements are integrated into our processes and systems.
- Stay current with evolving regulations and best practices in areas like AI. You will help shape the company’s approach to AI governance by identifying risks and establishing responsible usage policies.
- Proven experience in a Security Compliance, risk, or technical role (e.g. IT audit, system administration, security operations).
- A strong understanding of data protection principles and regulations, especially GDPR.
- Experience conducting IT risk assessments and evaluating the design and effectiveness of IT controls.
- Familiarity with the vendor due diligence and third-party risk management lifecycle.
- Excellent communication skills, with the ability to explain complex technical and compliance concepts to non-technical stakeholders.
- A collaborative, problem-solving mindset with high attention to detail.
- Familiarity with security frameworks like ISO 27001/27701. SOC 2 is a plus but not required.
- 25 Days Annual leave, increasing to 26 days after 12 months in the business
- Enhanced Company Pension (Matched up to 5% & Salary Sacrifice)
- Healthcare Cashplan with Medicash
- Private Healthcare
- Life Insurance with AIG
- Happl, our benefit platform which provides access to pre-negotiated discounts on a wide variety of services including entertainment, food, and fitness.
- Stock / Equity