Compliance & Assurance Lead
Listed on 2026-09-26
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Sure Cloud is a UK-headquartered provider of cloud-based GRC software, delivered as a multi-tenant SaaS platform hosted on AWS. We operate an ISO 27001:2022-certified ISMS, hold Cyber Essentials Plus, and make compliance central to both our product and how we run the business. As we scale the platform and our AI capability (Gracie), we're strengthening the internal governance, risk and compliance function that keeps our certifications, customer commitments and regulatory obligations on track.
A hands‑on, compliance‑focused role owning the day‑to‑day running of Sure Cloud's governance, risk and compliance programme — keeping the ISMS healthy, evidence continuously audit‑ready, and our certifications and regulatory obligations on track across ISO 27001, SOC 2, GDPR and ISO/IEC 42001. The emphasis is on assurance, evidence and audit outcomes: proving that controls operate, not running the underlying infrastructure. You'll work closely with the CTO, the SRE/engineering team (who implement and operate the technical controls) and the Security Working Group.
Keyresponsibilities Compliance & certifications
- ISO 27001:2022 — own audit readiness end to end, manage the BSI relationship, prepare and curate evidence, and coordinate internal and surveillance/recertification audits through to a clean outcome.
- SOC 2 — drive the programme toward SOC 2 Type 2 readiness and attestation: map controls, define and operate evidence collection over the observation window, and liaise with the external auditor.
- GDPR / data protection — operate the data protection programme:
RoPA, DPIAs, DSAR handling, breach‑notification readiness, policy updates, retention schedules and sub‑processor oversight. - ISO/IEC 42001 — maintain and mature Sure Cloud's AI management system alignment for Gracie, including AI governance controls and the AI Acceptable Use Policy.
- Establish and run continuous control monitoring — define control tests, monitor operating effectiveness, and surface exceptions for remediation rather than discovering gaps at audit time.
- Run and maintain the ISMS day‑to‑day: own the policy set, keep documents current, version‑controlled and reviewed on schedule, and drive the annual review cycle.
- Internal Audit - manage the plan and run audits
- Coordinate and run the Security Working Group — the standing governance forum for risk, incidents, audits, policy review and control oversight — and provide compliance reporting into the leadership team.
- Maintain the risk registers and run the risk assessment and treatment process, tracking treatment actions to closure.
- Oversee auditing of vulnerability management, patch compliance and security incident handling from a control and assurance standpoint — confirming SLAs are met and evidence is captured, while the SRE/engineering team owns the technical operation and remediation.
- Translate control and compliance requirements into clear, actionable asks for engineering/SRE/IT, and track them to closure.
- Own security questionnaires,DDQsand customer due diligence responses, and keep the answer library and Trust Centre content accurate and current.
- Run the supplier/third‑party risk process: tiered assessments, contractual security clauses, SOC 2/ISO reviews and annual re‑assessment.
- Support customer conversations on security and compliance matters before and during implementations.
- Deliver and track security and data‑protection awareness training and onboarding; report compliance to the Security Working Group.
- Champion a compliance‑by‑default culture across the business, with product and engineering embedding privacy and security‑by‑design.
- AI‑native — comfortable creating and using agentic AI (e.g. Claude Code) to build…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).