Rodeo
Get started

Achilles Information Limited

Information Security & Compliance Lead

Didcot
£55k – £65k/yr
Posted about 20 hours ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Information Security & Compliance Lead

Location: UK - Hybrid (Abingdon-based)
Reporting to: Head of IT Security

We are looking for an experienced Information Security & Compliance Lead to drive our SOC 2 assurance journey and strengthen our security and compliance capabilities across the business. This is a highly visible role that combines governance, risk and compliance expertise with hands-on security leadership. You will play a critical role in helping Achilles achieve and maintain SOC 2 Type I and Type II attestation while embedding practical, scalable security controls that support our global growth.

Working closely with teams across Technology, Product, Legal, People and Operations, you'll ensure security and compliance become a natural part of how we operate.

What You’ll Do

  • Lead the delivery of our SOC 2 roadmap, from readiness through to Type I, Type II and ongoing annual assurance.
  • Design, implement and improve security controls aligned to SOC 2 Trust Services Criteria and broader industry frameworks.
  • Conduct readiness assessments, identify control gaps, and drive remediation activities across the business.
  • Coordinate internal stakeholders, external auditors and assessors to ensure successful audit outcomes.
  • Establish and manage a sustainable controls and evidence programme that keeps Achilles audit-ready all year round.
  • Strengthen security operations across identity and access management, cloud security, endpoint protection, vulnerability management, monitoring and incident response.
  • Partner with Engineering and Product teams to embed security into architecture, development and operational processes.
  • Manage third-party security assessments and supplier assurance activities.
  • Support business continuity, disaster recovery and incident management exercises.
  • Develop meaningful security metrics and provide clear reporting on risk, compliance and remediation progress.
  • Deliver security awareness guidance and support customer due diligence and security assurance activities.
  • Champion continuous improvement through automation, standardisation and pragmatic risk management.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

What You’ll Bring

  • Proven experience leading or significantly contributing to successful SOC 2 Type I and Type II programmes.
  • Strong understanding of SOC 2 Trust Services Criteria, control design, audit preparation and evidence management.
  • Hands-on experience implementing and operating security controls within cloud-first or SaaS environments.
  • Knowledge of security frameworks such as ISO 27001, NIST Cybersecurity Framework and CIS Controls.
  • Experience with identity and access management, vulnerability management, incident response, secure change management and third-party risk management.
  • Ability to communicate complex security concepts clearly to both technical and non-technical stakeholders.
  • Strong analytical and problem-solving skills, with the ability to balance risk management and business objectives.
  • Experience working with external auditors, assessors and multiple internal control owners.
  • Professional certifications such as CISSP, CISA, CRISC, CCSP, ISO 27001 Lead Auditor/Implementer or Security+ are advantageous.
  • Experience working across international or distributed teams would be beneficial.

Why Join Us?

  • Be part of a global business making a meaningful impact on sustainability, ESG and responsible business practices.
  • Play a pivotal role in shaping and maturing Achilles' global security and compliance capabilities.
  • Work alongside talented colleagues across technology, product and business functions.
  • Join a collaborative, values-driven organisation committed to continuous improvement and innovation.
  • Enjoy hybrid working and opportunities to collaborate with colleagues around the world.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

We welcome applications from armed forces veterans, reservists and their families. We are committed to equity, diversity and inclusion in our practices and workforce. A full role profile is available at Careers at Achilles | Join the Team.

For more than 30 years, Achilles has protected organisations’ business interests and reputations by providing unrivalled levels of supply chain transparency, carbon reduction and management. We are the ESG and carbon management partner of choice for the world’s leading global brands.

Achilles specialises in supporting customers that require truly robust environmental, social and governance reporting to fully comply with ESG regulation, meet investor requirements, and achieve their own ambitious sustainability goals. We work with market-leading financial, industrial, commercial, and governmental organisations requiring the serious, detailed analysis and expert insight necessary to deliver exceptional reporting confidence.

Operating from 22 locations worldwide, Achilles is at the forefront of the battle against climate change, a champion for social justice and human rights, and an expert in health, safety, and risk management.

The Achilles Way – how we do things

  • Be Curious – Ask questions, understand why, challenge and grow
  • Commit – Show passion, create value, deliver simple solutions, be a leader
  • Collaborate – Think inclusive, show respect, be helpful, give thanks
Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

SOC 2 Compliance
Governance Risk and Compliance
Security Control Design
Audit Management
Cloud Security
Identity and Access Management
Vulnerability Management
Incident Response
Third-Party Risk Management
ISO 27001
NIST Cybersecurity Framework
CIS Controls
Business Continuity Planning
Disaster Recovery
Security Metrics Reporting
Stakeholder Management

Location

Didcot, England, United Kingdom

Sign up to applySee more jobs like this