Compliance Officer in London

Compliance Officer in London

London Full-Time 45000 - 45000 £ / year (est.) Working from home possible
EnergySys Limited

At a Glance

  • Tasks: Lead compliance initiatives and ensure regulatory standards are met in a dynamic environment.
  • Company: Join EnergySys, a trusted platform in the energy sector with over 20 years of experience.
  • Benefits: Enjoy unlimited holiday, private medical insurance, and enhanced parental leave.
  • Other info: Work closely with senior leadership and enjoy a flexible, high-trust culture.
  • Why this job: Take ownership of the compliance programme and make a real impact on the company's growth.
  • Qualifications: Experience with SOC 2 and ISO 27001, strong communication skills, and cloud literacy.

The predicted salary is between 45000 - 45000 £ per year.

Location: UK remote - fully remote

Hours: 37.5 hours

Salary: Up to £45,000 per annum

About EnergySys: EnergySys is a platform used by software builders and consultants who serve oil and gas companies. Our partners build applications on top of us, and those applications run some of the most critical data and reporting workflows in the energy sector. We’ve been around for over 20 years, which means we’re not a startup bet. We’re an established business with a real product, real customers, and a PE‑backed growth target.

Our culture: EnergySys is shifting towards a high‑performing, high‑trust environment based on freedom and responsibility. That means we expect our people to take ownership, use their judgement, and care deeply about their impact. In return, we give them the space and trust to do the job the way they believe is best. This role is perfect for someone who wants to lead and build, not just follow a playbook.

Why this role exists: As the business scales, the need for structured governance, process integrity, and accountability across day‑to‑day operations has become a strategic priority. This role exists to own that accountability. The postholder will serve as the operational backbone of the company—ensuring that internal processes are documented, consistently applied, and aligned with applicable regulatory requirements. Working closely with the CEO and leadership team, they will maintain clear ownership of cross‑functional projects, people‑related processes, and compliance‑sensitive workflows, ensuring that nothing falls through the gaps as the business grows.

What you’ll be responsible for:

  • Audit & Certification: You’ll own the ongoing SOC 2 Type II and ISO 27001:2022 audit lifecycle for an already‑certified organisation: surveillance and recertification audit planning, evidence readiness, auditor liaison, and remediation tracking. You’ll maintain the ISMS (including the Statement of Applicability) and handle customer security assessments and certification enquiries.
  • Drata: Primary administrator. You’ll own framework configuration and control mapping, maintain integration health across AWS, Microsoft Entra ID, Intune, GitHub, Rippling, and connected systems. Automated evidence collection sits with individual control owners; you monitor for gaps or failures and keep owners accountable, keeping Drata and the ISMS manual consistent.
  • Governance & Risk: Chair the Governance, Risk and Compliance Committee, owning the agenda and policy review cycle. Maintain the company risk register in Drata and report audit status, risk exposure, and control effectiveness to leadership and the board.
  • Policy & Documentation: Own the policy register in Drata, ensuring policies stay current and accurate, updating them in response to regulatory changes or operational changes, and advising leadership on required updates.
  • Vendor & Third‑Party Risk: Conduct and support structured vendor risk assessments, review SOC 2 reports, ISO certificates, and DPAs, maintain the vendor register, and ensure periodic reviews are completed on schedule.
  • Infrastructure & Evidence: Navigate AWS, Microsoft Entra ID, Intune, and GitHub to pull evidence with little to no developer assistance. Use AI tools to accelerate evidence gathering, policy drafting, and control assessments. Support access management and joiner/mover/leaver processes from a governance perspective.
  • Training, Culture & Regulatory: Administer cybersecurity awareness training via Rippling LMS and track completion against framework requirements. Support compliance across EnergySys’s three legal entities (UK, Australia, US), including GDPR and relevant data protection obligations. Embed a culture where compliance is practical, proportionate, and understood across the organisation.

What we’re looking for:

  • Hands‑on SOC 2 and/or ISO 27001 experience: evidence management, direct auditor engagement.
  • GRC platform experience (Drata, Vanta, or similar).
  • Cloud literacy: comfortable navigating AWS and Microsoft Entra ID, or actively willing to learn.
  • Strong written communication: policies, risk registers, committee papers & minutes.
  • Self‑directed and ownership‑minded, able to run a compliance programme independently.
  • AI‑native: you use LLMs and AI tools as genuine productivity accelerators.

In short: We need someone who maintains, operates, and owns; not someone who reports findings to others. You will be the sole compliance resource, working closely with the Head of Operations and engineering leadership. EnergySys is lean and fast‑moving; pragmatism and proportionality are valued over process for process’s sake. Drata is your tool, but the thinking, the judgement, and the ownership are yours.

What We Offer here @ EnergySys:

  • Unlimited holiday — flexibility to take the time you need; we trust you to manage your time and deliver.
  • Private medical insurance.
  • EnergySys matches your contributions up to 8% of salary.
  • Enhanced parental leave — 3 months full pay maternity, 4 weeks full pay paternity.
  • ISO 27001 Lead Implementer certification funded.
  • Direct access to senior leadership — you will work closely with the Head of Operations and CEO with genuine influence.
  • Real ownership — the compliance programme is yours to run; we have the foundations and the tools in place, but we need someone who takes initiative, sets the direction, and moves without waiting to be told.

How to Apply: Please send your CV alongside a brief cover note, no more than one page, addressing the following two questions:

  • Describe a time you owned and improved an existing compliance programme rather than building one from scratch. What did you change, what resistance did you encounter, and how did you bring people with you?
  • Walk us through how you’ve used a GRC platform (Drata, Vanta, or similar) to maintain audit readiness between certification cycles, including a time something slipped (a control owner missed evidence, an integration broke, a review lapsed) and how you caught and resolved it.

We will read your CV for the technical baseline. The cover note is how we understand how you think and how you work with people. Keep it concise, quality over length. Applications without a cover note will not be progressed.

Compliance Officer in London employer: EnergySys Limited

EnergySys is an exceptional employer that fosters a culture of innovation and collaboration, making it an ideal place for Compliance & Governance professionals to thrive. With a focus on employee growth, we offer comprehensive training and development opportunities, alongside the flexibility of remote work in the UK, allowing you to balance your professional and personal life effectively. Join us to be part of a forward-thinking team that values your expertise and empowers you to make a meaningful impact across our global operations.

EnergySys Limited

Contact Details:

EnergySys Limited Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Compliance Officer in London

Join Compliance Communities

Get involved in compliance and risk communities — both online and offline. Look for forums, LinkedIn groups, or even local meetups where compliance pros hang out. You never know who might drop a job opportunity your way!

Attend Industry Conferences

Keep an eye out for compliance and risk management conferences and workshops in your area. These events are a goldmine for networking, and they often have job boards or recruiters on-site looking for new talent. Plus, it’s a chance to learn what's trending in the field.

Leverage Your University Career Services

If you’ve recently graduated or are still studying, head over to your university's career services. Many companies, including those in compliance, actively recruit fresh talent through these services, so make sure you tap into that resource.

Showcase Your Knowledge Online

Start writing articles or blog posts about compliance topics that interest you. Share them on platforms like LinkedIn to demonstrate your knowledge and passion. This not only builds your presence in the field but can also catch the attention of companies like EnergySys Limited looking for candidates who are engaged and informed.

We think you need these skills to ace Compliance Officer in London

SOC 2 Type II experience
ISO 27001:2022 audit lifecycle management
GRC platform experience (Drata, Vanta, or similar)
Cloud literacy (AWS, Microsoft Entra ID)
Strong written communication
Self-directed and ownership-minded
AI tool utilisation for productivity

Some tips for your application 🫡

Show Your Understanding of Compliance:In the compliance-risk field, it's super important to showcase your understanding of regulations and risk management frameworks. Highlight any relevant coursework, certifications (like ICA or AML), or even projects that demonstrate your knowledge and commitment to this area. We want to see how you can navigate this complex landscape!

Quantify Your Achievements:When detailing your experience, try to quantify your achievements. For example, if you've previously worked on a project that improved compliance metrics or reduced risk exposure, give us the numbers! This data-driven approach really stands out to hiring managers in compliance-risk roles.

Tailor Your CV to Reflect Relevant Skills:Make sure your CV highlights skills that are particularly relevant to compliance, like attention to detail, analytical thinking, and report writing. Ensure these are easy to spot – consider using bullet points to break down your responsibilities and achievements for maximum impact!

Craft a Motivating Cover Letter:In your cover letter, let us know why you’re excited about the compliance-risk role at EnergySys Limited. Share what motivates you about compliance, and how you believe you can contribute to our mission. This is your chance to showcase not only your skills but also your passion for this important field!

How to prepare for a job interview at EnergySys Limited

Master the Regulations

Brush up on key compliance regulations relevant to the industry you're applying to. Familiarising yourself with specific laws and frameworks used in your field will give you an edge during technical questions. Show that you’re not just aware of them but can also apply them—think real-life scenarios!

Show Your Analytical Skills

Compliance roles really focus on analytical skills, so be prepared for case studies or situational questions during the interview. We've got to demonstrate how we approach risk assessments or compliance audits, possibly drawing on examples from past experiences or university projects. Bring some thoughtful case scenarios to discuss!

Know Your Tools

Get comfortable with commonly used compliance software and tools. Familiarity with platforms like RSA or MetricStream can really impress during your interview, as it shows you're ready to hit the ground running. If you’ve had any experience with them, make sure to highlight that!

Align with Company Culture

Since it's a full-time position, show your long-term commitment and interest in the company’s mission and values. Dive into how your ethics and professional philosophy align with EnergySys Limited’s stance on compliance. A shared vision can really resonate with interviewers looking for fit as much as skill!