At a Glance
- Tasks: Lead and manage compliance programmes, ensuring certifications are maintained and new projects are implemented.
- Company: Join OnTrack Retail Limited, a dynamic tech company revolutionising UK rail ticketing.
- Benefits: Enjoy flexible hybrid working, competitive salary, 25 days holiday, and health insurance.
- Other info: Directly report to the MD and influence a business-critical programme.
- Why this job: Make a real impact by building a compliance function from the ground up.
- Qualifications: Experience with ISO standards and data protection compliance is essential.
The predicted salary is between 50000 - 65000 £ per year.
About OnTrack Retail Limited
OnTrack Retail Limited (OTRL) is a UK rail retail technology company of 35 people, building and operating digital ticketing platforms for some of the UK’s major train operators, including GTR, Southeastern, and TransPennine Express. Our consumer-facing brand, TicketyBoo, is a train ticket booking app available to passengers across Great Britain.
We hold ISO 27001 accreditation and PCI DSS compliance, and operate in a regulated, high-availability environment where governance and security are central to everything we do. We are at an exciting point in our growth, actively pursuing new contract opportunities across the UK rail sector and have embarked on an accelerated programme to strengthen our compliance and accreditation posture. This role is central to that programme.
This is a newly created position, reflecting the increasing importance of compliance and accreditation to OTRL’s commercial success and operational integrity. You will own and manage our compliance programme in its entirety, from day-to-day maintenance of existing certifications through to leading new accreditation projects.
You will report directly to the Managing Director and work closely with our technical leads, operations team, and external certification bodies. This is a hands-on role: you will not be managing a large team, but you will be driving a significant and genuinely impactful programme of work across a business that takes compliance seriously.
Our Current and Target Accreditation Stack
- ISO 27001 — Information Security - Certified - Maintain and develop
- Cyber Essentials Plus - Newly achieved (June 2026) - Maintain annual renewal
- PCI DSS - Compliant - Maintain
- ISO 22301 — Business Continuity - Documentation complete, testing underway - Lead to certification
- ITIL v5 — Service Management - Programme in planning - Coordinate training cohort
- ISO 9001 — Quality Management - Under evaluation - Assess and potentially lead
- ISO 20000 — IT Service Management - Under evaluation - Assess and roadmap
Key Responsibilities
- Certification and Accreditation Management
- Own the full compliance calendar across all current and target certifications, ensuring surveillance audits, renewals, and evidence collection are managed proactively.
- Lead OTRL to ISO 22301 certification, building on existing documentation and testing programme.
- Manage our ISO 27001 programme through its annual surveillance and recertification cycle.
- Coordinate the ITIL v5 Foundation training cohort and support Practice Manager candidates.
- Assess the business case and feasibility for ISO 9001 and ISO 20000 and, where approved, lead implementation.
- Manage the relationship with our certification body and external auditors.
- GDPR and Data Protection
- Support OTRL’s data protection programme, working alongside our internal and Group DPOs who retain overall accountability.
- Own day-to-day operational data protection activity, DSAR processes, privacy impact assessments, and data breach documentation.
- Maintain our Records of Processing Activity (RoPA) and keep data protection policies current.
- Support incident response processes where personal data is involved.
- Supplier and Third Party Compliance
- Maintain OTRL’s supplier compliance framework, including contractual review cycles and third party security assessments.
- Manage Standard Contractual Clauses and international data transfer documentation.
- Support procurement processes with compliance due diligence on new suppliers.
- Policy and Internal Audit
- Own OTRL’s policy suite, maintaining, reviewing, and updating policies on an annual basis.
- Run the internal audit programme across ISO 27001 and ISO 22301, and subsequently any additional standards.
- Manage staff compliance training and attestation processes.
- Maintain the risk register and support management review processes.
- Bid and Tender Support
- Own the compliance and accreditation sections of tender responses, maintaining an up-to-date evidence library and statement of compliance that can be drawn on quickly when procurement windows open.
- Work with the MD to develop and communicate OTRL’s compliance roadmap to clients and procurement bodies.
Experience and Skills
Essential
- Hands-on experience implementing or maintaining ISO 27001, you have lived through at least one certification cycle, not just supported from a distance.
- Experience with at least one further ISO standard (ISO 22301, ISO 9001, or ISO 20000) at a practical implementation level.
- Solid working knowledge of UK GDPR and practical experience of data protection compliance in a technology or payments environment.
- Demonstrable ability to own and drive a compliance programme with limited supervision in a small, fast-moving organisation.
- Strong documentation skills, you write clearly, structure well, and produce audit-ready evidence without gold-plating.
- Comfortable working across technical and non-technical stakeholders.
Desirable
- ISO Lead Auditor qualification (27001 or equivalent), this is a genuine differentiator.
- ITIL Foundation certification or familiarity with the framework.
- Experience in a fintech, payments, or regulated technology environment.
- Familiarity with PCI DSS compliance requirements.
- Experience supporting public sector or regulated procurement processes.
- Knowledge of the UK rail industry or exposure to RDG/TOC commercial environments.
What We Offer
- A direct reporting line to the Managing Director and genuine influence over a business-critical programme.
- The chance to build a compliance function largely from scratch in a company that takes it seriously.
- A varied, substantial role, this is not a tick-box maintenance job.
- Flexible hybrid working.
- Salary of £50,000 – £65,000 depending on experience.
- 25 days holiday plus bank holidays.
- Support for relevant professional development and certification.
- Vitality health insurance.
Information Security and Compliance Manager in London employer: OnTrack Retail
OnTrack Retail Limited is an exceptional employer, offering a dynamic work environment where compliance and security are at the forefront of our operations. With a focus on employee growth, we provide opportunities to build a compliance function from the ground up, alongside flexible hybrid working arrangements and comprehensive benefits including professional development support and health insurance. Join us in shaping the future of rail retail technology while enjoying a meaningful and impactful role in a supportive team culture.
StudySmarter Expert Advice🤫
We think this is how you could land Information Security and Compliance Manager in London
✨Join Compliance Communities
Get involved in compliance and risk communities — both online and offline. Look for forums, LinkedIn groups, or even local meetups where compliance pros hang out. You never know who might drop a job opportunity your way!
✨Attend Industry Conferences
Keep an eye out for compliance and risk management conferences and workshops in your area. These events are a goldmine for networking, and they often have job boards or recruiters on-site looking for new talent. Plus, it’s a chance to learn what's trending in the field.
✨Leverage Your University Career Services
If you’ve recently graduated or are still studying, head over to your university's career services. Many companies, including those in compliance, actively recruit fresh talent through these services, so make sure you tap into that resource.
✨Showcase Your Knowledge Online
Start writing articles or blog posts about compliance topics that interest you. Share them on platforms like LinkedIn to demonstrate your knowledge and passion. This not only builds your presence in the field but can also catch the attention of companies like OnTrack Retail looking for candidates who are engaged and informed.
We think you need these skills to ace Information Security and Compliance Manager in London
Some tips for your application 🫡
Show Your Understanding of Compliance:In the compliance-risk field, it's super important to showcase your understanding of regulations and risk management frameworks. Highlight any relevant coursework, certifications (like ICA or AML), or even projects that demonstrate your knowledge and commitment to this area. We want to see how you can navigate this complex landscape!
Quantify Your Achievements:When detailing your experience, try to quantify your achievements. For example, if you've previously worked on a project that improved compliance metrics or reduced risk exposure, give us the numbers! This data-driven approach really stands out to hiring managers in compliance-risk roles.
Tailor Your CV to Reflect Relevant Skills:Make sure your CV highlights skills that are particularly relevant to compliance, like attention to detail, analytical thinking, and report writing. Ensure these are easy to spot – consider using bullet points to break down your responsibilities and achievements for maximum impact!
Craft a Motivating Cover Letter:In your cover letter, let us know why you’re excited about the compliance-risk role at OnTrack Retail. Share what motivates you about compliance, and how you believe you can contribute to our mission. This is your chance to showcase not only your skills but also your passion for this important field!
How to prepare for a job interview at OnTrack Retail
✨Master the Regulations
Brush up on key compliance regulations relevant to the industry you're applying to. Familiarising yourself with specific laws and frameworks used in your field will give you an edge during technical questions. Show that you’re not just aware of them but can also apply them—think real-life scenarios!
✨Show Your Analytical Skills
Compliance roles really focus on analytical skills, so be prepared for case studies or situational questions during the interview. We've got to demonstrate how we approach risk assessments or compliance audits, possibly drawing on examples from past experiences or university projects. Bring some thoughtful case scenarios to discuss!
✨Know Your Tools
Get comfortable with commonly used compliance software and tools. Familiarity with platforms like RSA or MetricStream can really impress during your interview, as it shows you're ready to hit the ground running. If you’ve had any experience with them, make sure to highlight that!
✨Align with Company Culture
Since it's a full-time position, show your long-term commitment and interest in the company’s mission and values. Dive into how your ethics and professional philosophy align with OnTrack Retail’s stance on compliance. A shared vision can really resonate with interviewers looking for fit as much as skill!