At a Glance
- Tasks: Lead security and compliance efforts, ensuring data protection and risk management.
- Company: Prolific, a leader in ethical AI research and data collection.
- Benefits: Competitive salary, remote work, and a mission-driven culture.
- Why this job: Join us at the forefront of AI innovation and make a real impact.
- Qualifications: 5+ years in security operations with strong cloud security experience.
- Other info: Opportunity for career growth and to shape security culture.
The predicted salary is between 43200 - 72000 ÂŁ per year.
Security and compliance at Prolific aren't afterthoughts — they're foundational to how we operate. As a company trusted by world-leading research institutions and AI labs to handle sensitive data at scale, we take our responsibility to protect that trust seriously. We maintain certifications like ISO 27001 and SOC 2, and we're looking for someone to own and evolve our security and compliance posture as we grow.
As Security & Compliance Lead, you'll be the go-to authority on information security across the organisation. You'll own our compliance program, lead security operations, and work hands‑on with engineering and platform teams to ensure security is embedded in how we build and operate — not bolted on after the fact. This means getting into the weeds of our cloud infrastructure, shaping how security fits into the SDLC, and driving a DevSecOps mindset across engineering.
You'll report to the Head of Engineering/Platform and work cross‑functionally with legal, techops, engineering, platform, and data teams. As we scale, there's a clear path for this role to grow into managing a small security function. This is a hands‑on senior role. You won't just be writing policies — you'll be monitoring threats, responding to incidents, driving audits, reviewing cloud security posture, and shaping how Prolific approaches security as we scale across the world.
What you'll be doing
- Security Operations & Cloud Security
- Monitor for security threats, vulnerabilities, and incidents across our infrastructure, applications, and tooling.
- Create, respond to, and investigate security alerts using SIEM tooling (e.g. Datadog), triaging and escalating as appropriate.
- Own and improve our endpoint security, vulnerability scanning (e.g. Snyk), and cloud security posture management across GCP and AWS.
- Design and implement security architectures across our cloud infrastructure, working hands‑on with Kubernetes, Terraform/IaC, and cloud‑native services.
- Lead incident response — minimising impact, ensuring rapid recovery, and coordinating post‑incident analysis and reporting.
- Coordinate penetration testing and manage remediation of findings.
- Compliance & Governance
- Take responsibility for all technical aspects of our compliance program ensuring we maintain ISO 27001, SOC 2, and Cyber Essentials certifications.
- Lead the preparation and coordination of external audits, ensuring documentation and evidence are always audit‑ready.
- Create, manage, and maintain security and compliance frameworks, including policies, procedures, and guidelines.
- Partner with legal and our DPO on GDPR and data privacy requirements, ensuring our security practices support our data protection obligations.
- Align security strategy with business objectives, managing risks while enabling growth.
- Assist data teams with governance requirements.
- Be the authority on information security within the engineering organisation, ensuring security is embedded throughout the SDLC.
- Work cross‑functionally with engineering and platform teams to integrate security into CI/CD pipelines, code review, and infrastructure‑as‑code workflows.
- Contribute to platform and infrastructure security architecture decisions, providing guidance on secure design patterns and cloud security best practices.
- Promote security awareness across the business, including secure development practices, cloud platform security, and general security hygiene.
- Identify and assess emerging threats and vulnerabilities, recommending actionable mitigations to reduce risk exposure.
- Monitor and report on trends in the cyber threat landscape, providing insights to inform organisational security decisions.
- Share threat intelligence and mitigation strategies with relevant teams to enhance awareness and preparedness.
What you'll bring
- 5+ years of experience in security operations, cloud security, or a combined security and compliance role, with a track record of owning and delivering security outcomes independently.
- Strong hands‑on experience with cloud security in GCP and/or AWS, including working with Kubernetes, Terraform/IaC, and cloud‑native security tooling.
- Deep understanding of compliance frameworks such as ISO 27001 and SOC 2, with experience owning or significantly contributing to audit preparation and certification maintenance.
- Experience with security tooling across SIEM, vulnerability scanning, endpoint security, and cloud security posture management.
- A solid understanding of DevSecOps principles and experience embedding security into the software development lifecycle.
- Working knowledge of GDPR and data privacy requirements, and experience partnering with legal or DPO functions.
- Strong communication skills — you can translate security risks into business language, influence engineering teams, and write documentation that's clear and actionable.
- The ability to work independently, manage competing priorities, and exercise good judgement about where to focus your time.
- A proactive mindset — you spot risks early, propose solutions, and take ownership without being asked.
Even better if you have
- Experience coordinating penetration testing programmes and managing remediation.
- Familiarity with infrastructure‑as‑code security scanning and policy‑as‑code approaches.
- Experience with incident response programme design or tabletop exercises.
- Exposure to customer security questionnaires, vendor due diligence, or third‑party risk assessments.
- Experience working in a scaling company where you've helped build security processes and culture from the ground up.
- A relevant security certification such as CISSP, CISM, or cloud‑specific security certifications (e.g. GCP Professional Cloud Security Engineer).
- Experience mentoring or growing into a people management role.
Why Prolific is a great place to work
We've built a unique platform that connects researchers and companies with a global pool of participants, enabling the collection of high‑quality, ethically sourced human behavioural data and feedback. This data is the cornerstone of developing more accurate, nuanced, and aligned AI systems.
We believe that the next leap in AI capabilities won't come solely from scaling existing models, but from integrating diverse human perspectives and behaviours into AI development. By providing this crucial human data infrastructure, Prolific is positioning itself at the forefront of the next wave of AI innovation – one that reflects the breadth and the best of humanity.
Working for us will place you at the forefront of AI innovation, providing access to our unique human data platform and opportunities for groundbreaking research. Join us to enjoy a competitive salary, benefits, and remote working within our impactful, mission‑driven culture.
Security & Compliance Lead in London employer: Prolific - UK Job Board?
Contact Detail:
Prolific - UK Job Board? Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Security & Compliance Lead in London
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by researching the company and its culture. Understand their security practices and compliance frameworks. This will help you tailor your answers and show that you're genuinely interested in the role.
✨Tip Number 3
Practice your technical skills! Brush up on your knowledge of cloud security, incident response, and compliance standards. Being hands-on with tools like SIEM and vulnerability scanners will give you an edge during technical interviews.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who are proactive about their job search.
We think you need these skills to ace Security & Compliance Lead in London
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter for the Security & Compliance Lead role. Highlight your relevant experience in security operations and compliance frameworks like ISO 27001 and SOC 2, so we can see how you fit right into our team.
Show Off Your Hands-On Experience: We love candidates who can get their hands dirty! Share specific examples of your work with cloud security, Kubernetes, and incident response. This will help us understand your practical skills and how you can contribute to our security posture.
Communicate Clearly: When writing your application, keep it clear and concise. Use straightforward language to explain complex security concepts. We want to see that you can translate security risks into business language, which is key for this role.
Apply Through Our Website: Don’t forget to submit your application through our website! It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it shows you’re keen on joining our mission-driven culture.
How to prepare for a job interview at Prolific - UK Job Board?
✨Know Your Stuff
Make sure you have a solid understanding of security operations, cloud security, and compliance frameworks like ISO 27001 and SOC 2. Brush up on your hands-on experience with GCP and AWS, as well as tools like Kubernetes and Terraform. Being able to discuss these topics confidently will show that you're the right fit for the role.
✨Show Your Proactive Mindset
During the interview, highlight instances where you've identified risks early and proposed solutions. Share specific examples of how you've taken ownership of security outcomes in previous roles. This will demonstrate your proactive approach and ability to manage competing priorities effectively.
✨Communicate Clearly
Strong communication skills are key for this role. Practice translating complex security risks into business language. Be prepared to explain how you've influenced engineering teams and created clear, actionable documentation in the past. This will help the interviewers see your ability to bridge the gap between security and business objectives.
✨Emphasise Collaboration
Since this role involves working cross-functionally with various teams, be ready to discuss your experience collaborating with legal, techops, and engineering teams. Share examples of how you've integrated security into the software development lifecycle and promoted security awareness across the organisation. This will showcase your ability to work well with others and drive a DevSecOps mindset.