Compliance & Assurance Lead in London

Compliance & Assurance Lead in London

London Full-Time No working from home possible
SureCloud

SureCloud is a UK-headquartered provider of cloud-based GRC software, delivered as a multi-tenant SaaS platform hosted on AWS. We operate an ISO 27001:2022-certified ISMS, hold Cyber Essentials Plus, and make compliance central to both our product and how we run the business. As we scale the platform and our AI capability (Gracie), we're strengthening the internal governance, risk and compliance function that keeps our certifications, customer commitments and regulatory obligations on track.

A hands‑on, compliance‑focused role owning the day‑to‑day running of SureCloud's governance, risk and compliance programme — keeping the ISMS healthy, evidence continuously audit‑ready, and our certifications and regulatory obligations on track across ISO 27001, SOC 2, GDPR and ISO/IEC 42001. The emphasis is on assurance, evidence and audit outcomes: proving that controls operate, not running the underlying infrastructure. You'll work closely with the CTO, the SRE/engineering team (who implement and operate the technical controls) and the Security Working Group.

Key responsibilities

Compliance & certifications

  • ISO 27001:2022 — own audit readiness end to end, manage the BSI relationship, prepare and curate evidence, and coordinate internal and surveillance/recertification audits through to a clean outcome.
  • SOC 2 — drive the programme toward SOC 2 Type 2 readiness and attestation: map controls, define and operate evidence collection over the observation window, and liaise with the external auditor.
  • GDPR / data protection — operate the data protection programme: RoPA, DPIAs, DSAR handling, breach‑notification readiness, policy updates, retention schedules and sub‑processor oversight.
  • ISO/IEC 42001 — maintain and mature SureCloud's AI management system alignment for Gracie, including AI governance controls and the AI Acceptable Use Policy.
  • Establish and run continuous control monitoring — define control tests, monitor operating effectiveness, and surface exceptions for remediation rather than discovering gaps at audit time.
  • Run and maintain the ISMS day‑to‑day: own the policy set, keep documents current, version‑controlled and reviewed on schedule, and drive the annual review cycle.
  • Internal Audit - manage the plan and run audits
  • Coordinate and run the Security Working Group — the standing governance forum for risk, incidents, audits, policy review and control oversight — and provide compliance reporting into the leadership team.
  • Maintain the risk registers and run the risk assessment and treatment process, tracking treatment actions to closure.
  • Oversee auditing of vulnerability management, patch compliance and security incident handling from a control and assurance standpoint — confirming SLAs are met and evidence is captured, while the SRE/engineering team owns the technical operation and remediation.
  • Translate control and compliance requirements into clear, actionable asks for engineering/SRE/IT, and track them to closure.

Customer assurance & third‑party risk

  • Own security questionnaires,DDQsand customer due diligence responses, and keep the answer library and Trust Centre content accurate and current.
  • Run the supplier/third‑party risk process: tiered assessments, contractual security clauses, SOC 2/ISO reviews and annual re‑assessment.
  • Support customer conversations on security and compliance matters before and during implementations.

Awareness & culture

  • Deliver and track security and data‑protection awareness training and onboarding; report compliance to the Security Working Group.
  • Champion a compliance‑by‑default culture across the business, with product and engineering embedding privacy and security‑by‑design.

Ways of working

  • AI‑native — comfortable creating and using agentic AI (e.g. Claude Code) to build agents and automated compliance processes.
  • Work with the product team to test new features and ideas for SureCloud's Security and GRC product sets, feeding real practitioner insight back into the roadmap.
  • Remote working — SureCloud offers hybrid from our office in Central London or fully remote working

What you'll bring

  • Demonstrable hands‑on experience running a compliance / GRC programme in a SaaS/cloud environment, with direct ownership of ISO 27001 certification and audit cycles.
  • Practical knowledge of SOC 2 and experience preparing for or supporting a SOC 2 examination, including evidence collection over an observation window.
  • Working knowledge of UK/EU GDPR and data‑protection operations (RoPA, DPIAs, DSARs, breach handling, sub‑processor oversight).
  • Strong evidence‑management and audit discipline: comfortable owning controls, gathering and curating proof, mapping controls across frameworks, and tracking remediation to closure.
  • Clear communicator able to translate requirements for engineers, customers and auditors alike, and to work independently in a remote‑first team.
  • Strong independent contributor, able to operate autonomously with guidance provided where required.

Nice to have

  • Understanding of ISO/IEC 42001 or AI governance frameworks (EU AI Act, NIST AI RMF).
  • Hands‑on experience with GRC tooling and continuous control monitoring.
  • Awareness of the underlying security operations of a fast‑growing, cloud‑first organisation (vulnerability management, endpoint management, incident response) sufficient to assure them — without needing to run them day‑to‑day.
  • AWS Security Speciality or similar cloud credential.

#J-18808-Ljbffr

SureCloud

Contact Details:

SureCloud Recruitment Team