SlipstreamJobsFresh Startup & VC-Backed Jobs

Information Security Lead

Dexory - Wallingford, Oxfordshire, United Kingdom - Hybrid - posted 2026-08-13

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Dexory is transforming the warehousing and logistics industry through autonomous robotics and data intelligence. We are seeking an Information Security Lead to own and drive our compliance programmes, including ISO 27001, SOC 1 Type 2, and SOC 2 Type 2 certifications. You will serve as the primary responder to customer security due diligence, building systems and knowledge bases that enable Dexory to scale securely without friction. Working closely with the Head of IT & Security, you'll embed good security practices across engineering, product, and operations. Key responsibilities include: - Own day-to-day execution of ISO 27001, SOC 1 Type 2, and SOC 2 Type 2 programmes, including evidence collection, control testing, policy maintenance, and auditor liaison - Maintain the GRC platform, keeping controls, evidence, and risk registers audit-ready - Drive continuous improvement of policies, procedures, and controls across the business - Serve as primary contact for customer security questionnaires (SIG, CAIQ, VSAQ, bespoke RFP sections) - Build and maintain a centralised security knowledge base for consistent, scalable responses - Partner with Sales and Customer Success to unblock deals where security is a gate - Support development and maintenance of information security policies and risk management framework - Conduct vendor and third-party security assessments during procurement - Contribute to incident response and vulnerability management processes - Monitor threat landscape relevant to autonomous robotics and warehouse intelligence - Develop and run security awareness training and phishing simulation programmes Required experience: - Background in information security, GRC, or compliance, ideally within B2B SaaS or technology - Hands-on ISO 27001 experience as implementer or internal auditor with genuine ownership - Solid working knowledge of SOC 1 and SOC 2 frameworks (AICPA Trust Services Criteria) - Familiarity with cloud security principles, particularly AWS - Experience with GRC/compliance platforms (Thoropass, Vanta, Drata) Desirable qualifications: - ISO 27001 Lead Implementer, CISM, CISA, CISSP, or CompTIA Security+ certification - Knowledge of OT, IoT, or robotics security considerations - Background in robotics or startup/scale-up environments The role is hybrid, requiring a minimum of 3 days onsite per week in Wallingford, Oxfordshire.

Similar roles