Skip to content

Governance & Compliance

QSA / Compliance Lead

Location
Remote (EU/UK)
Type
Full-time
Level
Lead
Posted
Apply for this role ↓

The role

Lead PCI DSS, ISO 27001 and SOC 2 engagements, guiding clients from gap analysis to certification with practical, risk-based advice.

What you’ll do

  • Run PCI DSS assessments, gap analyses and readiness reviews.
  • Support clients through ISO 27001 and SOC 2 programmes, from scoping to audit.
  • Translate technical test findings into compliance and risk language.
  • Build policy, control and evidence frameworks that teams can actually run.
  • Grow the compliance practice alongside the testing team.

What we’re looking for

  • Current or recent PCI QSA status, or equivalent hands-on PCI DSS assessment experience.
  • Working knowledge of ISO 27001 and SOC 2 control frameworks.
  • Experience leading client engagements and writing formal assessment reports.
  • Comfortable discussing technical controls with engineering teams.
  • Right to work in the UK or an EU country.

Nice to have

  • ISO 27001 Lead Auditor, CISA or CISM certification.
  • Experience with DORA, NIS2 or GDPR programmes.
  • Background in payments, fintech or e-commerce.

Don’t tick every box? Apply anyway — we hire for ability and curiosity, not a perfect keyword match.

How we hire

01

Application review

A consultant — not an automated filter — reads every CV and replies within 5 working days.

02

Intro call

30 minutes to talk about the role, your background and what you want next.

03

Practical exercise

A realistic, time-boxed task relevant to the role. No unpaid multi-day projects.

04

Team interview & offer

Meet the people you'd work with, then a decision within a week.

Apply

Apply for QSA / Compliance Lead

Takes about 5 minutes. Fields marked * are required.

Role
About you
Experience & availability
CV & cover note
CV / résumé *

What happens next

A consultant reads every application and replies within 5 working days.

Your data

Your CV goes straight to our hiring inbox. It is never published or shared outside the hiring team.