SureCloud
Compliance & Assurance Lead

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
About SureCloud
SureCloud is a UK-headquartered provider of cloud-based GRC software, delivered as a multi-tenant SaaS platform hosted on AWS. We operate an ISO 27001:2022-certified ISMS, hold Cyber Essentials Plus, and make compliance central to both our product and how we run the business. As we scale the platform and our AI capability (Gracie), we're strengthening the internal governance, risk and compliance function that keeps our certifications, customer commitments and regulatory obligations on track.
Role purpose
A hands-on, compliance-focused role owning the day-to-day running of SureCloud's governance, risk and compliance programme — keeping the ISMS healthy, evidence continuously audit-ready, and our certifications and regulatory obligations on track across ISO 27001, SOC 2, GDPR and ISO/IEC 42001. The emphasis is on assurance, evidence and audit outcomes: proving that controls operate, not running the underlying infrastructure. You'll work closely with the CTO, the SRE/engineering team (who implement and operate the technical controls) and the Security Working Group.
Key responsibilities
Compliance & certifications
- ISO 27001:2022 — own audit readiness end to end, manage the BSI relationship, prepare and curate evidence, and coordinate internal and surveillance/recertification audits through to a clean outcome.
- SOC 2 — drive the programme toward SOC 2 Type 2 readiness and attestation: map controls, define and operate evidence collection over the observation window, and liaise with the external auditor.
- GDPR / data protection — operate the data protection programme: RoPA, DPIAs, DSAR handling, breach-notification readiness, policy updates, retention schedules and sub-processor oversight.
- ISO/IEC 42001 — maintain and mature SureCloud's AI management system alignment for Gracie, including AI governance controls and the AI Acceptable Use Policy.
- Establish and run continuous control monitoring — define control tests, monitor operating effectiveness, and surface exceptions for remediation rather than discovering gaps at audit time.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Governance, ISMS & risk
- Run and maintain the ISMS day-to-day: own the policy set, keep documents current, version-controlled and reviewed on schedule, and drive the annual review cycle.
- Internal Audit - manage the plan and run audits.
- Coordinate and run the Security Working Group — the standing governance forum for risk, incidents, audits, policy review and control oversight — and provide compliance reporting into the leadership team.
- Maintain the risk registers and run the risk assessment and treatment process, tracking treatment actions to closure.
- Oversee auditing of vulnerability management, patch compliance and security incident handling from a control and assurance standpoint — confirming SLAs are met and evidence is captured, while the SRE/engineering team owns the technical operation and remediation.
- Translate control and compliance requirements into clear, actionable asks for engineering/SRE/IT, and track them to closure.
Customer assurance & third-party risk
- Own security questionnaires, DDQs and customer due diligence responses, and keep the answer library and Trust Centre content accurate and current.
- Run the supplier/third-party risk process: tiered assessments, contractual security clauses, SOC 2/ISO reviews and annual re-assessment.
- Support customer conversations on security and compliance matters before and during implementations.
Awareness & culture
- Deliver and track security and data-protection awareness training and onboarding; report compliance to the Security Working Group.
- Champion a compliance-by-default culture across the business, with product and engineering embedding privacy and security-by-design.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Ways of working
- AI-native — comfortable creating and using agentic AI (e.g. Claude Code) to build agents and automated compliance processes.
- Work with the product team to test new features and ideas for SureCloud's Security and GRC product sets, feeding real practitioner insight back into the roadmap.
- Remote working — SureCloud offers hybrid from our office in Central London or fully remote working.
What you'll bring
- Demonstrable hands-on experience running a compliance / GRC programme in a SaaS/cloud environment, with direct ownership of ISO 27001 certification and audit cycles.
- Practical knowledge of SOC 2 and experience preparing for or supporting a SOC 2 examination, including evidence collection over an observation window.
- Working knowledge of UK/EU GDPR and data-protection operations (RoPA, DPIAs, DSARs, breach handling, sub-processor oversight).
- Strong evidence-management and audit discipline: comfortable owning controls, gathering and curating proof, mapping controls across frameworks, and tracking remediation to closure.
- Clear communicator able to translate requirements for engineers, customers and auditors alike, and to work independently in a remote-first team.
- Strong independent contributor, able to operate autonomously with guidance provided where required.
Nice to have
- Relevant compliance certifications (e.g. ISO 27001 Lead Implementer/Auditor, CISA, CISM, CIPP/E).
- Understanding of ISO/IEC 42001 or AI governance frameworks (EU AI Act, NIST AI RMF).
- Hands-on experience with GRC tooling and continuous control monitoring.
- Awareness of the underlying security operations of a fast-growing, cloud-first organisation (vulnerability management, endpoint management, incident response) sufficient to assure them — without needing to run them day-to-day.
- AWS Security Speciality or similar cloud credential.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location