Information Security & Compliance Lead
Are you an experienced information security or compliance professional who believes compliance should enable a business rather than slow it down?
We are working with a fast-growing, well-invested B2B SaaS company specialising in business resilience and modern compliance across information security, data privacy and AI governance.
Their global platform is used by more than 65,000 people and helps organisations manage standards and regulations including ISO 27001, ISO 27701, ISO 42001, NIS2 and other increasingly complex governance requirements.
They are now looking for an Information Security & Compliance Lead to take ownership of their own internal compliance programme.
This isn't a traditional compliance role where the focus is simply on maintaining certifications, policing processes and ticking boxes.
You will be joining a company at the forefront of modern compliance, with the opportunity to show what simple, practical and commercially valuable governance can actually look like.
The Role
You will own the company's compliance posture across ISO 27001, ISO 27701, ISO 42001, Cyber Essentials and emerging standards, creating a best-practice implementation using the company's own SaaS platform.
The approach they take to compliance is important.
They want it to be light-touch, accessible and easy for people across the business to follow. Rather than acting as a gatekeeper, you will look at how good governance can make the organisation stronger, support customers and ultimately create commercial value.
You will:
- Own and continually improve the company's multi-framework compliance programme
- Lead internal and external audit cycles
- Maintain the risk register, Statement of Applicability and supporting compliance documentation
- Simplify internal governance processes and embed them into everyday ways of working
- Build a best-practice implementation across information security, privacy and AI governance
- Become one of the platform's most knowledgeable internal users
- Feed practical compliance experience directly back into the Product team
- Work with Customer Success and Professional Services to turn internal best practice into approaches customers can use
- Help demonstrate to customers and prospects what effective modern governance looks like
- Advise senior leadership on governance, risk and compliance
- Stay ahead of emerging standards and regulatory developments
There is also an opportunity to develop a genuine voice within the industry.
That could include getting involved in customer conversations, conferences, LinkedIn, podcasts, industry reports and other thought-leadership activity, representing a business that works at the heart of information security, privacy and AI governance.
You don't need to already be an established industry speaker. What matters is that you're someone who enjoys talking about the subject and wants to get involved.
What We're Looking For
- Strong practical experience across information security, governance, risk and compliance
- Significant hands-on experience with ISO 27001
- Experience managing a multi-framework compliance environment
- Experience with at least one additional framework or standard such as ISO 27701, ISO 42001, SOC 2, Cyber Essentials, NIS2 or DORA
- Experience within SaaS, technology or another relevant product-led environment
- A track record of making compliance simpler and more accessible to non-specialists
- A pragmatic approach to governance and an ability to avoid unnecessary process and bureaucracy
- Confidence engaging with senior stakeholders and teams outside compliance
- An understanding of how strong compliance and governance can create wider business and customer value
- Working knowledge of the UK and EU regulatory landscape
AI Governance
Experience with AI governance or ISO 42001 would be a major advantage.
You don't need to be an ISO 42001 expert, but the business is doing some particularly interesting work in this area and recognises that governing AI can require a different approach from traditional information security.
Someone who has already had exposure to AI governance, understands those differences, or is genuinely interested in developing in this area will stand out.
The Opportunity
This is an unusual opportunity for an experienced compliance professional.
Rather than running compliance within a business where governance is simply a supporting function, you will be doing it inside a SaaS company whose entire proposition is built around helping organisations approach information security, privacy, AI governance and business resilience better.
Your experience can directly influence:
- How the company runs its own compliance programme
- How the SaaS platform develops
- How customers implement and manage governance
- How the business talks about modern compliance
- What best practice looks like across emerging areas such as AI governance
If you believe compliance should be simple, useful and commercially valuable, rather than complicated for the sake of it, this could be a brilliant opportunity.
Additional Information
- Full-time, permanent position
- Fully remote within the UK
- Role sits within the Product team
- 25 days' holiday plus bank holidays, increasing with service
- NEST pension
- Perkbox benefits
- Development and training support
- Company events and opportunities to collaborate with the wider team
This role is ideal for someone with strong information security and ISO experience who wants to do more than maintain a compliance programme.
You'll have the opportunity to shape how modern governance is done, influence a SaaS product used globally and build a genuine voice in the future of information security and AI governance.