Rodeo
Get started

MRP-Global

Platform Security & Compliance Lead – AWS, Terraform, SOC 2, GDPR – Permanent, Hybrid, Full-Time – London, UK

London
Posted about 15 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Job Title: Platform Security & Compliance Lead

A UK-based technology organization is seeking an experienced Platform Security & Compliance Lead to own security, compliance, and governance across their digital wallet platform, reporting to the CTO, with significant autonomy and end-to-end ownership of the security function.

Key Responsibilities:

  • Own the security posture of the AWS environment, including IAM, VPC, Secrets Manager, ECS, Aurora, and access controls.
  • Manage identity and access management, including Cloudflare Zero Trust.
  • Embed security into engineering through threat modeling, secure code and design reviews, vulnerability management, and secure development practices.
  • Manage CI/CD and supply-chain security, including dependencies, GitHub Actions, build provenance, and container security.
  • Own security monitoring, incident response, vulnerability management, and penetration testing.
  • Lead the SOC 2 programme, including controls, evidence, audits, and remediation.
  • Manage UK GDPR and PECR requirements, including DPAs, sub-processors, data processing records, and privacy requirements.
  • Lead customer security reviews, questionnaires, vendor assessments, and security due diligence.
  • Maintain security policies, training, and compliance requirements relating to Apple and Google Wallet programs.
  • Own the security incident lifecycle, including response, notifications, post-incident reviews, and remediation.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Required Skills & Experience:

  • Deep hands-on experience securing production AWS environments, including IAM, VPC, containers, and databases.
  • Strong Terraform and infrastructure-as-code experience.
  • Strong application, cloud, and infrastructure security knowledge.
  • Experience with CI/CD, supply-chain security, vulnerability management, and incident response.
  • Pragmatic approach to security risk with strong problem-solving and decision-making skills.
  • Ability to work autonomously and effectively alongside engineering teams.
  • SOC 2 and UK GDPR experience would be highly advantageous.
  • Experience working with enterprise customers and security review processes is desirable.
  • Ruby/Rails or Go, ISO 27001, or experience in payments, ticketing, or access control would be beneficial.
  • Security certifications such as CISSP or CISM are welcomed but not required.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Job Details:

  • Location: London, UK
  • Working Basis: Hybrid (4 days on-site)
  • Employment Type: Permanent
Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

AWS
Terraform
SOC 2
GDPR
IAM
Cloud Security
Application Security
Vulnerability Management
Incident Response
CI/CD
Threat Modelling
Cloudflare Zero Trust
Container Security
Infrastructure as Code
Security Governance
Penetration Testing

Location

London, England, United Kingdom

Sign up to applySee more jobs like this