Information Security & Compliance Lead

Avanti Recruitment

Information Security & Compliance Lead

Are you an experienced information security or compliance professional who believes compliance should help a business rather than slow it down?

We’re working with a fast-growing, well-invested B2B SaaS company specialising in business resilience and modern compliance across information security, data privacy and AI governance.

Their global platform is used by more than 65,000 people and helps organisations manage standards and regulations including ISO 27001, ISO 27701, ISO 42001, NIS2 and other increasingly complex governance requirements.

They’re looking for an Information Security & Compliance Lead to take ownership of their internal compliance programme. There’s more to this than maintaining certifications and keeping documentation up to date. The business is at the forefront of modern compliance, and this is an opportunity to put simple, practical and commercially valuable governance into practice.

The Role

You’ll own the company’s compliance posture across ISO 27001, ISO 27701, ISO 42001, Cyber Essentials and emerging standards, using its own SaaS platform to build a best-practice implementation across information security, privacy and AI governance.

The business wants compliance to be light-touch, accessible and easy for people to follow. Your job will be to make governance part of how people work, rather than an extra layer of process, while helping the organisation become stronger, support its customers and create commercial value.

Your responsibilities will include:

  • Owning and continually improving the company’s multi-framework compliance programme.
  • Leading internal and external audit cycles.
  • Maintaining the risk register, Statement of Applicability and supporting compliance documentation.
  • Simplifying internal governance processes and embedding them into everyday ways of working.
  • Becoming one of the platform’s most knowledgeable internal users and feeding practical compliance experience back into the Product team.
  • Working with Customer Success and Professional Services to turn internal best practice into approaches customers can use.
  • Showing customers and prospects what effective modern governance looks like in practice.
  • Advising senior leadership on governance, risk and compliance.
  • Keeping up with emerging standards and regulatory developments.

There’s also scope to become a recognised voice in the industry through customer conversations, conferences, LinkedIn, podcasts, industry reports and other thought-leadership activity. You’ll be representing a business working at the heart of information security, privacy and AI governance.

You don’t need to be an established speaker. They’re looking for someone who enjoys discussing the subject and would like to get involved.

What We’re Looking For

  • Strong practical experience across information security, governance, risk and compliance, with significant hands-on ISO 27001 experience.
  • Experience managing a multi-framework compliance environment, including at least one additional framework or standard such as ISO 27701, ISO 42001, SOC 2, Cyber Essentials, NIS2 or DORA.
  • Experience within SaaS, technology or another relevant product-led environment.
  • A track record of making compliance simpler and more accessible to non-specialists.
  • A pragmatic approach to governance, avoiding unnecessary process and bureaucracy.
  • Confidence working with senior stakeholders and teams outside compliance.
  • An understanding of how good compliance and governance can create wider business and customer value.
  • Working knowledge of the UK and EU regulatory landscape.

AI Governance

Experience with AI governance or ISO 42001 would be a major advantage, although you don’t need to be an ISO 42001 expert.

The business is doing some particularly interesting work in this area and recognises that governing AI can require a different approach from traditional information security. Previous exposure to AI governance, an understanding of those differences or a genuine interest in developing your knowledge would all help you stand out.

The Opportunity

You’ll be running compliance within a SaaS company whose entire proposition is built around helping organisations improve information security, privacy, AI governance and business resilience. Governance isn’t just a supporting function here; it’s central to what the business does.

That gives your experience a wider application. Alongside shaping the internal compliance programme, you can influence how the platform develops, how customers implement and manage governance, and how the business talks about modern compliance. You’ll also help establish what best practice looks like in emerging areas such as AI governance.

For someone who believes compliance should be simple, useful and commercially valuable, rather than complicated for the sake of it, there’s a lot to get involved in.

Additional Information

  • Full-time, permanent position, fully remote within the UK.
  • The role sits within the Product team.
  • 25 days’ holiday plus bank holidays, increasing with service.
  • NEST pension and Perkbox benefits.
  • Development and training support.
  • Company events and opportunities to collaborate with the wider team.

This would suit someone with strong information security and ISO experience who wants to do more than maintain a compliance programme. You’ll have the opportunity to shape how modern governance is done, influence a SaaS product used globally and build your own voice in the future of information security and AI governance.

Apply Now →

Application opens at the source listing. Free for jobseekers.