At a Glance
- Tasks: Support information security compliance and manage audit processes for ISO 27001 and SOC 2.
- Company: Join RedCompass Labs, a leader in payment transformation and financial crime prevention.
- Benefits: Enjoy competitive pay, health insurance, life insurance, and generous holiday allowance.
- Why this job: Make a real impact in cybersecurity while working with cutting-edge technology.
- Qualifications: Knowledge of ISO 27001, SOC 2, and strong documentation skills are essential.
- Other info: Diverse and inclusive workplace with excellent career growth opportunities.
The predicted salary is between 36000 - 60000 £ per year.
RedCompass Labs enables good payments and helps stop the bad. We are experts in ISO20022-based payments, instant payments, cross-border payments, payments interoperability and financial crime. We use the latest Applied AI, micro‑services technology and deep payment knowledge to deliver payment transformation projects. These solutions help our clients accelerate their payments modernization programs, reducing costs and regulatory risk. With offices in London, Warsaw, Antwerp, Tokyo, Miami, Toronto, and Pune, we support clients worldwide.
Role Description
To provide operational and administrative support to the Head of Information Security in maintaining and maturing the Information Security Management System (ISMS), ensuring ongoing compliance with ISO 27001 and SOC 2 standards. This role will focus on evidence collection, documentation, audit readiness, incident response coordination, and day‑to‑day management of compliance artefacts and processes.
Key Responsibilities
- Assist in maintaining and updating ISMS documentation, including Statements of Applicability, risk treatment plans, and control records.
- Support the tracking and publishing of compliance artefacts in Vanta and other platforms.
- Own policy review, update and renewal process, tracked through Vanta.
- Monitor policy acknowledgements and ensure timely completion across the organization.
Audit & Certification Support
- Coordinate evidence collection and documentation for ISO 27001 and SOC 2 Type 1 & 2 audits.
- Help manage audit schedules, track remediation actions, and liaise with external auditors and vendors.
- Prepare and organise audit‑ready documentation and support effectiveness reviews.
Incident Management & Security Operations
- Support incident response planning and maintain logs, monitoring records, and configuration documentation.
- Track corrective actions from audits and ensure closure with supporting evidence.
- Assist in change control board meetings and processes.
AI Governance & Risk Management (Support)
- Help maintain AI risk assessment guidelines and vendor risk checklists.
- Assist with documentation and reporting for AI governance activities.
Business Continuity and Disaster Recovery
- Conduct risk assessments and business impact analyses to identify critical systems, processes and dependencies.
- Assist in the creation, review, and maintenance of Business Continuity and Disaster Recovery plans aligned with SOC 2 requirements and organizational risk posture.
- Coordinate and participate in regular BCP and DR testing exercises (e.g., tabletop exercises, failover tests) and document outcomes for audit readiness.
Administrative & Reporting Support
- Prepare quarterly security and compliance reports for review with Head of Information Security.
- Maintain records of audit status, risk posture, and compliance maturity.
- Support the alignment of security initiatives with organisational goals.
In addition to core operational duties, the role includes oversight of compliance and risk tracking activities within the Vanta platform. This includes:
- Monitoring and Managing Open Risk Items: Regularly reviewing Vanta dashboards to identify outstanding risk items, ensuring timely follow‑up and resolution in collaboration with relevant stakeholders.
- Tracking Test Status and Remediation Actions: Ensuring that scheduled tests (e.g., access reviews, vulnerability scans, control validations) are completed on time. Following up on failed or overdue tests and coordinating remediation efforts.
- Reporting and Escalation: Providing regular updates to leadership on the status of open risks and test outcomes, highlighting areas of concern and recommending mitigation strategies.
Skills & Experience Required
- Knowledge of ISO 27001 and SOC 2 Frameworks
- Documentation & Reporting Skills
- Incident Response & Security Operations Support
- Risk Assessment & Business Impact Analysis
- Attention to Detail
- Stakeholder Coordination
- Organisational & Time Management
- Experience with Compliance Platforms (e.g., Vanta)
Preferred
- Experience with Audit Preparation or External Audit Liaison
- Knowledge of Business Continuity & Disaster Recovery Planning
- Familiarity with AI Governance or Emerging Tech Risk
- Security Awareness Training or Policy Management
- Process Improvement Mindset
- Basic Technical Understanding
Contract of employment with RedCompass Labs includes the following competitive benefits package:
- Up to 10% of annual earnings as a personal performance bonus
- Life insurance
- Group Income Protection
- Health Insurance for you and your family
- Dental Insurance for you and your family
- Pension: the pension is currently 4% employer and 4% employee. You can also contribute more and to a private pension.
- 28 days annual holiday plus Public & Bank holidays and Company Holiday Day
RedCompass Labs is committed to promoting and supporting a diverse and inclusive workplace, ensuring fair and equitable treatment for all.
Information Security & SOC 2 Support Analyst employer: RedCompass Labs
Contact Detail:
RedCompass Labs Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Information Security & SOC 2 Support Analyst
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by researching the company and its culture. Understand their values and how they align with your skills, especially in areas like ISO 27001 and SOC 2 compliance. This will help you stand out as a candidate who truly gets what they’re about.
✨Tip Number 3
Practice your responses to common interview questions, but keep it natural. Use the STAR method (Situation, Task, Action, Result) to structure your answers, especially when discussing your experience with incident response or risk management.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who are proactive and engaged with our brand.
We think you need these skills to ace Information Security & SOC 2 Support Analyst
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Information Security & SOC 2 Support Analyst role. Highlight relevant experience with ISO 27001 and SOC 2 frameworks, and don’t forget to showcase your documentation and reporting skills!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you’re passionate about information security and how your skills align with our mission at RedCompass Labs. Keep it concise but impactful!
Showcase Your Attention to Detail: In this role, attention to detail is key. When filling out your application, double-check for any typos or errors. A polished application reflects your commitment to quality and professionalism.
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, you’ll find all the info you need about us and the role!
How to prepare for a job interview at RedCompass Labs
✨Know Your Standards
Familiarise yourself with ISO 27001 and SOC 2 frameworks before the interview. Be ready to discuss how your experience aligns with these standards, as this will show your understanding of the role's requirements.
✨Showcase Your Documentation Skills
Prepare examples of your past work related to documentation and reporting. Highlight any specific tools you've used, like Vanta, and be ready to explain how you ensured compliance and audit readiness in previous roles.
✨Incident Response Insights
Think of a time when you dealt with an incident response situation. Be prepared to share your approach, the steps you took, and the outcome. This will demonstrate your practical knowledge and problem-solving skills.
✨Engage with Stakeholders
Discuss your experience in stakeholder coordination. Prepare to talk about how you’ve managed communication and collaboration across teams, especially in compliance-related projects, as this is crucial for the role.