Manager, Security Controls & Compliance

Algolia Algolia · Enterprise · London, United Kingdom · Information Security

Algolia is a leader in AI Search, empowering businesses with fast, predictive search experiences. They are seeking a Manager, Security Controls & Compliance to oversee their security control and compliance framework, ensuring adherence to standards like SOC 2, ISO 27001, and ISO 42001. This role involves managing audits, optimizing compliance tooling, and translating operational signals into auditable evidence, with a focus on continuous improvement and operational excellence within a SaaS environment.

What you'd actually do

  1. Own and operate Algolia’s security compliance programmes (SOC 2, ISO 27001, C5, ISO 42001)
  2. Maintain and evolve a unified control framework mapped across multiple standards
  3. Manage the full audit lifecycle, including preparation, coordination, and remediation
  4. Design and run a risk-based internal audit programme
  5. Ensure controls are continuously evidenced and audit-ready, leveraging automation wherever possible

Skills

Required

  • Experience managing security compliance programmes such as C5, SOC 2 and ISO 27001
  • Strong understanding of security controls and how they operate in real-world environments
  • Experience working with compliance/GRC tooling (e.g. Vanta, or similar)
  • Comfortable working cross-functionally with technical and non-technical teams
  • Ability to translate operational processes and technical signals into clear, auditable evidence
  • Experience coordinating audits and working with external auditors
  • Strong organisational skills with a pragmatic, delivery-focused mindset

Nice to have

  • Experience with additional frameworks such as ISO 42001
  • Familiarity with SaaS environments and cloud-native tooling
  • Exposure to vendor risk management programmes
  • Experience building or improving compliance processes in a scaling organisation

What the JD emphasized

  • security control and compliance framework
  • demonstrate compliance across frameworks such as SOC 2, ISO 27001, C5, and emerging standards like ISO 42001
  • security compliance programmes such as C5, SOC 2 and ISO 27001
  • security controls
  • compliance/GRC tooling
  • auditable evidence
  • coordinating audits
  • additional frameworks such as ISO 42001