← All jobs

Information Security Lead

Wallingford, Oxfordshire, United Kingdom Full-time
Risk AnalystSecurity AnalystCyber ConsultantCompliance ManagerCompliance OfficerInformation Security LeaderCyber Security EngineerCyber Assurance ManagerSecurity Engineer

Archer is matching candidates to this role at Dexory. Create a free profile and Archer will check you against this role and every other live role, showing you exactly where you match.

Information Security Lead / ISO27001 / SOC / GRC /

 

Location: Wallingford - Oxfordshire (Hybrid) onsite circa 3 day minimum per week

 

Permanent

 

At Dexory, we are transforming the warehousing and logistics industry through data intelligence.

 

We’re currently recruiting for an Information Security Lead to own and drive our compliance programmes (ISO 27001, SOC 1 Type 2, SOC 2 Type 2), act as the primary responder to customer security due diligence, and build the systems and knowledge base that allow Dexory to scale securely without friction.

 

You'll work closely with the Head of IT & Security, embedding good security practice across engineering, product, and operations.

 

Offices based in Wallingford, Oxford and looking for someone who can do 3 days minimum on site ideally more.

 

Any experience within robotics or start up / scale up environments highly desirable.

 

Please apply for more information.

 

Responsibilities / Skills

 

  • Own the day-to-day execution of Dexory's ISO 27001, SOC 1 Type 2, and SOC 2 Type 2 programmes, including evidence collection, control testing, policy maintenance, and auditor liaison
  • Maintain our GRC platform - keeping controls, evidence, and risk registers current and audit-ready at all times
  • Drive continuous improvement of policies, procedures, and controls across the business
  • Serve as the primary point of contact for all inbound customer security questionnaires (SIG, CAIQ, VSAQ, bespoke RFP security sections)
  • Build, own, and continuously improve a centralised security knowledge base to enable faster, consistent, and accurate responses at scale
  • Partner closely with Sales and Customer Success to unblock deals where security is a gate, providing timely responses and where needed, direct engagement with customer security teams
  • Support the development and maintenance of Dexory's information security policies and risk management framework
  • Conduct vendor and third-party security assessments as part of the procurement and onboarding process
  • Contribute to Dexory's incident response and vulnerability management processes
  • Monitor the threat landscape for risks relevant to an autonomous robotics and warehouse intelligence business
  • Develop and run security awareness training and phishing simulation programmes across the business
  • Experience in an information security, GRC, or compliance role, ideally within a B2B SaaS or technology business
  • Hands-on experience with ISO 27001 as an implementer or internal auditor; genuine ownership, not just process participation
  • Solid working knowledge of SOC 1 and SOC 2 frameworks (AICPA Trust Services Criteria)
  • Familiarity with cloud security principles, particularly AWS
  • Nice to Have Certs (ISO 27001 Lead Implementer, CISM, CISA, CISSP, or CompTIA Security+)
  • Experience with GRC/compliance platforms such as Thoropass, Vanta, or Drata (nice to have)
  • Knowledge of OT, IoT, or robotics security considerations - a genuine differentiator given what we build

Apply knowing you're qualified

One free profile is all it takes. Archer checks you against this role and every other live role we list, and shows you exactly which requirements you meet before you apply.

Not quite the right role?

Archer scans thousands of live roles and surfaces the ones you genuinely match, each with a clear explanation of why. It keeps working after you apply, so you hear about roles you would never have found by searching.

Create your free profile