Tech Stack
AWSAzureCloudGoogle Cloud Platform
About the role
- Autonomously own, run, and evolve Monolith’s information security strategy and practices
- Maintain security policies, controls, and frameworks
- Manage technical security across cloud infrastructure, ensuring best practices for access, monitoring, and data protection
- Lead in-house ISO27001 compliance programme including audits, documentation, and certification renewal
- Ensure GDPR compliance across technical systems, business operations, and supplier relationships
- Research, evaluate, and apply relevant standards and regulations affecting AI, cloud computing, and personal data
- Establish and maintain a vendor risk management programme with due diligence, contract reviews, and ongoing monitoring
- Build a security-first culture through education, awareness and influencing senior leadership
- Recommend and implement security tooling, automation, and monitoring improvements
- Report to the Director of Operations
Requirements
- 4-7 years of experience in information security, compliance, or related roles
- Hands-on experience with ISO27001 compliance (audits, certification, renewals)
- Strong knowledge of GDPR requirements across technical and business operations
- Solid understanding of cloud infrastructure security (AWS, Azure, or GCP)
- Experience with supplier/vendor risk management
- Excellent communication skills with the ability to educate colleagues and influence senior leaders
- Proactive, analytical, and comfortable working autonomously
- Nice to have: ISO27001 Lead Implementer or Auditor certification
- Nice to have: Professional security certifications (e.g., CISSP, CISM, CCSK)
- Nice to have: Data protection certification (CIPP/E, CIPM)