Jobs and Careers
NM

Senior Information Security Compliance Specialist

NMI
Remote, UKRemotefull_timeVerifiedPosted 25 Apr 2025
💰 £67,500/yr(£57,500/yr£67,500/yr)

About the role

We are seeking a strategic and execution-driven Senior Information Security Compliance Specialist to champion enterprise-level compliance initiatives and embed regulatory excellence across our operations. In this role, you will lead the development and execution of scalable compliance programs that align with business goals, regulatory obligations, and audit requirements. You'll play a critical role in supporting PCI (DSS, PIN, P2PE, MPoC), and SOC 2 initiatives while cultivating a culture of proactive compliance and risk management.

This is primarily a remote position, with occasional in-person responsibilities for cryptographic ceremonies held at our Bristol, UK office.

The ideal candidate is a seasoned compliance specialist who:

  • Converts complex regulatory standards into pragmatic, scalable programs, policies, and procedures
  • Brings deep familiarity with PCI (DSS, PIN, P2PE, MPoC), and SOC 2
  • Partners cross-functionally to drive governance, automation, and continuous improvement
  • Leverages GRC tooling to enhance documentation, management, and reporting on compliance initiatives, risk, and controls
  • Communicates effectively across technical and non-technical stakeholders
  • Champions a proactive compliance culture organization-wide


Key Responsibilities:

Compliance Program Development & Execution:

  • Develop and evolve compliance programs for PCI (DSS, PIN, P2PE), and SOC 2 across their full lifecycle
  • Establish and maintain audit-ready compliance processes that support year-round readiness
  • Define internal roadmaps to achieve and sustain certification status
  • Own the full policy lifecycle, including control mapping, documentation governance, and change management

Risk Management & Control Validation:

  • Conduct risk assessments and controls testing to identify and remediate gaps
  • Collaborate with engineering, infrastructure, and operations teams to ensure effective design and implementation of controls
  • Lead NMI’s Business Continuity and Disaster Recovery planning, management, and testing programs
  • Provide compliance-focused input on new systems and service implementations

Audit Preparation & Oversight:

  • Serve as a primary point of contact for external auditors and assessors
  • Lead audit prep activities including walkthroughs, documentation reviews, and technical evidence collection
  • Ensure timely resolution of audit findings and communicate progress to stakeholders

Cross-Functional Collaboration & Enablement:

  • Engage with stakeholders across Engineering, Product, Legal, and HR to support compliance-by-design
  • Educate internal teams on compliance responsibilities, procedures, and controls
  • Support vendor risk and third-party security assessment activities

Skills & Experience:

Required:

  • 5+ years of experience in information security, IT risk, or compliance roles
  • In-depth experience with PCI DSS and at least two of: PCI PIN, PCI P2PE, SOC 2
  • Proven ability to manage end-to-end compliance projects including successful third-party audits
  • Familiarity with common security documentation, audit evidence gathering,  and security documentation  management practices
  • Strong organizational, project management, and stakeholder communication skills

Preferred:

  • Experience with compliance oversight for secure key management ceremonies and cryptographic key exchanges
  • Industry certifications such as CISA, CISM, CRISC, or ISO 27001 Lead Implementer
  • Background in SaaS or fintech environments
  • Exposure to secure development practices, risk assessments, and vendor risk management programs
  • Familiarity with common GRC tools such as Tugboat, Drata, or Vanta
  • Understanding of privacy regulations (e.g., GDPR, CCPA) as they relate to operational compliance

As well as being a part of something exciting everyday, you will also receive the following benefits:

  • Annual bonus scheme dependent on individual and company performance 
  • Annual salary of £57,500 - £67,500
  • 25 days holiday each year (+ bank holidays + 1 day after each year of service with up to a max. of 30 days)
  • Workplace pension scheme
  • Private medical insurance (upon 30 days of employment)
  • 7 hours per day, 35 hours per week
  • A remote first culture
  • Great work-life balance with our Flexi-time policy
  • Family Friendly policies (Enhanced Maternity and Paternity Pay and Shared Parental Leave).
  • A chance

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

NMI

View company profile →