Vacancy Name
Information Security & Compliance Lead
Created Date
7/31/2026 4:52 PM
Description
The Information Security & Compliance Lead will lead the practical security and compliance work required for Achilles to achieve and maintain a SOC 2 Type I and Type II attestation. The role will translate the applicable Trust Services Criteria into effective, sustainable controls; close readiness gaps; coordinate evidence and audit activity; and strengthen day-to-day security engineering across Achilles' systems, products and suppliers. Working across IT, Engineering, Product, Legal, People and business teams, the postholder will ensure that controls are well designed, consistently operated and demonstrably effective without creating unnecessary friction for the business.
Key Responsibilities
Own and maintain the SOC 2 delivery roadmap, initially supporting Type I readiness and progressing to Type II operating effectiveness and ongoing annual assurance.
Define and maintain the in-scope systems, services, data flows, locations, vendors and Trust Services Criteria in partnership with business and technical stakeholders.
Perform readiness and control-gap assessments; translate findings into prioritised remediation plans with clear owners, milestones, risks and acceptance criteria.
Design and document proportionate controls, control narratives, policies, procedures and evidence requirements that align with how Achilles operates.
Coordinate readiness assessors and the independent auditor, manage requests and walkthroughs, validate evidence quality, and drive timely resolution of exceptions and findings.
Establish a sustainable control calendar and evidence repository so control performance is traceable, repeatable and audit-ready throughout the year.
Qualifications
Degree or equivalent practical experience in cyber security, information technology, computer science or a related discipline.
A relevant professional certification such as CISA, CISSP, CCSP, ISO 27001 Lead Implementer/Lead Auditor, CRISC or Security+ is desirable; equivalent demonstrable experience will be considered.
SOC 2 practitioner, audit or control-assurance training is desirable.
Evidence of ongoing professional development in security engineering, assurance, cloud security or risk management.
Person Specification
Delivery focus: plans and drives complex, cross-functional work to clear outcomes, managing dependencies and escalating blockers early.
Influence and collaboration: builds credibility with technical teams, control owners, senior leaders and external auditors; explains requirements without unnecessary jargon.
Analytical judgement: evaluates risk and evidence objectively, distinguishes material weaknesses from minor issues, and proposes proportionate solutions.
Attention to detail: maintains accurate control documentation and evidence while retaining a clear view of programme priorities and business impact.
Ownership and integrity: handles sensitive information responsibly, challenges constructively and follows issues through to sustainable resolution.
Continuous improvement: simplifies, standardises and automates control activity where this improves assurance and operational efficiency.
We welcome applications from people of all backgrounds. We foster a diverse and inclusive culture that empowers staff to grow and maximise their skills in an environment free from all forms of inequality.
Our benefits packages vary from country to country dependant but we aim to provide flexible and competitive benefits that support individual financial, physical health and mental wellbeing. Some examples include:
-
Pension or retirement benefits
- Health insurance cover
-
Paid Annual Leave / PTO
-
Charity / Volunteering Day
-
Family friendly policies
-
Flexible working practices (dependent upon role and location)
-
Health & Wellbeing initiatives
When you apply for a role with Achilles, we collect and process your personal data as described in out recruitment privacy notice