Назад
Company hidden
54 минуты назад

Information Security Lead

Формат работы
hybrid
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Information Security Lead (ISO 27001/SOC/GRC): Owning compliance programmes, customer security due diligence, and security governance for warehouse intelligence and autonomous robotics solutions with an accent on ISO 27001, SOC 1/2, GRC, and cloud security. Focus on maintaining audit-ready controls and evidence, building scalable security knowledge systems, assessing third-party risks, and supporting incident response and vulnerability management.

Location: Wallingford, Oxfordshire, UK; hybrid with a minimum of 3 onsite days per week

Company

hirify.global develops data intelligence solutions that transform warehousing and logistics through autonomous robotics and warehouse intelligence.

What you will do

  • Own the day-to-day execution of the ISO 27001, SOC 1 Type 2, and SOC 2 Type 2 compliance programmes, including evidence collection, control testing, policy maintenance, and auditor liaison.
  • Maintain the GRC platform, controls, evidence, risk registers, policies, and procedures in an audit-ready state.
  • Respond to customer security questionnaires, including SIG, CAIQ, VSAQ, and bespoke RFP security sections, partnering with Sales and Customer Success to unblock deals.
  • Build and improve a centralised security knowledge base for consistent and efficient customer responses.
  • Conduct vendor and third-party security assessments and contribute to the information security risk management framework.
  • Support incident response, vulnerability management, security awareness training, phishing simulations, and threat monitoring for the robotics and warehouse intelligence business.

Requirements

  • Experience in information security, GRC, or compliance, ideally in a B2B SaaS or technology business.
  • Hands-on experience implementing or internally auditing ISO 27001 with genuine ownership of the programme.
  • Solid working knowledge of SOC 1 and SOC 2 frameworks and the AICPA Trust Services Criteria.
  • Familiarity with cloud security principles, particularly AWS.
  • Ability to work onsite in Wallingford for at least 3 days per week.
  • Knowledge of OT, IoT, or robotics security considerations is valuable for the role.

Nice to have

  • ISO 27001 Lead Implementer, CISM, CISA, CISSP, or CompTIA Security+ certification.
  • Experience with Thoropass, Vanta, Drata, or similar GRC and compliance platforms.
  • Experience in robotics or startup and scale-up environments.

Culture & Benefits

  • Operating principles focused on performance, impact, commitment, and shared success.
  • Private healthcare through Bupa with a 24/7 medical helpline.
  • Life insurance, income protection, pension contributions, and an Employee Assistance Programme.
  • 25 days of annual leave plus bank holidays.
  • Full onsite meals in Wallingford, snacks, and team events.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →