yandex
prolific
Страна
Великобритания
+500% приглашений

Откликайтесь
на вакансии с ИИ

Ускорим процесс поиска работы
LeadУдалённоПолная занятость

Security & Compliance Lead

Оценка ИИ

Высокий балл за работу в инновационной сфере (AI/Data), удаленный формат и возможность вырасти в руководителя функции безопасности. Компания имеет четкую миссию и зрелые процессы (уже есть SOC 2/ISO 27001).


Вакансия из Quick Offer Global, списка международных компаний
Пожаловаться

Сложность вакансии

ЛегкоСложно
Оценка ИИ

Роль требует редкого сочетания глубоких технических навыков (Kubernetes, Terraform, GCP/AWS) и экспертных знаний в области комплаенса (ISO 27001, SOC 2). Это позиция уровня Lead, предполагающая полную автономность и ответственность за стратегию безопасности всей компании.

Анализ зарплаты

Медиана100 000 £
Рынок85 000 £ – 120 000 £
Оценка ИИ

Зарплата в объявлении не указана, но для позиции Security Lead в Великобритании на удаленной основе рыночный диапазон составляет £85,000 – £115,000 в год. Учитывая специфику AI-стартапа и требования к DevSecOps, предложение может быть в верхней части этого диапазона.

Сопроводительное письмо

I am writing to express my strong interest in the Security & Compliance Lead position at Prolific. With over five years of experience in security operations and a deep expertise in cloud security within GCP and AWS environments, I am confident in my ability to evolve your security posture while maintaining the high standards of ISO 27001 and SOC 2 compliance that your partners trust.

In my previous roles, I have successfully integrated security into the SDLC using Terraform and Kubernetes, moving beyond simple policy writing to hands-on DevSecOps implementation. I am particularly drawn to Prolific's mission of providing high-quality human data for AI, and I am eager to apply my skills in incident response, vulnerability management, and audit coordination to ensure your platform remains a secure foundation for global research.

I thrive in scaling environments where security is a core business enabler. I look forward to the possibility of discussing how my technical background and proactive approach to risk management can support Prolific's continued growth and commitment to data protection.

+250% к просмотрам

Составьте идеальное письмо к вакансии с ИИ-агентом

Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в prolific уже сейчас

Присоединяйтесь к Prolific, чтобы возглавить направление безопасности в компании, формирующей будущее этичного ИИ!

Описание вакансии

Security & Compliance Lead

The Role

Security and compliance at Prolific aren't afterthoughts — they're foundational to how we operate. As a company trusted by world-leading research institutions and AI labs to handle sensitive data at scale, we take our responsibility to protect that trust seriously. We maintain certifications like ISO 27001 and SOC 2, and we're looking for someone to own and evolve our security and compliance posture as we grow.

As Security & Compliance Lead, you'll be the go-to authority on information security across the organisation. You'll own our compliance program, lead security operations, and work hands-on with engineering and platform teams to ensure security is embedded in how we build and operate — not bolted on after the fact. This means getting into the weeds of our cloud infrastructure, shaping how security fits into the SDLC, and driving a DevSecOps mindset across engineering.

You'll report to the Head of Engineering/Platform and work cross-functionally with legal, techops,  engineering, platform, and data teams. As we scale, there's a clear path for this role to grow into managing a small security function.

This is a hands-on senior role. You won't just be writing policies — you'll be monitoring threats, responding to incidents, driving audits, reviewing cloud security posture, and shaping how Prolific approaches security as we scale across the world.

What you'll be doing

Security Operations & Cloud Security

  • Monitor for security threats, vulnerabilities, and incidents across our infrastructure, applications, and tooling.
  • Create, respond to, and investigate security alerts using SIEM tooling (e.g. Datadog), triaging and escalating as appropriate.
  • Own and improve our endpoint security, vulnerability scanning (e.g. Snyk), and cloud security posture management across GCP and AWS.
  • Design and implement security architectures across our cloud infrastructure, working hands-on with Kubernetes, Terraform/IaC, and cloud-native services.
  • Lead incident response — minimising impact, ensuring rapid recovery, and coordinating post-incident analysis and reporting.
  • Coordinate penetration testing and manage remediation of findings.

Compliance & Governance

  • Take responsibility for all technical aspects of our compliance program ensuring we maintain ISO 27001, SOC 2, and Cyber Essentials certifications.
  • Lead the preparation and coordination of external audits, ensuring documentation and evidence are always audit-ready.
  • Create, manage, and maintain security and compliance frameworks, including policies, procedures, and guidelines.
  • Partner with legal and our DPO on GDPR and data privacy requirements, ensuring our security practices support our data protection obligations.
  • Align security strategy with business objectives, managing risks while enabling growth.
  • Assist data teams with governance requirements.

DevSecOps & Engineering Partnership

  • Be the authority on information security within the engineering organisation, ensuring security is embedded throughout the SDLC.
  • Work cross-functionally with engineering and platform teams to integrate security into CI/CD pipelines, code review, and infrastructure-as-code workflows.
  • Contribute to platform and infrastructure security architecture decisions, providing guidance on secure design patterns and cloud security best practices.
  • Promote security awareness across the business, including secure development practices, cloud platform security, and general security hygiene.

Threat Intelligence

  • Identify and assess emerging threats and vulnerabilities, recommending actionable mitigations to reduce risk exposure.
  • Monitor and report on trends in the cyber threat landscape, providing insights to inform organisational security decisions.
  • Share threat intelligence and mitigation strategies with relevant teams to enhance awareness and preparedness.

What you'll bring

  • 5+ years of experience in security operations, cloud security, or a combined security and compliance role, with a track record of owning and delivering security outcomes independently.
  • Strong hands-on experience with cloud security in GCP and/or AWS, including working with Kubernetes, Terraform/IaC, and cloud-native security tooling.
  • Deep understanding of compliance frameworks such as ISO 27001 and SOC 2, with experience owning or significantly contributing to audit preparation and certification maintenance.
  • Experience with security tooling across SIEM, vulnerability scanning, endpoint security, and cloud security posture management.
  • A solid understanding of DevSecOps principles and experience embedding security into the software development lifecycle.
  • Working knowledge of GDPR and data privacy requirements, and experience partnering with legal or DPO functions.
  • Strong communication skills — you can translate security risks into business language, influence engineering teams, and write documentation that's clear and actionable.
  • The ability to work independently, manage competing priorities, and exercise good judgement about where to focus your time.
  • A proactive mindset — you spot risks early, propose solutions, and take ownership without being asked.

Even better if you have

  • Experience coordinating penetration testing programmes and managing remediation.
  • Familiarity with infrastructure-as-code security scanning and policy-as-code approaches.
  • Experience with incident response programme design or tabletop exercises.
  • Exposure to customer security questionnaires, vendor due diligence, or third-party risk assessments.
  • Experience working in a scaling company where you've helped build security processes and culture from the ground up.
  • A relevant security certification such as CISSP, CISM, or cloud-specific security certifications (e.g. GCP Professional Cloud Security Engineer).
  • Experience mentoring or growing into a people management role.

*Why Prolific is a great place to work*

We've built a unique platform that connects researchers and companies with a global pool of participants, enabling the collection of high-quality, ethically sourced human behavioral data and feedback. This data is the cornerstone of developing more accurate, nuanced, and aligned AI systems.

We believe that the next leap in AI capabilities won't come solely from scaling existing models, but from integrating diverse human perspectives and behaviors into AI development. By providing this crucial human data infrastructure, Prolific is positioning itself at the forefront of the next wave of AI innovation – one that reflects the breath and the best of humanity.

Working for us will place you at the forefront of AI innovation, providing access to our unique human data platform and opportunities for groundbreaking research. Join us to enjoy a competitive salary, benefits, and remote working within our impactful, mission-driven culture.

*Links to more information on Prolific*

Benefits

External Handbook

Website

Youtube

Privacy Statement

By submitting your application, you agree that Prolific may collect your personal data for recruiting and global organisation planning. Prolific's Candidate Privacy Notice explains what personal information Prolific may process, where Prolific may process your personal information, its purposes for processing your personal information, and the rights you can exercise over Prolific use of your personal information.

+400% к собеседованиям

Создайте идеальное резюме с помощью ИИ-агента

Создайте идеальное резюме с помощью ИИ-агента

Навыки

  • ISO 27001
  • SOC 2
  • GCP
  • AWS
  • Kubernetes
  • Terraform
  • DevSecOps
  • SIEM
  • Datadog
  • Snyk
  • GDPR
  • Incident Response
  • Vulnerability Management
  • Infrastructure as Code

Возможные вопросы на собеседовании

Проверка практического опыта внедрения безопасности в процессы разработки.

Расскажите о вашем опыте интеграции инструментов безопасности (например, Snyk или сканеров IaC) в CI/CD пайплайны. С какими трудностями со стороны разработчиков вы сталкивались?

Оценка навыков управления облачной безопасностью.

Как бы вы организовали мониторинг и реагирование на инциденты в среде Kubernetes, развернутой в GCP/AWS?

Проверка умения совмещать требования регуляторов с бизнес-процессами.

Опишите ваш опыт прохождения аудита SOC 2 или ISO 27001. Как вы обеспечиваете 'audit-ready' состояние документации без ущерба для скорости разработки?

Оценка навыков реагирования на инциденты.

Опишите самый сложный инцидент информационной безопасности, которым вы руководили. Каковы были ваши действия по минимизации ущерба и последующему анализу?

Проверка лидерских качеств и стратегического мышления.

Как вы транслируете технические риски безопасности руководству и бизнес-подразделениям, чтобы получить поддержку для необходимых изменений?

Похожие вакансии

Navio
от 300 000 ₽

Ведущий специалист по безопасности приложений (AppSec)

LeadГибридРоссия
AppSec · SAST · SCA · ASOC · AntiDDoS · WAF · Kubernetes · Cloud Infrastructure · Linux · Jira · GitLab · Artifactory · Network Security
+13 навыков
Т-Банк
от 430 000 ₽

Red Team Lead

LeadВ офисеРоссия
Red Teaming · Offensive Security · Python · Go · C++ · PowerShell · Linux · Windows · Active Directory · MITRE ATT&CK · SIEM · EDR · WAF · Threat Intelligence · Purple Teaming · PKI · Cryptography
+17 навыков
netskope
147 000 $ – 299 500 $

Principal Engineer, Cloud Firewall

LeadУдалённоСША
C++ · TCP/IP · SSL/TLS · Firewall · IPS/IDS · Wireshark · TCPDump · GTest · PyTest · Ansible · Kubernetes · SQL · NoSQL · CI/CD · Jenkins · Distributed Systems
+16 навыков
doordashusa
193 800 $ – 285 000 $

Principal Privacy Engineer

LeadУдалённоСША
Privacy Engineering · Data Governance · Encryption · GDPR · CCPA · Machine Learning · Cryptography · Data Classification · PETs · Trusted Execution Environments · LLM
+11 навыков
iherb
177 000 $ – 225 000 $

Principal Application Security Engineer

LeadУдалённоСША
Python · C++ · .NET · JavaScript · Node.js · Java · AWS · Docker · SAST · DAST · SCA · Threat Modeling · Cryptography · API Design · Microservices · Cloudflare · OWASP Top 10
+17 навыков
SDOdev
380 000 ₽ – 500 000 ₽

Senior Android Security / Reverse Engineer (HTTPS Traffic, Google Services)

SeniorУдалённоРоссия
Android · iOS · TCP/IP · HTTPS · Cryptography · MITM · Frida · Objection · Apktool · Jadx · Hopper · Smali · Hermes · Swift · Dart · Objective-C · C++ · Reverse Engineering · Cybersecurity
+19 навыков
более 1000 офферов получено
4.9

1000+ офферов получено

Устали искать работу? Мы найдём её за вас

Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!

prolific
Страна
Великобритания