Security & Compliance Lead

Skills
DevopsMicrosoft AzureAmazon Web ServicesGeneral Data Protection RegulationGovernanceRisk ManagementAnd Compliance
Role

What the job involves

The main requirements, responsibilities and hiring steps.

Requirements

  • 4+ years in security and compliance with hands-on ownership of a compliance program
  • Relevant certification such as CISSP CIPP CISA CCSP Security+ or Azure/AWS security specialty
  • Ability to read Terraform and cloud configurations and verify controls
  • Experience running or supporting a SOC 2 program and using GRC tools such as Vanta Drata or Secureframe
  • Working knowledge of GDPR and UK GDPR including RoPA DPAs DPIAs and sub-processor management
  • Experience authoring security policy and responding to enterprise security questionnaires
  • Strong written communication and ability to translate between auditors engineers and clients
  • Hands-on infrastructure or DevOps experience including IaC CI/CD or cloud administration
  • Experience as a first security or compliance hire at an early-stage company
  • Direct incident response experience

Nice to have

  • Technical grounding
  • Documentation-first
  • Evidence-driven
  • Autonomy
  • Prioritization

Day to day

  • Own Litehouse's security and compliance program end to end, with a strong focus on governance, audit readiness, and operational rigor.
  • Administer Vanta, manage SOC 2 Type II evidence and remediation, and keep GDPR and UK GDPR controls current and defensible.
  • Work closely with engineering, auditors, clients, and advisors to verify controls, manage incidents, and drive practical security improvements across the platform.