Apply Edge Start your job search

Platform Security / Compliance Lead – AWS, Terraform, SOC 2, GDPR – Permanent, Hybrid – London, UK

MRP-Global · London Area, United Kingdom

Apply & track with Apply Edge
A UK based technology organisation are seeking an experienced Platform Security / Compliance Lead to own security, compliance, and governance across their digital platform, reporting to the CTO, with significant autonomy and end-to-end ownership of the security function.The ideal candidate will have strong hands-on experience securing production AWS environments, with excellent Terraform, IAM, cloud security, and application security knowledge. Experience with SOC 2, UK GDPR, and enterprise security reviews would be highly advantageous.This will be a permanent opportunity worked on a hybrid basis, 4 days on-site in London, UK.Key Responsibilities:Own the security posture of the AWS environment, including IAM, VPC, Secrets Manager, ECS, Aurora, and access controls.Manage identity and access management, including Cloudflare Zero Trust.Embed security into engineering through threat modelling, secure code and design reviews, vulnerability management, and secure development practices.Manage CI/CD and supply-chain security, including dependencies, GitHub Actions, build provenance, and container security.Own security monitoring, incident response, vulnerability management, and penetration testing.Lead the SOC 2 programme, including controls, evidence, audits, and remediation.Manage UK GDPR and PECR requirements, including DPAs, sub-processors, data processing records, and privacy requirements.Lead customer security reviews, questionnaires, vendor assessments, and security due diligence.Own the security incident lifecycle, including response, notifications, post-incident reviews, and remediation.Required Skills & Experience:Deep hands-on experience securing production AWS environments, including IAM, VPC, containers, and databases.Strong Terraform and infrastructure-as-code experience.Strong application, cloud, and infrastructure security knowledge.Experience with CI/CD, supply-chain security, vulnerability management, and incident response.Pragmatic approach to security risk with strong problem-solving and decision-making skills.Ability to work autonomously and effectively alongside engineering teams.SOC 2 and UK GDPR experience would be highly advantageous.Experience working with enterprise customers and security review processes is desirable.Ruby/Rails or Go, ISO 27001, or experience in payments, ticketing, or access control would be beneficial.Security certifications such as CISSP or CISM are welcomed but not required.