Information Security and Compliance Engineer in London
Information Security and Compliance Engineer

Information Security and Compliance Engineer in London

London Full-Time 36000 - 60000 £ / year (est.) No home office possible
E

At a Glance

  • Tasks: Own information security and compliance across innovative robotics products and cloud infrastructure.
  • Company: Join Engineered Arts, the leader in humanoid robotics with a fun and inclusive culture.
  • Benefits: Remote work flexibility, competitive salary, and opportunities for professional growth.
  • Why this job: Make a real impact on cutting-edge technology while ensuring security and compliance.
  • Qualifications: Experience in information security, compliance, and hands-on technical skills required.
  • Other info: Be part of a dynamic team pushing the boundaries of robotics innovation.

The predicted salary is between 36000 - 60000 £ per year.

Engineered Arts is seeking an Information Security and Compliance Engineer to own the technical and operational execution of information security and cybersecurity compliance across products, cloud infrastructure, internal systems, and Robot-as-a-Service (RaaS) platforms. Reporting to the Head of Compliance, this role is responsible for implementing, operating, and maintaining security controls, supporting certification to ISO 27001, SOC 2, and other relevant security frameworks, and embedding security-by-design into engineering, IT, and product operations as the business scales globally. This is a hands-on role with clear operational ownership of information security BAU, working closely with engineering, DevOps and IT, product management, and external auditors. This job can be worked remotely with bi-monthly visits to the London (Farringdon) office.

Key Responsibilities

  • Information Security and ISMS Operations
    • Implement, operate, and maintain the Information Security Management System (ISMS) aligned to ISO 27001.
    • Maintain risk assessments, risk registers, Statements of Applicability, and control mappings.
    • Collect, manage, and present evidence for ISO 27001 certification and surveillance audits.
    • Support SOC 2 readiness, control operation, evidence gathering, and audit coordination.
  • Security Controls and Engineering Integration
    • Implement and maintain security controls across:
    • Cloud infrastructure and internal IT systems
    • Robotics platforms, operating systems, and supporting services
    • eCommerce, RaaS, and customer-facing platforms
  • Work with engineering teams to embed security-by-design into system architecture, development pipelines, and operational workflows.
  • Support secure configuration, logging, monitoring, and access control practices.
  • Vulnerability and Incident Management
    • Operate vulnerability management processes including:
    • CVE monitoring and triage
    • Patch management coordination
    • Tracking and closure of remediation actions
  • Coordinate penetration testing and security assessments across products, platforms, and infrastructure.
  • Maintain incident response documentation, support tabletop exercises, and assist with post-incident reviews.
  • Identity, Access and Data Security
    • Support identity and access management (IAM) compliance including:
    • Role-based access control
    • Quarterly access reviews
    • MFA/2FA enforcement
  • Support encryption, key management, backup, and recovery controls.
  • Work with compliance and legal stakeholders on data protection and privacy-related security controls.
  • Supplier and Third-Party Security
    • Conduct security assessments of suppliers, cloud providers, and third parties.
    • Review security documentation, certifications, and contractual security requirements.
    • Track third-party security risks and remediation activities.
  • Audits, Documentation and Governance
    • Maintain security policies, procedures, standards, and technical evidence.
    • Support internal audits, external certification audits, and customer security due diligence requests.
    • Ensure security documentation remains current, controlled, and audit-ready.
  • Security Awareness and Compliance Culture
    • Support delivery of security awareness and role-specific training.
    • Act as a trusted security partner to engineering, IT, and product teams.
    • Promote pragmatic security that enables innovation while managing risk.
  • Essential Experience and Expertise

    • Hands-on experience in information security engineering, security operations, or security compliance roles.
    • Practical experience operating an ISO 27001 aligned ISMS, including risk management and audit evidence.
    • Working knowledge of cloud, infrastructure, and application security controls.
    • Experience with vulnerability management and incident response.
    • Ability to translate security and compliance requirements into practical technical controls.
    • Experience working with engineering, IT, non-technical stakeholders, and external auditors.
    • Strong documentation and evidence management skills.

    Desirable Experience and Expertise

    • Experience with SOC 2 or multi-framework security environments.
    • Exposure to product, platform, or robotics/embedded security.
    • Familiarity with IAM, data protection, and privacy-related controls.
    • Experience with supplier and third-party security assessments.
    • Involvement in security awareness or training initiatives.
    • Experience supporting scaling or globally distributed organisations.

    Reporting and Authority

    • Reports directly to the Head of Compliance.
    • Acts as the operational owner for information security and cybersecurity BAU.
    • Escalates strategic, high-risk, or novel security issues appropriately.

    Personal Attributes

    • Highly organised, methodical, and evidence-driven.
    • Comfortable operating autonomously as the day-to-day security owner.
    • Calm and structured during audits and security incidents.
    • Sound judgement in balancing security, usability, and delivery pace.

    Role Fit

    This role is ideal for an Information Security and Compliance Engineer who wants clear ownership, hands-on impact, and the opportunity to build security foundations that support the safe scaling of advanced robotics, AI platforms, and global services.

    About Engineered Arts

    Engineered Arts is the leading manufacturer of full-size humanoid robots used for entertainment, education and communication. With 20 years of hardware and software development, our robots have been sold in over 30 countries worldwide with customers such as NASA, PwC, Meta and many more. Our Ameca robot is well known as 'the face of AI' and a social media viral success, taking advantage of the generative AI craze. Along with our ultra-realistic Mesmer range of animated figures our robots continue to surprise and excite visitors at museums, theme parks, visitor attractions and trade shows as well as aid leading universities with AI and robotics research. Our robots are poised to break into the future mega-expansion service robot segment, with applications such as front of house, receptions, check-in desks, information points and PoS. We are also exploring how our humanoid robot technology can disrupt other robotics sectors such as the growing cobot sub-segment of the industrial robotics market.

    We are a team of dedicated engineers and creatives striving to develop the very best experiences for our customers. Our internal motto is 'Be Wow', everything we do is fun, entertaining or surprising to encounter. We always push the boundaries of what is possible in humanoid robotics, researching and developing new systems and techniques to further their appeal. We explore and challenge the human perception of robots as well as the fear and discomfort and the excitement and joy life-like mechanical humanoids present.

    At Engineered Arts, innovation is at the core of everything we do — and we believe true innovation only happens when diverse minds come together. We are committed to building a workplace where people of all backgrounds, identities, and perspectives feel welcome, supported, and empowered to contribute. Whether you're an engineer, developer, or creative thinker, we value what makes you unique. We actively promote inclusion across our hiring, design, and development practices, and we're always looking for new ways to reflect the world around us — in our team, our robots, and our ideas. Because building the future means including everyone in it.

    Information Security and Compliance Engineer in London employer: Engineered Arts

    Engineered Arts is an exceptional employer that fosters a culture of innovation and inclusivity, making it an ideal place for an Information Security and Compliance Engineer. With opportunities for professional growth and the chance to work on cutting-edge robotics technology, employees benefit from a supportive environment that values diverse perspectives. The flexibility of remote work combined with regular collaboration in our vibrant London office ensures a dynamic and engaging workplace experience.
    E

    Contact Detail:

    Engineered Arts Recruiting Team

    StudySmarter Expert Advice 🤫

    We think this is how you could land Information Security and Compliance Engineer in London

    ✨Tip Number 1

    Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

    ✨Tip Number 2

    Prepare for interviews by researching the company and its products. Understand their security needs and be ready to discuss how your skills align with their goals. Show them you’re not just another candidate, but someone who genuinely cares about their mission.

    ✨Tip Number 3

    Practice your technical skills! Brush up on relevant tools and frameworks, especially those mentioned in the job description. Being hands-on will give you the confidence to tackle any technical questions that come your way.

    ✨Tip Number 4

    Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you’re serious about joining our team at Engineered Arts and contributing to our innovative projects.

    We think you need these skills to ace Information Security and Compliance Engineer in London

    Information Security Management System (ISMS)
    ISO 27001
    SOC 2
    Risk Management
    Vulnerability Management
    Incident Response
    Cloud Security
    Access Management
    Data Protection
    Security Assessments
    Documentation Management
    Security Awareness Training
    Technical Evidence Management
    Collaboration with Engineering and IT Teams

    Some tips for your application 🫡

    Tailor Your Application: Make sure to customise your CV and cover letter for the Information Security and Compliance Engineer role. Highlight your hands-on experience with ISO 27001 and any relevant security frameworks, as this will show us you understand what we're looking for.

    Showcase Your Skills: Don’t just list your skills; give us examples of how you've implemented security controls or managed incidents in previous roles. We love seeing practical applications of your expertise, especially in cloud infrastructure and compliance.

    Be Clear and Concise: When writing your application, keep it straightforward and to the point. Use clear language to describe your experience and achievements, so we can easily see how you fit into our team and culture.

    Apply Through Our Website: We encourage you to apply directly through our website. This way, your application goes straight to us, and you can be sure it’s seen by the right people. Plus, it’s super easy to do!

    How to prepare for a job interview at Engineered Arts

    ✨Know Your Security Frameworks

    Familiarise yourself with ISO 27001 and SOC 2, as these are crucial for the role. Be prepared to discuss how you've implemented or maintained security controls in previous positions, and think of specific examples that demonstrate your hands-on experience.

    ✨Showcase Your Technical Skills

    Be ready to dive into the technical aspects of information security. Brush up on cloud infrastructure, vulnerability management, and incident response processes. Highlight any relevant projects where you successfully integrated security-by-design into engineering workflows.

    ✨Prepare for Scenario-Based Questions

    Expect questions that assess your problem-solving skills in real-world scenarios. Think about past incidents you've managed or security assessments you've conducted. Use the STAR method (Situation, Task, Action, Result) to structure your responses effectively.

    ✨Emphasise Collaboration and Communication

    This role requires working closely with various teams, so be prepared to discuss how you've collaborated with engineering, IT, and compliance stakeholders. Share examples of how you've communicated complex security concepts to non-technical audiences to ensure everyone is on the same page.

    Information Security and Compliance Engineer in London
    Engineered Arts
    Location: London

    Land your dream job quicker with Premium

    You’re marked as a top applicant with our partner companies
    Individual CV and cover letter feedback including tailoring to specific job roles
    Be among the first applications for new jobs with our AI application
    1:1 support and career advice from our career coaches
    Go Premium

    Money-back if you don't land a job in 6-months

    E
    Similar positions in other companies
    UK’s top job board for Gen Z
    discover-jobs-cta
    Discover now
    >