Overview
In this role you will help maintain and improve Alfa’s ISMS, ensuring ISO 27001 and ISO 27018 compliance. You will participate in audits (including SSAE 18/ISAE 3402 SOC 1 Type 2 and SOC 2 Type 2), identify control improvements, and support risk analysis and mitigation. You will document regulatory and audit evidence and collaborate with engineers, auditors, and leadership to keep security at the core of client trust. This is a hands-on, cross-functional role that directly affects how Alfa protects and demonstrates its security posture.
Pay / Benefits
- Flexible hybrid working
- 25 days’ annual leave plus bank holidays
- Pension contribution match up to 6%
- Private health insurance and private GP
- Enhanced maternity, paternity and adoption leave
- Life, disability and worldwide travel insurance
Responsibilities
- Maintain and continuously improve the ISMS and related policies/procedures
- Support ISO 27001 and ISO 27018 audits and regulatory inspections
- Contribute to risk analysis and mitigation of security controls
- Prepare clear documentation and evidence for audits and regulatory requirements
- Collaborate with engineers, auditors and leadership to communicate complex security requirements
- Participate in SSAE 18 / ISAE 3402 SOC 1 Type 2 and SOC 2 Type 2 assurance activities
Key requirements
- Bachelor’s degree
- Hands-on experience with ISO 27001 compliance methodologies and audit procedures
- 2+ years in a related role
- Understanding of information security principles
- Experience with documentation and reporting for stakeholders
- Familiarity with Jira and Confluence is a plus
- Experience in a regulated industry and exposure to other frameworks is advantageous
- Analytical thinking
- Strong problem-solving
- Detail-oriented and well-organized
- ISO 27001 and ISO 27018 compliance methodologies
- Audit procedures and regulatory inspections
- SSAE 18 / ISAE 3402 SOC 1 Type 2 and SOC 2 Type 2
…
