What do I need to bring with me? 🧳
You’ll need to be able to demonstrate the core skills this role requires. You don’t have to tick all the boxes right away; the important thing is that you’re willing to learn. Here’s what the team will be looking for in you:
👉 In-depth, practical experience obtaining and maintaining ISO 27001 certification, with solid knowledge of frameworks such as NIST — typically 3–5 years in an information security compliance role, though other experience levels will be considered.
👉 Proven ability to develop and maintain security policies and procedures that align with industry best practice.
👉 Experience conducting vendor security assessments and managing client security onboarding requirements, balancing risk against commercial objectives.
👉 Hands-on experience building or maintaining a security trust portal; familiarity with tools such as Drata or Vanta is a plus.
👉 Knowledge of SaaS and AI environments, with experience implementing and managing cloud security best practices.
👉 Strong communication skills — able to translate complex GRC topics into clear internal guidance and keep the wider business informed and engaged on security matters.
Equally important is attitude. We want people who think big (to make an impact), ask why (to find a better way), and show respect (to everyone, at every level, all the time). Those are our values, and they’re a big part of what we’re looking for in you.