Senior Information Security Specialist

Company: Deliveroo
Apply for the Senior Information Security Specialist
Location: London
Job Description:

Overview

In this role you will mature the global security and privacy compliance risk program, designing and operating a global compliance change management framework. You’ll map obligations, drive remediation across teams, and translate regulatory requirements into practical controls. You’ll facilitate risk workshops and communicate risk to leadership, shaping durable, scalable compliance across markets. This is a senior individual contributor role focused on turning ambiguity into actionable, auditable processes that protect customers and the business.

Pay / Benefits

  • healthcare
  • well-being
  • parential leave
  • pensions
  • generous annual leave
  • time off for charitable causes

Responsibilities

  • Design and operate a global compliance change management framework to identify new or changing obligations across markets and products
  • Maintain an obligation inventories view, including control mappings, ownership, risk decisions and remediation status
  • Lead compliance-impact assessments for new regulations, product launches, market expansions, vendor changes and major tech initiatives
  • Facilitate compliance risk workshops with cross-functional stakeholders
  • Translate complex regulatory and security requirements into practical control specifications for both engineers and non-technical teams
  • Identify control gaps, assess residual risk, define remediation plans and track progress to closure
  • Partner with control owners to improve evidence quality, audit readiness, and sustainability of controls
  • Mature risk register, compliance reporting, dashboards, metrics and executive risk communications
  • Support control mapping and harmonization across ISO 27001, SOC 2, NIST CSF, PCI DSS, GDPR, UK GDPR, NIS2, DORA and AI governance requirements
  • Promote a risk-based, pragmatic compliance culture that enables fast delivery while protecting customers and partners

Key requirements

  • 6+ years in GRC, security compliance, technology risk, privacy compliance, IT audit or related field in global tech/marketplace/SaaS/fintech/payments
  • Managed or contributed to a global compliance framework or security/privacy program
  • Built or improved a compliance change management or obligations mapping process
  • Facilitated risk assessments, workshops, control self-assessments and remediation planning with cross-functional stakeholders
  • Strong working knowledge of ISO 27001, SOC 2, GDPR or CCPA, and ability to assess applicability of new frameworks
  • Understanding of how security and privacy controls operate in cloud, IAM, SDLC, incident response, vendor risk, data governance and business continuity
  • Ability to translate regulatory requirements into clear control specifications and communicate risk in business terms
  • Clear written and spoken communication, producing policies, risk memos, narratives and executive updates
  • Comfort navigating ambiguity, balancing priorities, and driving outcomes with minimal direction
  • Ability to build trust and facilitate conversations with technical and non-technical stakeholders
  • strong facilitation and stakeholder management
  • clear and precise communication
  • ambition to work across interdisciplinary teams
  • ISO 27001
  • SOC 2
  • GDPR

Posted: September 14th, 2026