We are looking for an experienced Information Security & Compliance Lead to drive our SOC 2 assurance journey and strengthen our security and compliance capabilities across the business. This is a highly visible role that combines governance, risk and compliance expertise with hands‑on security leadership. You will play a critical role in helping Achilles achieve and maintain SOC 2 Type I and Type II attestation while embedding practical, scalable security controls that support our global growth.
Working closely with teams across Technology, Product, Legal, People and Operations, you’ll ensure security and compliance become a natural part of how we operate.
What You’ll Do
- Lead the delivery of our SOC 2 roadmap, from readiness through to Type I, Type II and ongoing annual assurance.
- Design, implement and improve security controls aligned to SOC 2 Trust Services Criteria and broader industry frameworks.
- Conduct readiness assessments, identify control gaps, and drive remediation activities across the business.
- Coordinate internal stakeholders, external auditors and assessors to ensure successful audit outcomes.
- Establish and manage a sustainable controls and evidence programme that keeps Achilles audit-ready all year round.
- Strengthen security operations across identity and access management, cloud security, endpoint protection, vulnerability management, monitoring and incident response.
- Partner with Engineering and Product teams to embed security into architecture, development and operational processes.
- Manage third-party security assessments and supplier assurance activities.
- Support business continuity, disaster recovery and incident management exercises.
- Develop meaningful security metrics and provide clear reporting on risk, compliance and remediation progress.
- Deliver security awareness guidance and support customer due diligence and security assurance activities.
- Champion continuous improvement through automation, standardisation and pragmatic risk management.
What You’ll Bring
- Proven experience leading or significantly contributing to successful SOC 2 Type I and Type II programmes.
- Strong understanding of SOC 2 Trust Services Criteria, control design, audit preparation and evidence management.
- Hands-on experience implementing and operating security controls within cloud-first or SaaS environments.
- Knowledge of security frameworks such as ISO 27001, NIST Cybersecurity Framework and CIS Controls.
- Experience with identity and access management, vulnerability management, incident response, secure change management and third-party risk management.
- Ability to communicate complex security concepts clearly to both technical and non-technical stakeholders.
- Strong analytical and problem-solving skills, with the ability to balance risk management and business objectives.
- Experience working with external auditors, assessors and multiple internal control owners.
- Professional certifications such as CISSP, CISA, CRISC, CCSP, ISO 27001 Lead Auditor/Implementer or Security+ are advantageous.
- Experience working across international or distributed teams would be beneficial.
Why Join Us?
- Be part of a global business making a meaningful impact on sustainability, ESG and responsible business practices.
- Play a pivotal role in shaping and maturing Achilles’ global security and compliance capabilities.
- Work alongside talented colleagues across technology, product and business functions.
- Join a collaborative, values-driven organisation committed to continuous improvement and innovation.
- Enjoy hybrid working and opportunities to collaborate with colleagues around the world.
We welcome applications from armed forces veterans, reservists and their families. We are committed to equity, diversity and inclusion in our practices and workforce. A full role profile is available at Careers at Achilles | Join the Team
For more than 30 years, Achilles has protected organisations’ business interests and reputations by providing unrivalled levels of supply chain transparency, carbon reduction and management. We are the ESG and carbon management partner of choice for the world’s leading global brands.
Achilles specialises in supporting customers that require truly robust environmental, social and governance reporting to fully comply with ESG regulation, meet investor requirements, and achieve their own ambitious sustainability goals. We work with market-leading financial, industrial, commercial, and governmental organisations requiring the serious, detailed analysis and expert insight necessary to deliver exceptional reporting confidence.
Operating from 22 locations worldwide, Achilles is at the forefront of the battle against climate change, a champion for social justice and human rights, and an expert in health, safety, and risk management.
The Achilles Way – how we do things
Be Curious – Ask questions, understand why, challenge and grow
Commit – Show passion, create value, deliver simple solutions, be a leader
Collaborate – Think inclusive, show respect, be helpful, give thanks
#J-18808-Ljbffr…
