Job Description
📋 Description Own design and automation of evidence collection for security/compliance controls Build tooling to automatically gather, validate, and organize compliance evidence Translate control requirements into automated, testable checks Embed evidence collection into Kubernetes operators, CI/CD, and infra automation Reduce manual audits by delivering continuous, always-current compliance state Own compliance tooling roadmap and prioritisation within security engineering 🎯 Requirements Strong software engineering background with automation/backend experience Experience in security/compliance function, ideally infra/cloud Familiarity with SOC 2/ISO 27001 and audit evidence Comfortable with Kubernetes, cloud/DC environments, and CI/CD pipelines Track record turning manual processes into automated, scalable systems Strong cross-functional communication across security, engineering, legal, and audit 🎁 Benefits Direct experience in a compliance-focused security engineering role Familiarity with policy-as-code or automated control-testing frameworks Experience supporting audits for infrastructure or data centres Exposure to multi-jurisdiction regulatory requirements (UK/EU/US) Background in broader security engineering beyond compliance-focused work